22 lines
1.0 KiB
Bash
22 lines
1.0 KiB
Bash
|
|
#!/usr/bin/env bash
|
||
|
|
# Bring up a node's Warp egress. Run as root.
|
||
|
|
# The WireGuard config at /etc/netvm/<node>.conf is human-generated
|
||
|
|
# (a credential). This script manages lifecycle only — it never creates
|
||
|
|
# or copies identities.
|
||
|
|
set -euo pipefail
|
||
|
|
NODE="${1:?usage: netvm-node-up.sh <node>}"
|
||
|
|
NETNS="warp-${NODE}"
|
||
|
|
CONF="/etc/netvm/${NODE}.conf"
|
||
|
|
[ -f "$CONF" ] || { echo "missing $CONF — human generates it once (wgcf), root-owned 0600"; exit 1; }
|
||
|
|
chmod 600 "$CONF"
|
||
|
|
ip netns add "$NETNS" 2>/dev/null || true
|
||
|
|
ip link add "wg-${NODE}" type wireguard 2>/dev/null || true
|
||
|
|
ip link set "wg-${NODE}" netns "$NETNS"
|
||
|
|
ip netns exec "$NETNS" wg setconf "wg-${NODE}" < "$CONF"
|
||
|
|
ip netns exec "$NETNS" ip link set lo up
|
||
|
|
ip netns exec "$NETNS" ip link set "wg-${NODE}" up
|
||
|
|
# NOTE: addresses/routes come from the generated config (wgcf carries them).
|
||
|
|
EGRESS=$(ip netns exec "$NETNS" curl -s --max-time 15 ifconfig.me || true)
|
||
|
|
echo "node=$NODE netns=$NETNS egress=${EGRESS:-UNREACHABLE}"
|
||
|
|
[ -n "$EGRESS" ] || { echo "egress check failed"; exit 1; }
|