0272104504
WireGuard on the router is configured by hand, so its tunnels are not reproducible from code. This adds a module to manage it from hieradata. - add `wireguard` class to install wireguard-tools and manage interfaces from a hash - add `wireguard::interface` to render `/etc/wireguard/<iface>.conf` (0600) and enable `wg-quick@<iface>` - keep private and preshared keys `Sensitive` end to end (`wireguard::interfaces` lookup_options `convert_to: Sensitive`, typed peer Struct) - without `private_key`, generate `/etc/wireguard/<iface>.key` (0600) only if absent and load it via PostUp, so the key never rotates - apply config changes with `wg syncconf` instead of restarting the tunnel Reviewed-on: #538 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
64 lines
2.1 KiB
Puppet
64 lines
2.1 KiB
Puppet
# manage one wg-quick interface; without private_key, /etc/wireguard/<iface>.key is generated once and loaded via PostUp
|
|
define wireguard::interface (
|
|
Array[Stdlib::IP::Address] $addresses,
|
|
Optional[Stdlib::Port] $listen_port = undef,
|
|
Optional[Integer[1280, 9000]] $mtu = undef,
|
|
Optional[Sensitive[String[1]]] $private_key = undef,
|
|
Array[Struct[{
|
|
public_key => String[1],
|
|
allowed_ips => Variant[String[1], Array[String[1], 1]],
|
|
preshared_key => Optional[Sensitive[String[1]]],
|
|
endpoint => Optional[String[1]],
|
|
persistent_keepalive => Optional[Integer[0, 65535]],
|
|
}]] $peers = [],
|
|
) {
|
|
|
|
$conf = "/etc/wireguard/${name}.conf"
|
|
$key = $private_key.then |$k| { $k.unwrap }
|
|
|
|
if $private_key =~ Undef {
|
|
$keyfile = "/etc/wireguard/${name}.key"
|
|
|
|
exec { "wireguard_genkey_${name}":
|
|
command => "/bin/sh -c 'umask 077; wg genkey > ${keyfile}'",
|
|
creates => $keyfile,
|
|
path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'],
|
|
require => File['/etc/wireguard'],
|
|
}
|
|
|
|
file { $keyfile:
|
|
ensure => file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0600',
|
|
require => Exec["wireguard_genkey_${name}"],
|
|
before => [File[$conf], Service["wg-quick@${name}"]],
|
|
}
|
|
}
|
|
|
|
file { $conf:
|
|
ensure => file,
|
|
owner => 'root',
|
|
group => 'root',
|
|
mode => '0600',
|
|
content => Sensitive(template('wireguard/wg.conf.erb')),
|
|
show_diff => false,
|
|
notify => Exec["wireguard_syncconf_${name}"],
|
|
}
|
|
|
|
service { "wg-quick@${name}":
|
|
ensure => running,
|
|
enable => true,
|
|
require => File[$conf],
|
|
}
|
|
|
|
# syncconf applies peer/key changes without bouncing the tunnel; address/mtu changes need a manual restart
|
|
exec { "wireguard_syncconf_${name}":
|
|
command => "/bin/bash -c 'wg syncconf ${name} <(wg-quick strip ${name})'",
|
|
onlyif => "/usr/sbin/ip link show ${name}",
|
|
path => ['/usr/bin', '/usr/sbin', '/bin', '/sbin'],
|
|
refreshonly => true,
|
|
require => Service["wg-quick@${name}"],
|
|
}
|
|
}
|