2024-01-08 14:05:17 +03:00
|
|
|
#!/usr/bin/bash
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# https://wiki.alpinelinux.org/wiki/Configure_a_Wireguard_interface_(wg)
|
|
|
|
|
|
|
|
|
|
cd $(dirname $0)
|
|
|
|
|
PATH=$PATH:$(dirname "$(pwd)")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
source ../.pct-helpers
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
readConfig
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
DFL_ID=${DFL_ID:=103}
|
|
|
|
|
DFL_CTHOSTNAME=${DFL_CTHOSTNAME:=wireguard}
|
|
|
|
|
|
|
|
|
|
DFL_CORES=${DFL_CORES:=1}
|
|
|
|
|
DFL_RAM=${DFL_RAM:=256}
|
|
|
|
|
DFL_SWAP=${DFL_SWAP:=${DFL_RAM}}
|
|
|
|
|
DFL_DRIVE=${DFL_DRIVE:=1}
|
|
|
|
|
|
|
|
|
|
WAN_IP=-
|
|
|
|
|
WAN_GATE=-
|
|
|
|
|
ADMIN_IP=-
|
|
|
|
|
ADMIN_GATE=-
|
|
|
|
|
LAN_IP=-
|
|
|
|
|
LAN_GATE=-
|
|
|
|
|
|
|
|
|
|
REBOOT=${REBOOT:=1}
|
|
|
|
|
|
2024-01-10 00:17:14 +03:00
|
|
|
DFL_ENDPOINT=${DFL_ENDPOINT:=${DOMAIN}}
|
|
|
|
|
xread "Wireguard endpoint: " ENDPOINT
|
|
|
|
|
|
2024-01-08 14:05:17 +03:00
|
|
|
readVars
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_1="\
|
|
|
|
|
--hostname $CTHOSTNAME \
|
|
|
|
|
--cores $CORES \
|
|
|
|
|
--memory $RAM \
|
|
|
|
|
--swap $SWAP \
|
|
|
|
|
--net0 name=lan,bridge=vmbr${LAN_BRIDGE},firewall=1,ip=dhcp,type=veth \
|
|
|
|
|
--net1 name=admin,bridge=vmbr${ADMIN_BRIDGE},firewall=1,ip=dhcp,type=veth \
|
|
|
|
|
--storage local-lvm \
|
|
|
|
|
--rootfs local-lvm:$DRIVE \
|
|
|
|
|
--unprivileged 1 \
|
|
|
|
|
--features nesting=1 \
|
|
|
|
|
${PCT_EXTRA} \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
OPTS_STAGE_2="\
|
|
|
|
|
--onboot 1 \
|
|
|
|
|
"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
|
|
|
|
|
echo "# Building config..."
|
|
|
|
|
buildAssets "$TEMPLATE_DIR" "$ASSETS_DIR"
|
|
|
|
|
|
|
|
|
|
echo "# Creating CT..."
|
|
|
|
|
pctCreateAlpine $ID "${OPTS_STAGE_1}" "$PASS"
|
|
|
|
|
|
|
|
|
|
echo "# Installing dependencies..."
|
2024-01-09 15:49:42 +03:00
|
|
|
@ lxc-attach $ID apk add iptables wireguard-tools-wg-quick make
|
2024-01-08 14:05:17 +03:00
|
|
|
|
|
|
|
|
echo "# Copying assets..."
|
|
|
|
|
@ pct-push-r $ID ./assets /
|
|
|
|
|
|
2024-01-09 13:54:09 +03:00
|
|
|
#echo "# Setup: wireguard server..."
|
2024-01-09 17:20:56 +03:00
|
|
|
@ lxc-attach $ID -- bash -c 'cd /root && make server'
|
2024-01-09 15:49:42 +03:00
|
|
|
|
|
|
|
|
echo "# Setup: wireguard default profile..."
|
2024-01-09 17:20:56 +03:00
|
|
|
@ lxc-attach $ID -- bash -c "cd /root && \
|
2024-01-10 00:24:35 +03:00
|
|
|
ENDPOINT_PORT=51820 \
|
|
|
|
|
ENDPOINT=${ENDPOINT} \
|
|
|
|
|
CLIENT_IP=10.42.0.1/32 \
|
2024-01-10 01:02:08 +03:00
|
|
|
DNS=${NS_LAN_IP/\/*} \
|
2024-01-10 00:24:35 +03:00
|
|
|
ALLOWED_IPS=0.0.0.0/0 \
|
2024-01-09 15:49:42 +03:00
|
|
|
make default.client"
|
2024-01-09 17:32:10 +03:00
|
|
|
@ lxc-attach $ID -- chmod 600 /etc/wireguard/wg0.conf
|
2024-01-09 15:49:42 +03:00
|
|
|
|
|
|
|
|
echo "# client config:"
|
|
|
|
|
@ mkdir -p clients
|
2024-01-09 17:14:04 +03:00
|
|
|
@ pct pull $ID /etc/wireguard/clients/default.conf clients/default.conf
|
2024-01-08 14:05:17 +03:00
|
|
|
|
2024-01-09 13:54:55 +03:00
|
|
|
#echo "# Setup: bridge device..."
|
2024-01-09 15:49:42 +03:00
|
|
|
@ lxc-attach $ID wg-quick up wg0
|
2024-01-08 14:05:17 +03:00
|
|
|
|
|
|
|
|
echo "# Post config..."
|
|
|
|
|
pctSet $ID "${OPTS_STAGE_2}" $REBOOT
|
|
|
|
|
|
|
|
|
|
echo "# Done."
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
#----------------------------------------------------------------------
|
|
|
|
|
# vim:set ts=4 sw=4 :
|
|
|
|
|
|
|
|
|
|
|