Add wireguard module #538
Reference in New Issue
Block a user
Delete Branch "benvin/wireguard-module"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
WireGuard on the router is configured by hand, so its tunnels are not reproducible from code. This adds a module to manage it from hieradata.
wireguardclass to install wireguard-tools and manage interfaces from a hashwireguard::interfaceto render/etc/wireguard/<iface>.conf(0600) and enablewg-quick@<iface>Sensitiveend to end (wireguard::interfaceslookup_optionsconvert_to: Sensitive, typed peer Struct)private_key, generate/etc/wireguard/<iface>.key(0600) only if absent and load it via PostUp, so the key never rotateswg syncconfinstead of restarting the tunnelVariant[String, Sensitive[String]]accepts a plain String, andpeersisArray[Hash](line 46) withpreshared_keyread from it, so eyaml-decrypted keys land as plaintext resource parameters in the catalog/PuppetDB (show_diff => falseon the file does not cover that) → typeprivate_keyasOptional[Sensitive[String]], and type peers asArray[Struct[{public_key => String[1], allowed_ips => Variant[String,Array[String]], preshared_key => Optional[Sensitive[String]], endpoint => Optional[String], persistent_keepalive => Optional[Integer]}]]with hiera lookup_optionsconvert_to: Sensitivefor the nested keysprivate_keyis unset, PostUp runswg set %i private-key /etc/wireguard/%i.key, but nothing checks or manages that file, so a missing key makeswg-quick@<iface>fail to start → add afile { "/etc/wireguard/${name}.key": ensure => file, mode => "0600", replace => false }(or anunless-style guard) so the dependency is explicitif @keyis true for an empty string, renderingPrivateKey =→ useString[1]in the typeNo findings.