kitadmin 14d46d96a4 fix: daemon hang, postinst mkdir, hub key authorization, boot persistence
SPK daemon fixes (x5925 testing feedback):
- register_with_hub: added --max-time 15 to prevent indefinite hang
- Removed bash 'local' keyword for busybox ash compatibility
- postinst: mkdir -p /usr/local/bin before copying Tailscale binaries
- postinst: chmod +x all bin/*.sh (fixes 644 execute bit bug)
- Added x5925-boot.sh for reboot persistence (stopgap until daemon fixed)

Hub security hardening:
- Added POST /api/authorize-key endpoint with device_id + pubkey
- Keys auto-authorized with restrict,port-forwarding,permitlisten="<port>"
- No shell access allowed — only tunnel forwarding to assigned port
- Server.py updated with input validation on key format
- register.sh --authorize-key subcommand for secure key management

GL daemon: same --max-time fix applied for curl timeout

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 04:09:49 +00:00

kit-busrouter

Configuration and operational notes for the bus-fleet edge routers.

Hardware

GL.iNet GL-XE3000 (5G "Puli") running OpenWrt. LAN address 192.168.8.1, login root.

Management access

Routers are managed out-of-band over a WireGuard tunnel to the busfleet hub. Each router dials the hub and mgmt SSH is allowed inbound over the tunnel only — never exposed on the WAN.

Item Value
WG client interface / firewall zone wgclient1 (proto=wgclient)
Router tunnel IP 10.88.0.2/32
Hub tunnel IP 10.88.0.1
Hub endpoint 167.172.237.162:51820 (UDP)
Tunnel subnet 10.88.0.0/24
Inbound mgmt SSH rule Allow-WG-mgmt-SSH — tcp/22 from 10.88.0.0/24, src zone wgclient1
Hub jump key busfleet-hub-jump (ed25519) in /etc/dropbear/authorized_keys, perms 600

The hub reaches a router with:

ssh -J busfleet-hub-jump root@10.88.0.2   # over the established tunnel

Docs

S
Description
Pioneer Bus Fleet — kit-connect, syno-balance, busfleet-hub
Readme 126 MiB
Languages
Shell 78.6%
HTML 15.3%
Python 4.9%
Makefile 1.2%