# balancer-lite-lua.dlog — Deployment Log ## 2026-09-04 Initial Prototype ### What Created new workspace project `balancer-lite-lua/` for OpenWrt 22.03 Lua 5.1 port of balancer-lite's hysteresis watchdog, flap detection, signed webhook outbox, and retention store. Thin-layer only (~800–1000 LOC) — composes with mwan3/netifd rather than replacing them. ### Commit `09fad45` — "Initial Lua 5.1 prototype for OpenWrt 22.03" ### Files - `src/balancerlite/state.lua` — 8-state hysteresis machine (INIT, WAN_A/B_PRIMARY, SWITCHING_TO_A/B, DEGRADED, BOTH_DOWN) - `src/balancerlite/probes.lua` — ICMP/TCP/DNS health checks via ping/nc/nslookup subprocesses - `src/balancerlite/store.lua` — JSONL append-only event log + compaction - `src/balancerlite/outbox.lua` — Signed webhook retry queue with exponential backoff + circuit breaker - `src/balancerlite/sha256.lua` — SHA-256/HMAC-SHA256 via `openssl dgst` CLI - `src/balancerlite/config.lua` — UCI config file parser - `src/balancerlite/main.lua` — procd-compatible poll loop daemon - `src/balancerlite/json.lua` — Pure-Lua JSON encoder (JSON.stringify only) - `etc/init.d/balancerlite` — procd init script - `etc/config/balancerlite` — UCI config example - `Makefile` — lint + test targets - `tests/state.lua` — 8 state machine tests (all passing) - `tests/sha256.lua` — SHA-256 + HMAC-SHA256 test vectors (all passing) - `MEMORY.md`, `README.md` ### Test Results ``` lua5.1 tests/state.lua → PASS: state (8/8 tests) lua5.1 tests/sha256.lua → PASS: sha256 (3/3 vectors) ``` All modules pass `luac5.1 -p` (parse check). ### Verification Commands ```sh cd /root/.openclaw/workspace/balancer-lite-lua make test # runs all tests make lint # runs luac5.1 -p on all modules ``` ### Remote `https://git3.techno-world.net/lrosales/balancer-lite-lua.git` ⚠️ Repo does not exist yet on git3 — creation via Gogs API returned 401. Manual repo creation needed on https://git3.techno-world.net first. ### Notes - HMAC-SHA256 uses `openssl dgst -hmac` CLI (openssl-util package on OpenWrt 22.03) - No lua-crypto dependency; no raw sockets; all probes via subprocess - State machine verified against Go source: 8 states, same transition logic - SWITCHING_TO_* are one-drive-cycle intermediate states - BOTH_DOWN transitions directly to stable primary (no intermediate) - BOTH_DOWN clears switch_times (flap detection not counted during all-down) - DEGRADED entry: flap check counts #record_switch calls; needs `flap_threshold` of them ### Remaining Work 1. Create empty repo on git3.techno-world.net, then `git push -u origin master` 2. Write `src/balancerlite/routing.lua` (policy routing via `ip` commands) 3. Write `src/balancerlite/wg.lua` (WireGuard endpoint re-point via `wg set`) 4. Write `balancerlite-ctl` CLI tool (status/events/switch/compact) 5. Runtime test on `openwrt-testbed`