Sure, since "bootstrapped" is slightly overloaded, I'll post all the configs that could be referring to. Some of these contain passwords, I'm not worried about it since those get regenerated on every install cycle.
Right after install, this is the config on the hEX:
/interface/vlan/add comment="Bootstrap Interface" interface=ether2 name=bootstrap0 vlan-id=2
/ip/address/add address=100.64.1.1/24 interface=bootstrap0
/certificate
add name=ca common-name=local_ca key-usage=key-cert-sign
add name=self common-name=localhost
sign ca
sign self
/ip service
set www disabled=no
set www-ssl certificate=self disabled=no
/user/group/add name=readonly policy=read,ssh,web
/user/add name=gizmo-fms group=full password=36db8f0f067949e9be38ff023ed0c56b
/user/add name=gizmo-ro group=readonly password=AmicablyStrewnDial
And this is the config on the hAP
/ip/dhcp-client/add interface=ether1 disabled=no
/certificate
add name=ca common-name=local_ca key-usage=key-cert-sign
add name=self common-name=localhost
sign ca
sign self
/ip service
set www disabled=no
set www-ssl certificate=self disabled=no
/user/group/add name=readonly policy=read,ssh,web
/user/add name=gizmo-fms group=full password=36db8f0f067949e9be38ff023ed0c56b
/user/add name=gizmo-ro group=readonly password=AmicablyStrewnDial
After applying the terraform with a special bootstrap flag which prevents certain firewall rules from locking me out until all are applied (which is why the drop all rule is disabled), this is the config on the hEX:
# 1970-01-02 00:24:17 by RouterOS 7.14.2
# software id = LIBF-JR99
#
# model = RB750UPr2
# serial number = HFE090F2A1Z
/interface bridge
add frame-types=admit-only-vlan-tagged ingress-filtering=no name=br0 \
vlan-filtering=yes
/interface vlan
add comment="Bootstrap Interface" interface=ether2 name=bootstrap0 vlan-id=2
add comment="FMS Network" interface=br0 name=fms0 vlan-id=10
add comment="Peer Networks" interface=br0 name=peer0 vlan-id=30
add comment=team451 interface=br0 name=team451 vlan-id=500
add comment=team452 interface=br0 name=team452 vlan-id=501
add comment=team453 interface=br0 name=team453 vlan-id=502
add comment=team454 interface=br0 name=team454 vlan-id=503
add comment=team455 interface=br0 name=team455 vlan-id=504
add comment=team456 interface=br0 name=team456 vlan-id=505
add comment=team457 interface=br0 name=team457 vlan-id=506
add comment=team458 interface=br0 name=team458 vlan-id=507
add comment=team459 interface=br0 name=team459 vlan-id=508
add comment=team460 interface=br0 name=team460 vlan-id=509
add comment=team461 interface=br0 name=team461 vlan-id=510
add comment=team462 interface=br0 name=team462 vlan-id=511
add comment=team463 interface=br0 name=team463 vlan-id=512
add comment=team464 interface=br0 name=team464 vlan-id=513
add comment=team465 interface=br0 name=team465 vlan-id=514
add comment=team466 interface=br0 name=team466 vlan-id=515
add comment=team467 interface=br0 name=team467 vlan-id=516
add comment=team468 interface=br0 name=team468 vlan-id=517
add comment=team469 interface=br0 name=team469 vlan-id=518
add comment=team470 interface=br0 name=team470 vlan-id=519
add comment=team471 interface=br0 name=team471 vlan-id=520
add comment="Upstream Networks" interface=br0 name=wan0 vlan-id=20
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/ip pool
add comment=team457 name=team457 ranges=10.4.57.2-10.4.57.10
add comment="FMS Default IP Pool" name=fms ranges=100.64.0.1-100.64.0.30
add comment=team464 name=team464 ranges=10.4.64.2-10.4.64.10
add comment=team458 name=team458 ranges=10.4.58.2-10.4.58.10
add comment=team456 name=team456 ranges=10.4.56.2-10.4.56.10
add comment=team452 name=team452 ranges=10.4.52.2-10.4.52.10
add comment=team471 name=team471 ranges=10.4.71.2-10.4.71.10
add comment=team470 name=team470 ranges=10.4.70.2-10.4.70.10
add comment=team451 name=team451 ranges=10.4.51.2-10.4.51.10
add comment=team460 name=team460 ranges=10.4.60.2-10.4.60.10
add comment=team466 name=team466 ranges=10.4.66.2-10.4.66.10
add comment=team467 name=team467 ranges=10.4.67.2-10.4.67.10
add comment=team459 name=team459 ranges=10.4.59.2-10.4.59.10
add comment=team465 name=team465 ranges=10.4.65.2-10.4.65.10
add comment=team462 name=team462 ranges=10.4.62.2-10.4.62.10
add comment=team468 name=team468 ranges=10.4.68.2-10.4.68.10
add comment=team461 name=team461 ranges=10.4.61.2-10.4.61.10
add comment=team454 name=team454 ranges=10.4.54.2-10.4.54.10
add comment=team469 name=team469 ranges=10.4.69.2-10.4.69.10
add comment=team455 name=team455 ranges=10.4.55.2-10.4.55.10
add comment=team453 name=team453 ranges=10.4.53.2-10.4.53.10
add comment=team463 name=team463 ranges=10.4.63.2-10.4.63.10
/ip dhcp-server
add address-pool=fms comment="FMS Default DHCP Server" interface=fms0 \
lease-time=10m name=FMS
add address-pool=team462 comment=team462 interface=team462 lease-time=10m \
name=team462
add address-pool=team468 comment=team468 interface=team468 lease-time=10m \
name=team468
add address-pool=team457 comment=team457 interface=team457 lease-time=10m \
name=team457
add address-pool=team470 comment=team470 interface=team470 lease-time=10m \
name=team470
add address-pool=team471 comment=team471 interface=team471 lease-time=10m \
name=team471
add address-pool=team453 comment=team453 interface=team453 lease-time=10m \
name=team453
add address-pool=team469 comment=team469 interface=team469 lease-time=10m \
name=team469
add address-pool=team456 comment=team456 interface=team456 lease-time=10m \
name=team456
add address-pool=team463 comment=team463 interface=team463 lease-time=10m \
name=team463
add address-pool=team459 comment=team459 interface=team459 lease-time=10m \
name=team459
add address-pool=team464 comment=team464 interface=team464 lease-time=10m \
name=team464
add address-pool=team460 comment=team460 interface=team460 lease-time=10m \
name=team460
add address-pool=team467 comment=team467 interface=team467 lease-time=10m \
name=team467
add address-pool=team452 comment=team452 interface=team452 lease-time=10m \
name=team452
add address-pool=team465 comment=team465 interface=team465 lease-time=10m \
name=team465
add address-pool=team461 comment=team461 interface=team461 lease-time=10m \
name=team461
add address-pool=team455 comment=team455 interface=team455 lease-time=10m \
name=team455
add address-pool=team454 comment=team454 interface=team454 lease-time=10m \
name=team454
add address-pool=team451 comment=team451 interface=team451 lease-time=10m \
name=team451
add address-pool=team458 comment=team458 interface=team458 lease-time=10m \
name=team458
add address-pool=team466 comment=team466 interface=team466 lease-time=10m \
name=team466
/user group
add name=readonly policy="ssh,read,web,!local,!telnet,!ftp,!reboot,!write,!pol\
icy,!test,!winbox,!password,!sniff,!sensitive,!api,!romon,!rest-api"
/interface bridge port
add bridge=br0 interface=ether3 internal-path-cost=10 path-cost=10 pvid=10
add bridge=br0 interface=ether1 internal-path-cost=10 path-cost=10 pvid=20
add bridge=br0 comment="Upstream Networks" interface=wan0 internal-path-cost=\
10 path-cost=10 pvid=20
add bridge=br0 interface=ether4 internal-path-cost=10 path-cost=10 pvid=10
add bridge=br0 interface=ether5 internal-path-cost=10 path-cost=10 pvid=10
add bridge=br0 interface=ether2 internal-path-cost=10 path-cost=10 pvid=10
add bridge=br0 comment="Peer Networks" interface=peer0 internal-path-cost=10 \
path-cost=10 pvid=30
add bridge=br0 comment="FMS Network" interface=fms0 internal-path-cost=10 \
path-cost=10 pvid=10
add bridge=br0 comment=team462 interface=team462 internal-path-cost=10 \
path-cost=10 pvid=511
add bridge=br0 comment=team452 interface=team452 internal-path-cost=10 \
path-cost=10 pvid=501
add bridge=br0 comment=team459 interface=team459 internal-path-cost=10 \
path-cost=10 pvid=508
add bridge=br0 comment=team466 interface=team466 internal-path-cost=10 \
path-cost=10 pvid=515
add bridge=br0 comment=team463 interface=team463 internal-path-cost=10 \
path-cost=10 pvid=512
add bridge=br0 comment=team469 interface=team469 internal-path-cost=10 \
path-cost=10 pvid=518
add bridge=br0 comment=team455 interface=team455 internal-path-cost=10 \
path-cost=10 pvid=504
add bridge=br0 comment=team465 interface=team465 internal-path-cost=10 \
path-cost=10 pvid=514
add bridge=br0 comment=team456 interface=team456 internal-path-cost=10 \
path-cost=10 pvid=505
add bridge=br0 comment=team461 interface=team461 internal-path-cost=10 \
path-cost=10 pvid=510
add bridge=br0 comment=team457 interface=team457 internal-path-cost=10 \
path-cost=10 pvid=506
add bridge=br0 comment=team464 interface=team464 internal-path-cost=10 \
path-cost=10 pvid=513
add bridge=br0 comment=team458 interface=team458 internal-path-cost=10 \
path-cost=10 pvid=507
add bridge=br0 comment=team467 interface=team467 internal-path-cost=10 \
path-cost=10 pvid=516
add bridge=br0 comment=team470 interface=team470 internal-path-cost=10 \
path-cost=10 pvid=519
add bridge=br0 comment=team468 interface=team468 internal-path-cost=10 \
path-cost=10 pvid=517
add bridge=br0 comment=team460 interface=team460 internal-path-cost=10 \
path-cost=10 pvid=509
add bridge=br0 comment=team454 interface=team454 internal-path-cost=10 \
path-cost=10 pvid=503
add bridge=br0 comment=team471 interface=team471 internal-path-cost=10 \
path-cost=10 pvid=520
add bridge=br0 comment=team451 interface=team451 internal-path-cost=10 \
path-cost=10 pvid=500
add bridge=br0 comment=team453 interface=team453 internal-path-cost=10 \
path-cost=10 pvid=502
/interface bridge vlan
add bridge=br0 untagged=ether2 vlan-ids=10
add bridge=br0 tagged=ether1 vlan-ids=30
add bridge=br0 untagged=ether1 vlan-ids=20
add bridge=br0 comment="Bridge Networks" tagged=br0 vlan-ids="10,20,30,500,501\
,502,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,5\
20"
add bridge=br0 tagged="team451,team452,team453,team454,team455,team456,team457\
,team458,team459,team460,team461,team462,team463,team464,team465,team466,t\
eam467,team468,team469,team470,team471,ether3,ether4,ether5" vlan-ids="500\
,501,502,503,504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,5\
19,520"
/ip address
add address=100.64.1.1/24 interface=bootstrap0 network=100.64.1.0
add address=100.64.0.1/24 interface=fms0 network=100.64.0.0
add address=10.4.56.1/24 interface=team456 network=10.4.56.0
add address=10.4.67.1/24 interface=team467 network=10.4.67.0
add address=10.4.61.1/24 interface=team461 network=10.4.61.0
add address=10.4.64.1/24 interface=team464 network=10.4.64.0
add address=10.4.52.1/24 interface=team452 network=10.4.52.0
add address=10.4.51.1/24 interface=team451 network=10.4.51.0
add address=10.4.54.1/24 interface=team454 network=10.4.54.0
add address=10.4.71.1/24 interface=team471 network=10.4.71.0
add address=10.4.68.1/24 interface=team468 network=10.4.68.0
add address=10.4.69.1/24 interface=team469 network=10.4.69.0
add address=10.4.63.1/24 interface=team463 network=10.4.63.0
add address=10.4.58.1/24 interface=team458 network=10.4.58.0
add address=10.4.62.1/24 interface=team462 network=10.4.62.0
add address=10.4.60.1/24 interface=team460 network=10.4.60.0
add address=10.4.70.1/24 interface=team470 network=10.4.70.0
add address=10.4.66.1/24 interface=team466 network=10.4.66.0
add address=10.4.53.1/24 interface=team453 network=10.4.53.0
add address=10.4.65.1/24 interface=team465 network=10.4.65.0
add address=10.4.59.1/24 interface=team459 network=10.4.59.0
add address=10.4.55.1/24 interface=team455 network=10.4.55.0
add address=10.4.57.1/24 interface=team457 network=10.4.57.0
/ip dhcp-client
add comment="External Upstream" interface=wan0 use-peer-dns=no use-peer-ntp=\
no
/ip dhcp-server lease
add address=100.64.0.10 comment="Field 1" mac-address=78:9A:18:7E:54:5D \
server=FMS
/ip dhcp-server network
add address=10.4.51.0/24 comment=team451 dns-server=10.4.51.1 gateway=\
10.4.51.1
add address=10.4.52.0/24 comment=team452 dns-server=10.4.52.1 gateway=\
10.4.52.1
add address=10.4.53.0/24 comment=team453 dns-server=10.4.53.1 gateway=\
10.4.53.1
add address=10.4.54.0/24 comment=team454 dns-server=10.4.54.1 gateway=\
10.4.54.1
add address=10.4.55.0/24 comment=team455 dns-server=10.4.55.1 gateway=\
10.4.55.1
add address=10.4.56.0/24 comment=team456 dns-server=10.4.56.1 gateway=\
10.4.56.1
add address=10.4.57.0/24 comment=team457 dns-server=10.4.57.1 gateway=\
10.4.57.1
add address=10.4.58.0/24 comment=team458 dns-server=10.4.58.1 gateway=\
10.4.58.1
add address=10.4.59.0/24 comment=team459 dns-server=10.4.59.1 gateway=\
10.4.59.1
add address=10.4.60.0/24 comment=team460 dns-server=10.4.60.1 gateway=\
10.4.60.1
add address=10.4.61.0/24 comment=team461 dns-server=10.4.61.1 gateway=\
10.4.61.1
add address=10.4.62.0/24 comment=team462 dns-server=10.4.62.1 gateway=\
10.4.62.1
add address=10.4.63.0/24 comment=team463 dns-server=10.4.63.1 gateway=\
10.4.63.1
add address=10.4.64.0/24 comment=team464 dns-server=10.4.64.1 gateway=\
10.4.64.1
add address=10.4.65.0/24 comment=team465 dns-server=10.4.65.1 gateway=\
10.4.65.1
add address=10.4.66.0/24 comment=team466 dns-server=10.4.66.1 gateway=\
10.4.66.1
add address=10.4.67.0/24 comment=team467 dns-server=10.4.67.1 gateway=\
10.4.67.1
add address=10.4.68.0/24 comment=team468 dns-server=10.4.68.1 gateway=\
10.4.68.1
add address=10.4.69.0/24 comment=team469 dns-server=10.4.69.1 gateway=\
10.4.69.1
add address=10.4.70.0/24 comment=team470 dns-server=10.4.70.1 gateway=\
10.4.70.1
add address=10.4.71.0/24 comment=team471 dns-server=10.4.71.1 gateway=\
10.4.71.1
add address=100.64.0.0/24 comment="Options for FMS" dns-server=100.64.0.1 \
domain=gizmo gateway=100.64.0.1
/ip firewall address-list
add address=127.0.53.53 comment="Name collision occurence" list=bogons_v4
add address=100.64.0.0/24 comment="NAT Source Pool" list=nat_sources
add address=192.168.0.0/16 comment=RFC1918 list=bogons_v4
add address=0.0.0.0/8 comment="'This' network" list=bogons_v4
add address=240.0.0.0/4 comment="Reserved for future use" list=bogons_v4
add address=127.0.0.0/8 comment=Loopback list=bogons_v4
add address=255.255.255.255 comment="Limited Broadcast" list=bogons_v4
add address=203.0.113.0/24 comment=TEST-NET-3 list=bogons_v4
add address=192.0.2.0/24 comment=TEST-NET-1 list=bogons_v4
add address=192.0.0.0/24 comment="IETF Protocol Assignments" list=bogons_v4
add address=172.16.0.0/12 comment=RFC1918 list=bogons_v4
add address=198.51.100.0/24 comment=TEST-NET-2 list=bogons_v4
add address=100.64.0.0/10 comment=CG-NAT list=bogons_v4
add address=198.18.0.0/15 comment=\
"Network interconect device benchmark testing" list=bogons_v4
add address=169.254.0.0/16 comment="Link Local" list=bogons_v4
add address=224.0.0.0/4 comment=Multicast list=bogons_v4
add address=10.0.0.0/8 comment=RFC1918 list=bogons_v4
/ip firewall filter
add action=accept chain=input comment=accept-established connection-state=\
established,related,untracked
add action=accept chain=input in-interface=peer0
add action=drop chain=input comment=drop-invalid connection-state=invalid
add action=accept chain=input protocol=icmp
add action=drop chain=input comment=deny-bogons-to-self in-interface=wan0 \
src-address-list=bogons_v4
add action=drop chain=input comment=default-deny in-interface=!fms0
/ip firewall nat
add action=masquerade chain=srcnat comment=nat-masquerade out-interface=wan0 \
src-address-list=nat_sources
/ip service
set telnet disabled=yes port=21
set ftp disabled=yes
set www disabled=yes
set www-ssl certificate=self disabled=no
set api disabled=yes port=8278
set winbox disabled=yes
set api-ssl disabled=yes
/system identity
set name=gizmo-edge
/system note
set show-at-login=no
Immediately prior to losing communication with the hAP, the configuration is as follows:
# 1970-01-02 00:11:44 by RouterOS 7.14.2
# software id = 1J90-DG0X
#
# model = RB952Ui-5ac2nD
# serial number = HF6090SBZFK
/interface bridge
add frame-types=admit-only-vlan-tagged ingress-filtering=no name=br0 \
vlan-filtering=yes
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
set [ find default-name=wlan2 ] ssid=MikroTik
/interface vlan
add comment=team451 interface=br0 name=team451 vlan-id=500
add comment=team452 interface=br0 name=team452 vlan-id=501
add comment=team453 interface=br0 name=team453 vlan-id=502
add comment=team454 interface=br0 name=team454 vlan-id=503
add comment=team455 interface=br0 name=team455 vlan-id=504
add comment=team456 interface=br0 name=team456 vlan-id=505
add comment=team457 interface=br0 name=team457 vlan-id=506
add comment=team458 interface=br0 name=team458 vlan-id=507
add comment=team459 interface=br0 name=team459 vlan-id=508
add comment=team460 interface=br0 name=team460 vlan-id=509
add comment=team461 interface=br0 name=team461 vlan-id=510
add comment=team462 interface=br0 name=team462 vlan-id=511
add comment=team463 interface=br0 name=team463 vlan-id=512
add comment=team464 interface=br0 name=team464 vlan-id=513
add comment=team465 interface=br0 name=team465 vlan-id=514
add comment=team466 interface=br0 name=team466 vlan-id=515
add comment=team467 interface=br0 name=team467 vlan-id=516
add comment=team468 interface=br0 name=team468 vlan-id=517
add comment=team469 interface=br0 name=team469 vlan-id=518
add comment=team470 interface=br0 name=team470 vlan-id=519
add comment=team471 interface=br0 name=team471 vlan-id=520
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/user group
add name=readonly policy="ssh,read,web,!local,!telnet,!ftp,!reboot,!write,!pol\
icy,!test,!winbox,!password,!sniff,!sensitive,!api,!romon,!rest-api"
/interface bridge port
add bridge=br0 interface=ether3 internal-path-cost=10 path-cost=10 pvid=500
add bridge=br0 interface=ether5 internal-path-cost=10 path-cost=10 pvid=500
add bridge=br0 interface=ether4 internal-path-cost=10 path-cost=10 pvid=500
add bridge=br0 interface=ether2 internal-path-cost=10 path-cost=10 pvid=500
add bridge=br0 comment=team457 interface=team457 internal-path-cost=10 \
path-cost=10 pvid=506
add bridge=br0 comment=team468 interface=team468 internal-path-cost=10 \
path-cost=10 pvid=517
add bridge=br0 comment=team462 interface=team462 internal-path-cost=10 \
path-cost=10 pvid=511
add bridge=br0 comment=team456 interface=team456 internal-path-cost=10 \
path-cost=10 pvid=505
add bridge=br0 comment=team460 interface=team460 internal-path-cost=10 \
path-cost=10 pvid=509
add bridge=br0 comment=team453 interface=team453 internal-path-cost=10 \
path-cost=10 pvid=502
add bridge=br0 comment=team455 interface=team455 internal-path-cost=10 \
path-cost=10 pvid=504
add bridge=br0 comment=team451 interface=team451 internal-path-cost=10 \
path-cost=10 pvid=500
add bridge=br0 comment=team466 interface=team466 internal-path-cost=10 \
path-cost=10 pvid=515
add bridge=br0 comment=team471 interface=team471 internal-path-cost=10 \
path-cost=10 pvid=520
add bridge=br0 comment=team452 interface=team452 internal-path-cost=10 \
path-cost=10 pvid=501
add bridge=br0 comment=team458 interface=team458 internal-path-cost=10 \
path-cost=10 pvid=507
add bridge=br0 comment=team459 interface=team459 internal-path-cost=10 \
path-cost=10 pvid=508
add bridge=br0 comment=team470 interface=team470 internal-path-cost=10 \
path-cost=10 pvid=519
add bridge=br0 comment=team454 interface=team454 internal-path-cost=10 \
path-cost=10 pvid=503
add bridge=br0 comment=team464 interface=team464 internal-path-cost=10 \
path-cost=10 pvid=513
add bridge=br0 comment=team467 interface=team467 internal-path-cost=10 \
path-cost=10 pvid=516
add bridge=br0 comment=team469 interface=team469 internal-path-cost=10 \
path-cost=10 pvid=518
add bridge=br0 comment=team465 interface=team465 internal-path-cost=10 \
path-cost=10 pvid=514
add bridge=br0 comment=team461 interface=team461 internal-path-cost=10 \
path-cost=10 pvid=510
add bridge=br0 comment=team463 interface=team463 internal-path-cost=10 \
path-cost=10 pvid=512
/interface bridge vlan
add bridge=br0 comment="Bridge Networks" tagged=br0 vlan-ids="500,501,502,503,\
504,505,506,507,508,509,510,511,512,513,514,515,516,517,518,519,520"
add bridge=br0 tagged="team451,team452,team453,team454,team455,team456,team457\
,team458,team459,team460,team461,team462,team463,team464,team465,team466,t\
eam467,team468,team469,team470,team471" vlan-ids="500,501,502,503,504,505,\
506,507,508,509,510,511,512,513,514,515,516,517,518,519,520"
/ip dhcp-client
add interface=ether1
/ip service
set telnet disabled=yes port=21
set ftp disabled=yes
set www disabled=yes
set www-ssl certificate=self disabled=no
set api disabled=yes port=8278
set winbox disabled=yes
set api-ssl disabled=yes
/system identity
set name=gizmo-field-1
/system note
set show-at-login=no
These configs are from the hEX having a special bootstrap0 interface that can be reached over vlan 2, and the hAP being accessible via ether1 directly.