Files
kit-busrouter/README.md
T
allen f15ac69925 feat: kit-busrouter v2.0 — complete Synology + GL fleet router platform
Includes:
- package/ GL-XE3000 kit-busrouter (opkg)
- scripts/provision.sh (GL) and provision-synology.sh (Synology)
- syno-balance/ — new WAN balancer replacing aiwanbal (SmartWAN adapter)
- kit-connect/ — unified connectivity SPK (Tailscale + reverse SSH)
- docs/deployment/synology-rt2600ac-checklist.md — 62-point checklist
- docs/provisioning/device-identity.md — fleet identity spec
- docs/pilot/checklist.md — field pilot validation
- x4078_20260721.dss — reference config backup

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-22 00:07:14 +00:00

35 lines
1.1 KiB
Markdown

# kit-busrouter
Configuration and operational notes for the bus-fleet edge routers.
## Hardware
**GL.iNet GL-XE3000** (5G "Puli") running OpenWrt. LAN address `192.168.8.1`, login `root`.
## Management access
Routers are managed out-of-band over a **WireGuard tunnel** to the busfleet hub. Each
router dials the hub and mgmt SSH is allowed *inbound over the tunnel only* — never
exposed on the WAN.
| Item | Value |
|------|-------|
| WG client interface / firewall zone | `wgclient1` (`proto=wgclient`) |
| Router tunnel IP | `10.88.0.2/32` |
| Hub tunnel IP | `10.88.0.1` |
| Hub endpoint | `167.172.237.162:51820` (UDP) |
| Tunnel subnet | `10.88.0.0/24` |
| Inbound mgmt SSH rule | `Allow-WG-mgmt-SSH` — tcp/22 from `10.88.0.0/24`, `src` zone **`wgclient1`** |
| Hub jump key | `busfleet-hub-jump` (ed25519) in `/etc/dropbear/authorized_keys`, perms `600` |
The hub reaches a router with:
```sh
ssh -J busfleet-hub-jump root@10.88.0.2 # over the established tunnel
```
## Docs
- [docs/mgmt-tunnel-ssh.md](docs/mgmt-tunnel-ssh.md) — provisioning and troubleshooting inbound
mgmt SSH over the WireGuard tunnel.