0272104504
WireGuard on the router is configured by hand, so its tunnels are not reproducible from code. This adds a module to manage it from hieradata. - add `wireguard` class to install wireguard-tools and manage interfaces from a hash - add `wireguard::interface` to render `/etc/wireguard/<iface>.conf` (0600) and enable `wg-quick@<iface>` - keep private and preshared keys `Sensitive` end to end (`wireguard::interfaces` lookup_options `convert_to: Sensitive`, typed peer Struct) - without `private_key`, generate `/etc/wireguard/<iface>.key` (0600) only if absent and load it via PostUp, so the key never rotates - apply config changes with `wg syncconf` instead of restarting the tunnel Reviewed-on: #538 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
32 lines
757 B
Plaintext
32 lines
757 B
Plaintext
# THIS FILE IS MANAGED BY PUPPET
|
|
[Interface]
|
|
<% @addresses.each do |addr| -%>
|
|
Address = <%= addr %>
|
|
<% end -%>
|
|
<% if @listen_port -%>
|
|
ListenPort = <%= @listen_port %>
|
|
<% end -%>
|
|
<% if @mtu -%>
|
|
MTU = <%= @mtu %>
|
|
<% end -%>
|
|
<% if @key -%>
|
|
PrivateKey = <%= @key %>
|
|
<% else -%>
|
|
PostUp = wg set %i private-key /etc/wireguard/%i.key
|
|
<% end -%>
|
|
<% @peers.each do |peer| -%>
|
|
|
|
[Peer]
|
|
PublicKey = <%= peer['public_key'] %>
|
|
<% if peer['preshared_key'] -%>
|
|
PresharedKey = <%= peer['preshared_key'].unwrap %>
|
|
<% end -%>
|
|
AllowedIPs = <%= Array(peer['allowed_ips']).join(', ') %>
|
|
<% if peer['endpoint'] -%>
|
|
Endpoint = <%= peer['endpoint'] %>
|
|
<% end -%>
|
|
<% if peer['persistent_keepalive'] -%>
|
|
PersistentKeepalive = <%= peer['persistent_keepalive'] %>
|
|
<% end -%>
|
|
<% end -%>
|