| 
									
										
										
										
											2024-01-08 14:05:17 +03:00
										 |  |  | #!/usr/bin/bash
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | # https://wiki.alpinelinux.org/wiki/Configure_a_Wireguard_interface_(wg) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | cd $(dirname $0) | 
					
						
							|  |  |  | PATH=$PATH:$(dirname "$(pwd)") | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | source ../.pct-helpers | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | readConfig | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | DFL_ID=${DFL_ID:=103} | 
					
						
							|  |  |  | DFL_CTHOSTNAME=${DFL_CTHOSTNAME:=wireguard} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | DFL_CORES=${DFL_CORES:=1} | 
					
						
							|  |  |  | DFL_RAM=${DFL_RAM:=256} | 
					
						
							|  |  |  | DFL_SWAP=${DFL_SWAP:=${DFL_RAM}} | 
					
						
							|  |  |  | DFL_DRIVE=${DFL_DRIVE:=1} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | WAN_IP=- | 
					
						
							|  |  |  | WAN_GATE=- | 
					
						
							|  |  |  | ADMIN_IP=- | 
					
						
							|  |  |  | ADMIN_GATE=- | 
					
						
							|  |  |  | LAN_IP=- | 
					
						
							|  |  |  | LAN_GATE=- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | REBOOT=${REBOOT:=1} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | readVars | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | OPTS_STAGE_1="\
 | 
					
						
							|  |  |  | 	--hostname $CTHOSTNAME \
 | 
					
						
							|  |  |  | 	--cores $CORES \
 | 
					
						
							|  |  |  | 	--memory $RAM \
 | 
					
						
							|  |  |  | 	--swap $SWAP \
 | 
					
						
							|  |  |  | 	--net0 name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1,ip=dhcp,type=veth \
 | 
					
						
							|  |  |  | 	--net1 name=admin,bridge=vmbr${ADMIN_BRIDGE},firewall=1,ip=dhcp,type=veth \
 | 
					
						
							|  |  |  | 	--storage local-lvm \
 | 
					
						
							|  |  |  | 	--rootfs local-lvm:$DRIVE \
 | 
					
						
							|  |  |  | 	--unprivileged 1 \
 | 
					
						
							|  |  |  | 	--features nesting=1 \
 | 
					
						
							|  |  |  | 	${PCT_EXTRA} \
 | 
					
						
							|  |  |  | "
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | OPTS_STAGE_2="\
 | 
					
						
							|  |  |  | 	--onboot 1 \
 | 
					
						
							|  |  |  | "
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | echo "# Building config..." | 
					
						
							|  |  |  | buildAssets "$TEMPLATE_DIR" "$ASSETS_DIR" | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | echo "# Creating CT..." | 
					
						
							|  |  |  | pctCreateAlpine $ID "${OPTS_STAGE_1}" "$PASS" | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | echo "# Installing dependencies..." | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | @ lxc-attach $ID apk add iptables wireguard-tools-wg-quick make | 
					
						
							| 
									
										
										
										
											2024-01-08 14:05:17 +03:00
										 |  |  | 
 | 
					
						
							|  |  |  | echo "# Copying assets..." | 
					
						
							|  |  |  | @ pct-push-r $ID ./assets / | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-01-09 13:54:09 +03:00
										 |  |  | #echo "# Setup: wireguard server..." | 
					
						
							| 
									
										
										
										
											2024-01-09 17:20:56 +03:00
										 |  |  | @ lxc-attach $ID -- bash -c 'cd /root && make server' | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | 
 | 
					
						
							|  |  |  | echo "# Setup: wireguard default profile..." | 
					
						
							| 
									
										
										
										
											2024-01-09 17:20:56 +03:00
										 |  |  | @ lxc-attach $ID -- bash -c "cd /root && \
 | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | 	ENDPOINT_PORT=51820 | 
					
						
							|  |  |  | 	ENDPOINT=${DOMAIN} | 
					
						
							|  |  |  | 	CLIENT_IP=10.42.0.1/32 | 
					
						
							|  |  |  | 	DNS=${NS_LAN_IP} | 
					
						
							|  |  |  | 	ALLOWED_IPS=0.0.0.0/0 | 
					
						
							|  |  |  | 		make default.client" 
 | 
					
						
							| 
									
										
										
										
											2024-01-09 17:32:10 +03:00
										 |  |  | @ lxc-attach $ID -- chmod 600 /etc/wireguard/wg0.conf | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | 
 | 
					
						
							|  |  |  | echo "# client config:" | 
					
						
							|  |  |  | @ mkdir -p clients | 
					
						
							| 
									
										
										
										
											2024-01-09 17:14:04 +03:00
										 |  |  | @ pct pull $ID /etc/wireguard/clients/default.conf clients/default.conf | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | echo "# ---" | 
					
						
							| 
									
										
										
										
											2024-01-09 17:43:17 +03:00
										 |  |  | @ lxc-attach $ID -- cat /etc/wireguard/clients/default.conf | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | echo "# ---" | 
					
						
							| 
									
										
										
										
											2024-01-08 14:05:17 +03:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2024-01-09 13:54:55 +03:00
										 |  |  | #echo "# Setup: bridge device..." | 
					
						
							| 
									
										
										
										
											2024-01-09 15:49:42 +03:00
										 |  |  | @ lxc-attach $ID wg-quick up wg0  | 
					
						
							| 
									
										
										
										
											2024-01-08 14:05:17 +03:00
										 |  |  | 
 | 
					
						
							|  |  |  | echo "# Post config..." | 
					
						
							|  |  |  | pctSet $ID "${OPTS_STAGE_2}" $REBOOT | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | echo "# Done." | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | #---------------------------------------------------------------------- | 
					
						
							|  |  |  | # vim:set ts=4 sw=4 : | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 |