6f5fb19a64
Peersync script: validate-first (jq contract check before ANY state change), head-file + generated-peers conf model, syncconf-from-tmp then atomic mv (live conf never diverges in the failure direction), zero-peer payload valid (wipe). hub.yaml: 0.32.0 image + WG_ENDPOINT_SSH_* env + optional Secret mount so the pod starts before the runbook's step-6 Secret exists. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6