Doc/code drift: the partner-network design (and downstream docs like site-types.md) describes the partner-managed guard pattern as guard_type: partner (generic, the correct long-term name). The hydraguard CLI / API still requires --guard citymesh and rejects partner:
hydraguard/pkg/api/handlers.go:497
return fmt.Errorf("invalid guard_type: must be omada, citymesh, linuxvm, or gateway")
Footnoted in 3 docs today (partner-network-design.md, site-types.md, citymesh-venue.md), but the underlying rename is not done.
partner as the canonical value in pkg/api/handlers.go validation, with citymesh kept as an accepted alias for back-compat with existing mesh.yaml files in the wild.internal/cli/venue.go to list partner first.mesh.yaml on the Brussels hub from citymesh → partner (one-time edit; auto-backup #1 covers the rollback if needed).partner vs citymesh footnote from partner-network-design.md, site-types.md, citymesh-venue.md once the code accepts the canonical name.Keep citymesh-venue.md filename as-is (or rename to partner-venue.md — bikeshed).
hydraguard venue add foo --guard partner succeeds.guard_type: citymesh in mesh.yaml still load and apply.