Network Map
Name → internal host → VLAN → path intent, for every name CertVault tracks for tenant jtnt. Built for janus-sow.md J6/J7 (C-10, G-1): before this page, this map existed in no file, table, or GUI anywhere in the estate.
edge_routes/certificates tables on janus — all read-only. It does not auto-refresh. Wiring it to a live source (CertVault's API, re-run on a schedule) is follow-on work, not done here. VLAN **names/IDs** for the two HQ subnets were not found in any document or queried live from the MikroTik in this pass — shown as bare subnets rather than invented.Tracked names
Flagged rows: no internal answer where an external answer and/or a live edge route imply one is intended (the exact case J6/J7's acceptance describes), or no answer at all.
What this page does not cover
The full J6 acceptance also covers controlling the MikroTik edge (NAT, port-forwards, routing, WireGuard peers/allowed-IPs) through /opt/mikrotik-mcp, live hairpin detection, and the coturn allowed-peer-ip fix (/16 → documented /24, RFC1918 denies restored). None of that is done by this page — it is a read-only name/host/VLAN/intent register, which is what this lane was scoped to build. The edge-device changes are a separate, higher-blast-radius piece of work.