################################################################ ### ROUTER EGRESS PLAN ################################################################ INSTANCE=mgts-main INSTANCE_DIR=/opt/router-ops/instances/mgts-main EGRESS_YML=/opt/router-ops/instances/mgts-main/egress.yml MODE=DRY_RUN_ONLY REMOTE_CHANGES=NO ################################################################ ### EXPECTED SLOTS FROM PROFILE ################################################################ hmn_slot_1 iface=vpn1 table=201 fwmark=0x201 provider=hidemyname role=active weight=100 hmn_slot_2 iface=vpn2 table=202 fwmark=0x202 provider=hidemyname role=active weight=100 hmn_slot_3 iface=vpn3 table=203 fwmark=0x203 provider=hidemyname role=active weight=100 hmn_slot_4 iface=vpn4 table=204 fwmark=0x204 provider=hidemyname role=active weight=100 hmn_slot_5 iface=vpn5 table=205 fwmark=0x205 provider=hidemyname role=active weight=100 ################################################################ ### VM101 CURRENT BASIC STATE ################################################################ Wed Jul 8 08:40:08 UTC 2026 08:40:08 up 16:02, load average: 0.00, 0.00, 0.00 lo UNKNOWN 127.0.0.1/8 ::1/128 eth0 UP 95.165.105.4/20 fe80::be24:11ff:fe42:83cf/64 eth1 UP 10.200.0.2/24 fe80::be24:11ff:fe09:4e2c/64 eth2 UP 10.71.100.2/24 fe80::be24:11ff:fe4d:7a71/64 eth3 UP 10.201.0.2/24 fe80::be24:11ff:fec8:2ee1/64 vpn1 UNKNOWN 10.91.233.132/32 default via 95.165.96.1 dev eth0 proto static src 95.165.105.4 10.71.100.0/24 dev eth2 proto kernel scope link src 10.71.100.2 10.200.0.0/24 dev eth1 proto kernel scope link src 10.200.0.2 10.201.0.0/24 dev eth3 proto kernel scope link src 10.201.0.2 10.250.100.0/24 via 10.71.100.1 dev eth2 proto static 95.165.96.0/20 dev eth0 proto kernel scope link src 95.165.105.4 95.211.68.119 via 95.165.96.1 dev eth0 proto static 178.215.227.13 via 95.165.96.1 dev eth0 proto static 192.71.27.64 via 95.165.96.1 dev eth0 proto static 192.121.163.235 via 95.165.96.1 dev eth0 proto static 0: from all lookup local 10019: from all iif eth1 lookup 200 10020: from 10.200.0.0/24 lookup 200 32766: from all lookup main 32767: from all lookup default rc=0 ################################################################ ### VM101 LEGACY AUTOMATION FREEZE CHECK ################################################################ === crontab === # STEP_029C1_DISABLED * * * * * /usr/bin/vpn-egress-manager.sh >/dev/null 2>&1 # STEP_029C1_DISABLED 20 4 * * * /root/hmn/hmn-refresh-pool-cron.sh # STEP_029C1_DISABLED 7,22,37,52 * * * * /root/hmn/hmn-pool-low-watermark-check.sh run >/dev/null 2>&1 # STEP_029C1_DISABLED 5,35 * * * * /root/hmn/hmn-refresh-retry-cron.sh # STEP_029C1_DISABLED 10 3 * * * /root/hmn/hmn-clean-old-files.sh >/dev/null 2>&1 # STEP_029C1_DISABLED * * * * * /root/hmn/hmn-vpn-user-override.sh tick >/dev/null 2>&1 === hotplug iface === drwxr-xr-x 2 root root 4096 Jul 8 08:35 . drwxr-xr-x 10 root root 4096 Apr 20 11:42 .. -rw-r--r-- 1 root root 155 Jun 23 2025 00-netstate -rw-r--r-- 1 root root 498 Jun 23 2025 20-firewall === legacy processes === rc=0 ################################################################ ### VM101 CURRENT EGRESS INTERFACE SUMMARY ################################################################ --- vpn1 --- proto=amneziawg auto=0 disabled=0 addresses=10.91.233.132/32 hmn_role=active_spare_slot hmn_endpoint=178.215.227.13:44408 vpn1 UNKNOWN 10.91.233.132/32 --- vpn2 --- proto=amneziawg auto=0 disabled=0 addresses=10.86.108.200/32 hmn_role=active_spare_slot hmn_endpoint=192.121.163.235:42530 --- vpn3 --- --- vpn4 --- --- vpn5 --- --- vpn_user --- proto=amneziawg auto=0 disabled=0 addresses=10.90.235.244/32 hmn_role=user_select_slot hmn_endpoint=37.235.54.96:38971 --- vpn_test --- proto=amneziawg auto=0 disabled=0 addresses=10.67.234.5/32 hmn_role=test_slot hmn_endpoint=192.71.27.64:40044 rc=0 ################################################################ ### VM101 FIREWALL VPN_OUT SUMMARY ################################################################ firewall.@zone[4].name='vpn_out' firewall.@zone[4].network='vpn1' 'vpn2' 'vpn_user' firewall.@rule[7].src='vpn_in' firewall.@forwarding[1].src='vpn_in' firewall.@forwarding[1].dest='vpn_out' firewall.@forwarding[2].src='vpn_in' rc=0 ################################################################ ### VM101 TABLE/ROUTE LEGACY SUMMARY ################################################################ === rt_tables === # # reserved values # 128 prelocal 255 local 254 main 253 default 0 unspec # # local # #1 inr.ruhep === table 200 === default dev vpn1 scope link 10.200.0.0/24 dev eth1 scope link src 10.200.0.2 10.201.0.0/24 dev eth3 scope link src 10.201.0.2 === candidate new tables 201-205 === --- table 201 --- --- table 202 --- --- table 203 --- --- table 204 --- --- table 205 --- rc=0 ################################################################ ### VM101 HMN CANDIDATE POOL SUMMARY ################################################################ === hmn dirs === drwx------ 12 root root 4096 Jul 6 14:24 . drwxr-x--- 13 root root 4096 Jul 8 08:35 .. drwx------ 19 root root 24576 Jul 8 06:15 backups drwx------ 2 root root 8192 Jul 8 06:16 cache drwxr-xr-x 8 root root 4096 Jun 1 15:29 checkpoints drwxr-xr-x 3 root root 4096 Jun 1 10:06 configs -rwxr-xr-x 1 root root 6765 Jun 1 14:32 hmn-apply-selected.sh -rwxr-xr-x 1 root root 541 Jul 1 08:22 hmn-clean-old-files.sh -rwxr-xr-x 1 root root 1525 Jun 1 10:04 hmn-code-test.sh -rwxr-xr-x 1 root root 8926 Jun 1 13:58 hmn-download-all-awg.sh -rwxr-xr-x 1 root root 5125 Jun 3 16:20 hmn-load-vpn-slot.sh -rwxr-xr-x 1 root root 4949 Jun 3 16:20 hmn-load-vpn-test.sh -rwxr-xr-x 1 root root 7032 Jul 6 14:24 hmn-load-vpn-user.sh -rwxr-xr-x 1 root root 3181 Jun 1 15:12 hmn-plan-selected.sh -rwxr-xr-x 1 root root 2908 Jun 1 14:00 hmn-plan-selected.sh.before-active-not-top2-fix-20260601-151230 -rwxr-xr-x 1 root root 6149 Jun 3 16:20 hmn-pool-low-watermark-check.sh -rwxr-xr-x 1 root root 3169 Jun 1 13:55 hmn-rank-awg.sh -rwxr-xr-x 1 root root 6084 Jun 3 16:20 hmn-refill-slot.sh -rwxr-xr-x 1 root root 4979 Jun 1 15:28 hmn-refresh-awg.sh -rwxr-xr-x 1 root root 4726 Jun 1 14:41 hmn-refresh-awg.sh.before-awk-lock-20260601-152842 -rwxr-xr-x 1 root root 4726 Jun 1 14:41 hmn-refresh-awg.sh.before-lock-20260601-152728 -rwxr-xr-x 1 root root 533 Jun 3 16:20 hmn-refresh-pool-cron.sh -rwxr-xr-x 1 root root 8534 Jun 3 16:20 hmn-refresh-pool-safe.sh -rwxr-xr-x 1 root root 4309 Jun 3 16:20 hmn-refresh-retry-cron.sh -rwxr-xr-x 1 root root 1648 Jun 1 10:03 hmn-set-code.sh -rwxr-xr-x 1 root root 5925 Jun 3 16:20 hmn-test-all-awg.sh -rwxr-xr-x 1 root root 7298 Jun 3 16:20 hmn-validate-current-pool.sh -rwxr-xr-x 1 root root 5011 Jul 6 14:24 hmn-vpn-egress-revive.sh -rwxr-xr-x 1 root root 7379 Jul 6 10:00 hmn-vpn-user-override.sh -rw------- 1 root root 434 Jul 6 16:10 hmn.env drwx------ 2 root root 4096 Jul 8 04:20 logs drwxr-xr-x 9 root root 4096 Jul 6 14:24 patch-backups -rw-r--r-- 1 root root 201414 Jul 8 06:16 refill.log drwx------ 2 root root 4096 Jul 8 04:31 reports drwx------ 17 root root 4096 Jul 8 04:20 runs drwx------ 2 root root 4096 Jul 8 04:31 state drwxr-xr-x 19 root root 4096 Jul 8 04:20 test-runs === latest config count === 0 === latest configs sample === === selected/cache files === /root/hmn/backups/client001-before-h42c-load-slots-20260603-163645/selected-awg1-latest.tsv.before /root/hmn/backups/client001-before-h42d-selected-cache-20260603-163829/selected-awg1-latest.tsv.before /root/hmn/backups/refresh-safe-before-20260604-042000-21898/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260604-042000-21898/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260604-042000-21898/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260605-042000-15413/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260605-042000-15413/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260605-042000-15413/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-042000-12109/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-042000-12109/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-042000-12109/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-180709-17601/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-180709-17601/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260606-180709-17601/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-042000-18519/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-042000-18519/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-042000-18519/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-120709-11931/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-120709-11931/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-120709-11931/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-122209-3961/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-122209-3961/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-122209-3961/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-180718-22253/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-180718-22253/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260607-180718-22253/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260608-042000-18279/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260608-042000-18279/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260608-042000-18279/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260706-161226-12417/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260706-161226-12417/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260706-161226-12417/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260707-042000-9733/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260707-042000-9733/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260707-042000-9733/selected-awg1-latest.tsv /root/hmn/backups/refresh-safe-before-20260708-042000-24122/ok-awg1-strict-all-latest.tsv /root/hmn/backups/refresh-safe-before-20260708-042000-24122/ok-awg1-strict-foreign-latest.tsv /root/hmn/backups/refresh-safe-before-20260708-042000-24122/selected-awg1-latest.tsv /root/hmn/cache/fail-awg1-latest.tsv /root/hmn/cache/ok-awg1-strict-all-latest.tsv /root/hmn/cache/ok-awg1-strict-all-latest.tsv.before-validate-20260707-042048 /root/hmn/cache/ok-awg1-strict-all-latest.tsv.before-validate-20260708-042044 /root/hmn/cache/ok-awg1-strict-foreign-latest.tsv /root/hmn/cache/ok-awg1-strict-foreign-latest.tsv.before-validate-20260707-042048 /root/hmn/cache/ok-awg1-strict-foreign-latest.tsv.before-validate-20260708-042044 /root/hmn/cache/ok-awg1-strict-latest.tsv /root/hmn/cache/ok-awg1-strict-latest.tsv.before-validate-20260707-042048 /root/hmn/cache/ok-awg1-strict-latest.tsv.before-validate-20260708-042044 /root/hmn/cache/quarantine-awg1-latest.tsv /root/hmn/cache/quarantine-awg1-latest.tsv.before-validate-20260706-161434 /root/hmn/cache/quarantine-awg1-latest.tsv.before-validate-20260707-042048 /root/hmn/cache/quarantine-awg1-latest.tsv.before-validate-20260708-042044 /root/hmn/cache/ranked-awg1-latest.tsv /root/hmn/cache/selected-awg1-20260601-110707.tsv /root/hmn/cache/selected-awg1-20260601-135559.tsv /root/hmn/cache/selected-awg1-20260601-145208.tsv /root/hmn/cache/selected-awg1-20260601-152436.tsv /root/hmn/cache/selected-awg1-latest.tsv /root/hmn/cache/selected-awg1-latest.tsv.before-refill-20260706-165740 /root/hmn/cache/selected-awg1-latest.tsv.before-refill-20260706-170839 /root/hmn/cache/selected-awg1-latest.tsv.before-refill-20260708-061633 /root/hmn/cache/selected-awg1-loadpath-check.tsv /root/hmn/cache/wg-candidates-latest.tsv /root/hmn/cache/working-awg1-latest.tsv /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908.tar.gz /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/99-vpn-egress-manager /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/99-vpnin-policy-route /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/STATUS.txt /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/active-slot /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/hmn-apply-selected.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/hmn-download-all-awg.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/hmn-load-vpn-slot.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/hmn-plan-selected.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/hmn-rank-awg.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/quarantine-awg1-latest.tsv /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/ranked-awg1-latest.tsv /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/selected-awg1-latest.tsv /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/vpn-egress-manager.sh /root/hmn/checkpoints/stable-apply-selected-standby-only-20260601-143908/vpn-table200-local-routes.sh /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/STATUS.txt /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/hmn-apply-selected.sh /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/hmn-plan-selected.sh /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/quarantine-awg1-latest.tsv /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/ranked-awg1-latest.tsv /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/selected-awg1-latest.tsv /root/hmn/checkpoints/stable-nightly-refresh-cron-20260601-152930/working-awg1-latest.tsv /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/STATUS.txt /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/hmn-apply-selected.sh /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/hmn-plan-selected.sh /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/quarantine-awg1-latest.tsv /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/ranked-awg1-latest.tsv /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/selected-awg1-latest.tsv /root/hmn/checkpoints/stable-refresh-wrapper-standby-only-20260601-151334/working-awg1-latest.tsv /root/hmn/checkpoints/stable-safe-failover-vpn1-amsterdam-20260601-134555/STATUS.txt /root/hmn/checkpoints/stable-safe-failover-vpn2-tallinn-20260601-142114/STATUS.txt /root/hmn/checkpoints/stable-safe-failover-vpn2-tallinn-20260601-142114/hmn-plan-selected.sh /root/hmn/checkpoints/stable-safe-failover-vpn2-tallinn-20260601-142114/quarantine-awg1-latest.tsv /root/hmn/checkpoints/stable-safe-failover-vpn2-tallinn-20260601-142114/ranked-awg1-latest.tsv /root/hmn/checkpoints/stable-safe-failover-vpn2-tallinn-20260601-142114/selected-awg1-latest.tsv /root/hmn/checkpoints/stable-vpn1-amsterdam-20260601-131612/STATUS.txt /root/hmn/hmn-apply-selected.sh /root/hmn/hmn-plan-selected.sh /root/hmn/hmn-plan-selected.sh.before-active-not-top2-fix-20260601-151230 /root/hmn/hmn-pool-low-watermark-check.sh /root/hmn/hmn-refresh-pool-cron.sh /root/hmn/hmn-refresh-pool-safe.sh /root/hmn/hmn-validate-current-pool.sh /root/hmn/logs/cron-refresh-pool-safe-last.log /root/hmn/logs/refresh-pool-safe-20260706-161226-12417.log /root/hmn/logs/refresh-pool-safe-20260707-042000-9733.log /root/hmn/logs/refresh-pool-safe-20260708-042000-24122.log /root/hmn/logs/validate-current-pool-20260706-161434.log /root/hmn/logs/validate-current-pool-20260707-042048.log /root/hmn/logs/validate-current-pool-20260708-042044.log /root/hmn/runs/20260601-100614/wg-candidates.tsv /root/hmn/runs/20260601-100614/working-awg1.tsv /root/hmn/runs/20260601-144311/wg-candidates.tsv /root/hmn/runs/20260601-144311/working-awg1.tsv /root/hmn/runs/20260601-151531/wg-candidates.tsv /root/hmn/runs/20260601-151531/working-awg1.tsv rc=0 ################################################################ ### DRY-RUN DECISION ################################################################ No changes applied. Expected next implementation steps: 1. Create local egress tool skeleton under product/egress/bin. 2. Create VM101-side /opt/router-ops/egress runtime directory. 3. Add read-only slot status command. 4. Add apply steps only after explicit confirmation. Safety constraints still active: - do not touch VM101 WAN eth0 - do not touch VM101 DNAT 51820/51830 - do not touch VM100 wg_remote/wg_paid - do not globally restart network - do not flush ip rules