################################################################ ### HMN APPLY PREFLIGHT ################################################################ INSTANCE=mgts-main MODE=READ_ONLY REMOTE_CHANGES=NO STRATEGY=preserve_existing candidate_source=/root/hmn/cache/ok-awg1-strict-foreign-latest.tsv rows=15 selected_source=/root/hmn/cache/selected-awg1-latest.tsv rows=2 quarantine_source=/root/hmn/cache/quarantine-awg1-latest.tsv rows=0 ################################################################ ### PROPOSED PRESERVE_EXISTING PLAN ################################################################ slot iface table fwmark reason endpoint avg file hmn_slot_1 vpn1 201 0x201 preserve_existing_selected 178.215.227.13:44408 53.234 150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf hmn_slot_2 vpn2 202 0x202 preserve_existing_selected 192.121.163.235:42530 38.879 128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf hmn_slot_3 vpn3 203 0x203 fill_from_primary 95.211.68.119:45176 43.304 075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf hmn_slot_4 vpn4 204 0x204 fill_from_primary 78.31.250.16:41729 46.381 072-NL-Netherlands-Amsterdam-S8-78.31.250.16-awg1.conf hmn_slot_5 vpn5 205 0x205 fill_from_primary 157.173.27.69:41797 57.299 049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf ################################################################ ### CONFIG FILE AVAILABILITY ################################################################ 150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf -> FOUND /root/hmn/configs/awg1/20260601-100614/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260601-144311/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260601-151531/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260604-042000/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260605-042000/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260606-042000/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260606-180709/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260607-042000/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260607-120709/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf /root/hmn/configs/awg1/20260607-122209/150-NL-Netherlands-Amsterdam-R5-178.215.227.13-awg1.conf 128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf -> FOUND /root/hmn/configs/awg1/20260601-100614/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260601-144311/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260601-151531/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260604-042000/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260605-042000/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260606-042000/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260606-180709/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260607-042000/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260607-120709/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf /root/hmn/configs/awg1/20260607-122209/128-LV-Latvia-Riga-S1-192.121.163.235-awg1.conf 075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf -> FOUND /root/hmn/configs/awg1/20260601-100614/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260601-144311/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260601-151531/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260604-042000/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260605-042000/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260606-042000/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260606-180709/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260607-042000/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260607-120709/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf /root/hmn/configs/awg1/20260607-122209/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf 072-NL-Netherlands-Amsterdam-S8-78.31.250.16-awg1.conf -> FOUND /root/hmn/configs/awg1/20260707-042000/072-NL-Netherlands-Amsterdam-S8-78.31.250.16-awg1.conf /root/hmn/configs/awg1/20260708-042000/072-NL-Netherlands-Amsterdam-S8-78.31.250.16-awg1.conf 049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf -> FOUND /root/hmn/configs/awg1/20260601-100614/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260601-144311/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260601-151531/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260604-042000/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260605-042000/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260606-042000/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260606-180709/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260607-042000/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260607-120709/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf /root/hmn/configs/awg1/20260607-122209/049-DE-Germany-Berlin-S7-157.173.27.69-awg1.conf ################################################################ ### REMOTE SAFETY STATE ################################################################ __BASIC__ Wed Jul 8 10:04:55 UTC 2026 lo UNKNOWN 127.0.0.1/8 ::1/128 eth0 UP 95.165.105.4/20 fe80::be24:11ff:fe42:83cf/64 eth1 UP 10.200.0.2/24 fe80::be24:11ff:fe09:4e2c/64 eth2 UP 10.71.100.2/24 fe80::be24:11ff:fe4d:7a71/64 eth3 UP 10.201.0.2/24 fe80::be24:11ff:fec8:2ee1/64 vpn1 UNKNOWN 10.91.233.132/32 __RULES__ 0: from all lookup local 10019: from all iif eth1 lookup 200 10020: from 10.200.0.0/24 lookup 200 32766: from all lookup main 32767: from all lookup default __ROUTES_MAIN__ default via 95.165.96.1 dev eth0 proto static src 95.165.105.4 10.71.100.0/24 dev eth2 proto kernel scope link src 10.71.100.2 10.200.0.0/24 dev eth1 proto kernel scope link src 10.200.0.2 10.201.0.0/24 dev eth3 proto kernel scope link src 10.201.0.2 10.250.100.0/24 via 10.71.100.1 dev eth2 proto static 95.165.96.0/20 dev eth0 proto kernel scope link src 95.165.105.4 95.211.68.119 via 95.165.96.1 dev eth0 proto static 178.215.227.13 via 95.165.96.1 dev eth0 proto static 192.71.27.64 via 95.165.96.1 dev eth0 proto static 192.121.163.235 via 95.165.96.1 dev eth0 proto static __TABLES__ TABLE:200 default dev vpn1 scope link 10.200.0.0/24 dev eth1 scope link src 10.200.0.2 10.201.0.0/24 dev eth3 scope link src 10.201.0.2 TABLE:201 TABLE:202 TABLE:203 TABLE:204 TABLE:205 __CRON__ # STEP_029C1_DISABLED * * * * * /usr/bin/vpn-egress-manager.sh >/dev/null 2>&1 # STEP_029C1_DISABLED 20 4 * * * /root/hmn/hmn-refresh-pool-cron.sh # STEP_029C1_DISABLED 7,22,37,52 * * * * /root/hmn/hmn-pool-low-watermark-check.sh run >/dev/null 2>&1 # STEP_029C1_DISABLED 5,35 * * * * /root/hmn/hmn-refresh-retry-cron.sh # STEP_029C1_DISABLED 10 3 * * * /root/hmn/hmn-clean-old-files.sh >/dev/null 2>&1 # STEP_029C1_DISABLED * * * * * /root/hmn/hmn-vpn-user-override.sh tick >/dev/null 2>&1 __HOTPLUG__ drwxr-xr-x 2 root root 4096 Jul 8 08:35 . drwxr-xr-x 10 root root 4096 Apr 20 11:42 .. -rw-r--r-- 1 root root 155 Jun 23 2025 00-netstate -rw-r--r-- 1 root root 498 Jun 23 2025 20-firewall __PROCESSES__ __FIREWALL__ firewall.@zone[3].name='vpn_in' firewall.@zone[3].network='vpn_in' firewall.@zone[4].name='vpn_out' firewall.@zone[4].network='vpn1' 'vpn2' 'vpn_user' firewall.@rule[7].name='Allow-ICMP-from-vpn_in-to-router' firewall.@rule[7].src='vpn_in' firewall.@forwarding[0]=forwarding firewall.@forwarding[0].src='direct_in' firewall.@forwarding[0].dest='wan' firewall.@forwarding[1]=forwarding firewall.@forwarding[1].src='vpn_in' firewall.@forwarding[1].dest='vpn_out' firewall.@forwarding[2]=forwarding firewall.@forwarding[2].src='vpn_in' firewall.@forwarding[2].dest='wan' __UCI_NETWORK_SAFE__ IFACE:vpn1 proto=amneziawg auto=0 disabled=0 addresses=10.91.233.132/32 hmn_role=active_spare_slot hmn_endpoint=178.215.227.13:44408 IFACE:vpn2 proto=amneziawg auto=0 disabled=0 addresses=10.86.108.200/32 hmn_role=active_spare_slot hmn_endpoint=192.121.163.235:42530 IFACE:vpn3 IFACE:vpn4 IFACE:vpn5 IFACE:vpn_user proto=amneziawg auto=0 disabled=0 addresses=10.90.235.244/32 hmn_role=user_select_slot hmn_endpoint=37.235.54.96:38971 IFACE:vpn_test proto=amneziawg auto=0 disabled=0 addresses=10.67.234.5/32 hmn_role=test_slot hmn_endpoint=192.71.27.64:40044 ################################################################ ### PREFLIGHT RESULT ################################################################ remote_check_rc=0 config_files_ok=YES slot_count=5 unique_config_files=5 PREFLIGHT_DECISION=PASS_READONLY Next safe step: generate an apply plan package, still without applying.