# manage one wg-quick interface; without private_key, /etc/wireguard/.key is generated once and loaded via PostUp define wireguard::interface ( Array[Stdlib::IP::Address] $addresses, Optional[Stdlib::Port] $listen_port = undef, Optional[Integer[1280, 9000]] $mtu = undef, Optional[Sensitive[String[1]]] $private_key = undef, Array[Struct[{ public_key => String[1], allowed_ips => Variant[String[1], Array[String[1], 1]], preshared_key => Optional[Sensitive[String[1]]], endpoint => Optional[String[1]], persistent_keepalive => Optional[Integer[0, 65535]], }]] $peers = [], ) { $conf = "/etc/wireguard/${name}.conf" $key = $private_key.then |$k| { $k.unwrap } if $private_key =~ Undef { $keyfile = "/etc/wireguard/${name}.key" exec { "wireguard_genkey_${name}": command => "/bin/sh -c 'umask 077; wg genkey > ${keyfile}'", creates => $keyfile, path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'], require => File['/etc/wireguard'], } file { $keyfile: ensure => file, owner => 'root', group => 'root', mode => '0600', require => Exec["wireguard_genkey_${name}"], before => [File[$conf], Service["wg-quick@${name}"]], } } file { $conf: ensure => file, owner => 'root', group => 'root', mode => '0600', content => Sensitive(template('wireguard/wg.conf.erb')), show_diff => false, notify => Exec["wireguard_syncconf_${name}"], } service { "wg-quick@${name}": ensure => running, enable => true, require => File[$conf], } # syncconf applies peer/key changes without bouncing the tunnel; address/mtu changes need a manual restart exec { "wireguard_syncconf_${name}": command => "/bin/bash -c 'wg syncconf ${name} <(wg-quick strip ${name})'", onlyif => "/usr/sbin/ip link show ${name}", path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'], refreshonly => true, require => Service["wg-quick@${name}"], } }