# manage one wg-quick interface; without private_key, the existing /etc/wireguard/.key is loaded via PostUp define wireguard::interface ( Array[Stdlib::IP::Address] $addresses, Optional[Stdlib::Port] $listen_port = undef, Optional[Integer[1280, 9000]] $mtu = undef, Optional[Variant[String, Sensitive[String]]] $private_key = undef, Array[Hash] $peers = [], ) { $conf = "/etc/wireguard/${name}.conf" $key = $private_key ? { Sensitive => $private_key.unwrap, default => $private_key, } file { $conf: ensure => file, owner => 'root', group => 'root', mode => '0600', content => Sensitive(template('wireguard/wg.conf.erb')), show_diff => false, notify => Exec["wireguard_syncconf_${name}"], } service { "wg-quick@${name}": ensure => running, enable => true, require => File[$conf], } # syncconf applies peer/key changes without bouncing the tunnel; address/mtu changes need a manual restart exec { "wireguard_syncconf_${name}": command => "/bin/bash -c 'wg syncconf ${name} <(wg-quick strip ${name})'", onlyif => "/usr/sbin/ip link show ${name}", path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'], refreshonly => true, require => Service["wg-quick@${name}"], } }