02721045044a3319f0489879b06646f8542eb8b5
WireGuard on the router is configured by hand, so its tunnels are not reproducible from code. This adds a module to manage it from hieradata. - add `wireguard` class to install wireguard-tools and manage interfaces from a hash - add `wireguard::interface` to render `/etc/wireguard/<iface>.conf` (0600) and enable `wg-quick@<iface>` - keep private and preshared keys `Sensitive` end to end (`wireguard::interfaces` lookup_options `convert_to: Sensitive`, typed peer Struct) - without `private_key`, generate `/etc/wireguard/<iface>.key` (0600) only if absent and load it via PostUp, so the key never rotates - apply config changes with `wg syncconf` instead of restarting the tunnel Reviewed-on: #538 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
Description
production puppet-control repository
Languages
Puppet
66.5%
HTML
27.6%
Ruby
5.9%