Compare commits

..

No commits in common. "0a58cdc734b0f798d50578b5c17f7a980459f065" and "97f88b63af28163220f4e01c9af8619f952b3f06" have entirely different histories.

4 changed files with 45 additions and 57 deletions

View File

@ -1,30 +1,23 @@
SERVER_DIR := /etc/wireguard/
SERVER_TPL := templates/wg0.conf
SERVER_CLIENT_TPL := templates/wg0-client.tpl
SERVER_CONF := $(SERVER_DIR)/wg0.conf
SERVER_KEY := $(SERVER_DIR)/server_id
SERVER_PUBLIC_KEY := $(SERVER_DIR)/server_id.pub
SERVER_CLIENT_TPL := templates/wg0-client.conf
SERVER_CONF := /etc/wireguard/wg0.conf
SERVER_KEY := /etc/wireguard/server_id
SERVER_PUBLIC_KEY := /etc/wireguard/server_id.pub
CLIENT_TPL := templates/client.conf
CLIENT_DIR := $(SERVER_DIR)/clients/
CLIENT_DIR := /etc/wireguard/clients/
CLIENT_IPS ?= 10.42.0.0/16
ENDPOINT_PORT ?= 51820
ENDPOINT ?= 1.2.3.4
# XXX need to generate this...
CLIENT_IP ?= 10.42.0.1/32
DNS ?= 10.1.1.1
ALLOWED_IPS ?= 0.0.0.0/0
ENDPOINT_PORT := 51820
ENDPOINT :=
CLIENT_IPS := 10.42.0.0/16
DNS := 10.1.1.1
%_id:
@ mkdir -p $$(dirname $@)
wg genkey 2> /dev/null > $@
chmod 600 $@
wg genkey > $@
%_id.pub: %_id
cat $< | wg pubkey > $@
@ -33,32 +26,31 @@ ALLOWED_IPS ?= 0.0.0.0/0
$(SERVER_CONF): $(SERVER_TPL) $(SERVER_KEY)
cat $< \
| sed \
-e 's/\$${ENDPOINT_PORT}/$(ENDPOINT_PORT)/g' \
-e 's/\$${CLIENT_IPS}/$(subst /,\/,$(CLIENT_IPS))/g' \
-e 's/\$${SERVER_PRIVATE_KEY}/'$$(cat "$(SERVER_KEY)" | sed -e 's/\//\\\//g')'/g' \
-e 's/$${SERVER_PORT}/$(SERVER_PORT)/g' \
-e 's/$${CLIENT_IPS}/$(CLIENT_IPS)/g' \
-e 's/$${SERVER_PRIVATE_KEY}/'$$(cat "$(SERVER_KEY)")'/g' \
> "$@"
%.client: $(CLIENT_TPL) $(SERVER_CLIENT_TPL) \
$(CLIENT_DIR)/%.conf: $(CLIENT_TPL) $(SERVER_CLIENT_TPL) \
$(CLIENT_DIR)/%_id $(CLIENT_DIR)/%_id.pub \
$(SERVER_CONF) $(SERVER_PUBLIC_KEY)
@ mkdir -p $(CLIENT_DIR)
cat "$<" \
| sed \
-e 's/\$${DNS}/$(DNS)/g' \
-e 's/\$${ENDPOINT}/$(ENDPOINT)/g' \
-e 's/\$${ENDPOINT_PORT}/$(ENDPOINT_PORT)/g' \
-e 's/\$${ALLOWED_IPS}/$(subst /,\/,$(ALLOWED_IPS))/g' \
-e 's/\$${CLIENT_IP}/$(subst /,\/,$(CLIENT_IP))/g' \
-e 's/\$${CLIENT_PRIVATE_KEY}/'$$(cat "$(CLIENT_DIR)/$*_id" | sed -e 's/\//\\\//g')'/g' \
-e 's/\$${SERVER_PUBLIC_KEY}/'$$(cat "$(SERVER_PUBLIC_KEY)" | sed -e 's/\//\\\//g')'/g' \
> "$(CLIENT_DIR)/$*.conf"
-e 's/$${DNS}/$(DNS)/g' \
-e 's/$${ENDPOINT}/$(ENDPOINT)/g' \
-e 's/$${ENDPOINT_PORT}/$(ENDPOINT_PORT)/g' \
-e 's/$${ALLOWED_IPS}/$(ALLOWED_IPS)/g' \
-e 's/$${CLIENT_IP}/$(CLIENT_IP)/g' \
-e 's/$${CLIENT_PRIVATE_KEY}/'$$(cat "$(CLIENT_DIR)/$%_id")'/g' \
-e 's/$${SERVER_PUBLIC_KEY}/'$$(cat "$(SERVER_PUBLIC_KEY)")'/g' \
> "$@"
cat "$(SERVER_CLIENT_TPL)" \
| sed \
-e 's/\$${CLIENT_IP}/$(subst /,\/,$(CLIENT_IP))/g' \
-e 's/\$${ENDPOINT}/$(ENDPOINT)/g' \
-e 's/\$${ENDPOINT_PORT}/$(ENDPOINT_PORT)/g' \
-e 's/\$${CLIENT_PUBLIC_KEY}/'$$(cat "$(CLIENT_DIR)/$*_id.pub" | sed -e 's/\//\\\//g')'/g' \
-e 's/\$${SERVER_PUBLIC_KEY}/'$$(cat "$(SERVER_PUBLIC_KEY)" | sed -e 's/\//\\\//g')'/g' \
-e 's/$${CLIENT_IP}/$(CLIENT_IP)/g' \
-e 's/$${ENDPOINT}/$(ENDPOINT)/g' \
-e 's/$${ENDPOINT_PORT}/$(ENDPOINT_PORT)/g' \
-e 's/$${CLIENT_PUBLIC_KEY}/'$$(cat "$(CLIENT_DIR)/$%_id.pub")'/g' \
-e 's/$${SERVER_PUBLIC_KEY}/'$$(cat "$(SERVER_PUBLIC_KEY)")'/g' \
>> "$(SERVER_CONF)"
@ -66,4 +58,7 @@ $(SERVER_CONF): $(SERVER_TPL) $(SERVER_KEY)
server: $(SERVER_CONF)
clients:

View File

@ -1,6 +1,6 @@
[Interface]
PrivateKey = ${CLIENT_PRIVATE_KEY}
Address = ${CLIENT_IP}
Address = ${CLIENT_IP}/32
DNS = ${DNS}
[Peer]

View File

@ -1,6 +1,6 @@
[Peer]
PublicKey = ${CLIENT_PUBLIC_KEY}
AllowedIPs = ${CLIENT_IP}
AllowedIPs = ${CLIENT_IP}/32
Endpoint = ${ENDPOINT}:${ENDPOINT_PORT}

View File

@ -69,33 +69,26 @@ echo "# Creating CT..."
pctCreateAlpine $ID "${OPTS_STAGE_1}" "$PASS"
echo "# Installing dependencies..."
@ lxc-attach $ID apk add iptables wireguard-tools-wg-quick make
@ lxc-attach $ID apk add iptables wireguard-tools-wg-quick
echo "# Copying assets..."
@ pct-push-r $ID ./assets /
#echo "# Setup: wireguard server..."
@ lxc-attach $ID -- bash -c 'cd /root && make server'
echo "# Setup: wireguard server..."
@ lxc-attach $ID -- bash -c 'wg genkey | tee server.privatekey | wg pubkey > server.publickey'
echo "# Setup: wireguard default profile..."
@ lxc-attach $ID -- bash -c "cd /root && \
ENDPOINT_PORT=51820
ENDPOINT=${DOMAIN}
CLIENT_IP=10.42.0.1/32
DNS=${NS_LAN_IP}
ALLOWED_IPS=0.0.0.0/0
make default.client"
@ lxc-attach $ID -- chmod 600 /etc/wireguard/wg0.conf
# XXX move this into a script on the CT side...
echo "# Setup: wireguard user..."
xread "profile name: " WG_PROFILE
xread "allowed ips: " ALLOWED_IPs
echo "# client config:"
@ mkdir -p clients
@ pct pull $ID /etc/wireguard/clients/default.conf clients/default.conf
echo "# ---"
@ lxc-attach $ID -- cat /etc/wireguard/clients/default.conf
echo "# ---"
# XXX client:
# - generate keys
# - add to wg0.conf
# - add to $WG_PROFILE.conf
#echo "# Setup: bridge device..."
@ lxc-attach $ID wg-quick up wg0
echo "# Setup: bridge device..."
@ lxc-attach $ID wg up wg0
echo "# Post config..."
pctSet $ID "${OPTS_STAGE_2}" $REBOOT