Finish the GL.iNet work that remains after the backend shipped and the Slate 7 Pro went live. Carried out of #516, which is closed as implemented. The Omada decommission is a separate ticket: #535. Background: #516 (backend + rollout), #517 (device API verification), #522 (mesh tunnel bring-up), hydraneck/docs/runbooks/glinet.md (the full device picture).
sint-niklaas-tourism-office (mesh address 10.10.5.1, "4.8.4 (GL.iNet GL-BE10000)").wgclient1 plus /usr/bin/hydra-wg-up.sh, and survives reboots.hydraneck wg setup (config CRUD over the JSON-RPC API) works. hydraneck wg on|off is broken on firmware 4.8+ and wg status reports the tunnel as down even when it is up.Firmware 4.8+ removed wg-client start, stop, and get_status from the JSON-RPC API. The replacement vpn-client module is the global-proxy engine and cannot do subnet-selective routing; it must not be used. The reliable control surface is SSH (dropbear, port 22, root + admin password, the documented fallback).
pkg/glinet (golang.org/x/crypto/ssh; password auth with the same secret the JSON-RPC client uses).EnableWireGuard: ifup wgclient1 (the on-device hydra-wg-up.sh logic re-adds address and routes). DisableWireGuard: ifdown wgclient1.WireGuardUp: parse wg show wgclient1 (handshake present = up). Fixes the false "down" from the missing service entry in system get_status./usr/bin/hydra-wg-up.sh: install and update it over SSH so the tunnel bootstrap is reproducible on the next device, not hand-installed (#522 installed it manually).access: write.docs/runbooks/glinet.md and CLAUDE.md: remove the "broken on 4.8+" caveats once wg on|off work.