Files

30 lines
1.3 KiB
Bash
Raw Permalink Normal View History

#!/usr/bin/env bash
# netvm-new-identity.sh <node> — HUMAN-RUN ONLY, on the node itself.
#
# Generates a fresh Warp WireGuard identity and installs it at
# /etc/netvm/<node>.conf (root-owned, 0600).
#
# This script handles a credential (the Warp private key). It must be run
# by the human on the node — never by an operator agent, never over a
# relayed session. Agents must not execute it, copy its outputs, or read
# /etc/netvm. (The operator sudoers allowlist deliberately excludes it.)
set -euo pipefail
NODE="${1:?usage: netvm-new-identity.sh <node>}"
CONF="/etc/netvm/${NODE}.conf"
[ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; }
if ! command -v wgcf >/dev/null 2>&1; then
echo "installing wgcf..."
if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf
elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf
else echo "install wgcf manually, then re-run"; exit 1; fi
fi
WORK="$(mktemp -d)"
trap 'rm -rf "$WORK"' EXIT
cd "$WORK"
echo "registering Warp identity..."
wgcf register --accept-tos
echo "generating WireGuard profile..."
wgcf generate
sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF"
echo "installed $CONF (root-owned, 0600); working copies removed"