unkin-agent 0272104504 Add wireguard module (#538)
WireGuard on the router is configured by hand, so its tunnels are not reproducible from code. This adds a module to manage it from hieradata.

- add `wireguard` class to install wireguard-tools and manage interfaces from a hash
- add `wireguard::interface` to render `/etc/wireguard/<iface>.conf` (0600) and enable `wg-quick@<iface>`
- keep private and preshared keys `Sensitive` end to end (`wireguard::interfaces` lookup_options `convert_to: Sensitive`, typed peer Struct)
- without `private_key`, generate `/etc/wireguard/<iface>.key` (0600) only if absent and load it via PostUp, so the key never rotates
- apply config changes with `wg syncconf` instead of restarting the tunnel

Reviewed-on: #538
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-04 14:17:07 +11:00
2026-03-17 17:38:22 +11:00
2026-02-03 19:56:14 +11:00
2026-10-04 14:17:07 +11:00
2023-07-02 14:21:09 +10:00
2026-10-04 14:17:07 +11:00
2023-06-21 22:03:43 +10:00
2025-07-08 20:19:36 +10:00
2024-02-17 22:57:36 +11:00
S
Description
production puppet-control repository
3.9 MiB
Languages
Puppet 66.5%
HTML 27.6%
Ruby 5.9%