Manager's WireGuard tunnel read-only; manager's own SSH logins left out of Events (v0.34.0)
#205: the WireGuard tunnel the manager reaches a device through is left
alone from here. The page marks it Protected, says why, and shows it and
every peer on it read-only: no switch-off, edit or delete, no adding
peers. The API refuses any write to that interface or its peers, including
moving another peer onto it. The peer carrying the manager is marked
Manager (Maybe manager where the device doesn't track connections, in
which case the tunnel is still protected). This replaces 0.33.0's mix of
refusing some changes and guarding others.
#238: the manager's own SSH sessions (backups, commands, terminal) no
longer fill Events: "publickey accepted" lines with the fingerprint of the
key the manager deployed to that device, and "logged in/out ... via ssh"
for the manager's SSH account from the manager's own address. Anyone
else's SSH login is kept.
Also: removing a firmware mirror deletes the manager's cached packages
for versions no other mirror holds; pg 8.23.1 (Dependabot #237).
Docs: change-guard.md (The manager's WireGuard tunnel), alerting.md (The
manager's own sessions).
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.34.0-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.34.0-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/