NetVM: per-node Warp egress design + lifecycle scripts

This commit is contained in:
Antigravity Agent
2026-10-03 00:01:09 -04:00
commit 0f2a87b08a
6 changed files with 147 additions and 0 deletions
+8
View File
@@ -0,0 +1,8 @@
#!/usr/bin/env bash
# Tear down a node's Warp egress. Run as root.
set -euo pipefail
NODE="${1:?usage: netvm-node-down.sh <node>}"
NETNS="warp-${NODE}"
ip netns exec "$NETNS" ip link set "wg-${NODE}" down 2>/dev/null || true
ip netns del "$NETNS" 2>/dev/null || true
echo "node=$NODE down"
+21
View File
@@ -0,0 +1,21 @@
#!/usr/bin/env bash
# Bring up a node's Warp egress. Run as root.
# The WireGuard config at /etc/netvm/<node>.conf is human-generated
# (a credential). This script manages lifecycle only — it never creates
# or copies identities.
set -euo pipefail
NODE="${1:?usage: netvm-node-up.sh <node>}"
NETNS="warp-${NODE}"
CONF="/etc/netvm/${NODE}.conf"
[ -f "$CONF" ] || { echo "missing $CONF — human generates it once (wgcf), root-owned 0600"; exit 1; }
chmod 600 "$CONF"
ip netns add "$NETNS" 2>/dev/null || true
ip link add "wg-${NODE}" type wireguard 2>/dev/null || true
ip link set "wg-${NODE}" netns "$NETNS"
ip netns exec "$NETNS" wg setconf "wg-${NODE}" < "$CONF"
ip netns exec "$NETNS" ip link set lo up
ip netns exec "$NETNS" ip link set "wg-${NODE}" up
# NOTE: addresses/routes come from the generated config (wgcf carries them).
EGRESS=$(ip netns exec "$NETNS" curl -s --max-time 15 ifconfig.me || true)
echo "node=$NODE netns=$NETNS egress=${EGRESS:-UNREACHABLE}"
[ -n "$EGRESS" ] || { echo "egress check failed"; exit 1; }
+8
View File
@@ -0,0 +1,8 @@
#!/usr/bin/env bash
# Live topology: netns -> egress IP. Run as root for netns exec.
set -u
for ns in $(ip netns list 2>/dev/null | awk '{print $1}' | grep '^warp-'); do
node="${ns#warp-}"
egress=$(ip netns exec "$ns" curl -s --max-time 10 ifconfig.me 2>/dev/null || echo UNREACHABLE)
printf '%-20s %-16s %s\n' "$node" "$ns" "$egress"
done
+7
View File
@@ -0,0 +1,7 @@
#!/usr/bin/env bash
# Prerequisite checks for a NetVM host. Reports only; safe for any user.
set -u
ok=1
need() { command -v "$1" >/dev/null 2>&1 && echo "ok: $1" || { echo "MISSING: $1"; ok=0; }; }
need ip; need wg; need tailscale; need warp-cli; need waypipe; need chromium; need curl
[ "$ok" = 1 ] && echo "ALL CHECKS PASSED" || { echo "CHECKS FAILED"; exit 1; }