kitadmin 34f8074ee7 fix: audit gaps — GL local keyword, key authorization in wizards, register script parity
GL daemon: removed remaining 'local ts_ip' (busybox ash compat)
Synology wizard: auto-authorizes tunnel key via POST /api/authorize-key
GL wizard: same key authorization flow added
Synology: added connect-register.sh for parity with GL
syno-balance build.sh: removed deprecated checksum file (same lesson as kit-connect)

All four curl hubs (wizards + register scripts) now have --max-time 15.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 04:20:40 +00:00

kit-busrouter

Configuration and operational notes for the bus-fleet edge routers.

Hardware

GL.iNet GL-XE3000 (5G "Puli") running OpenWrt. LAN address 192.168.8.1, login root.

Management access

Routers are managed out-of-band over a WireGuard tunnel to the busfleet hub. Each router dials the hub and mgmt SSH is allowed inbound over the tunnel only — never exposed on the WAN.

Item Value
WG client interface / firewall zone wgclient1 (proto=wgclient)
Router tunnel IP 10.88.0.2/32
Hub tunnel IP 10.88.0.1
Hub endpoint 167.172.237.162:51820 (UDP)
Tunnel subnet 10.88.0.0/24
Inbound mgmt SSH rule Allow-WG-mgmt-SSH — tcp/22 from 10.88.0.0/24, src zone wgclient1
Hub jump key busfleet-hub-jump (ed25519) in /etc/dropbear/authorized_keys, perms 600

The hub reaches a router with:

ssh -J busfleet-hub-jump root@10.88.0.2   # over the established tunnel

Docs

S
Description
Pioneer Bus Fleet — kit-connect, syno-balance, busfleet-hub
Readme 126 MiB
Languages
Shell 78.6%
HTML 15.3%
Python 4.9%
Makefile 1.2%