NetVM: per-node Warp egress design + lifecycle scripts
This commit is contained in:
Executable
+21
@@ -0,0 +1,21 @@
|
||||
#!/usr/bin/env bash
|
||||
# Bring up a node's Warp egress. Run as root.
|
||||
# The WireGuard config at /etc/netvm/<node>.conf is human-generated
|
||||
# (a credential). This script manages lifecycle only — it never creates
|
||||
# or copies identities.
|
||||
set -euo pipefail
|
||||
NODE="${1:?usage: netvm-node-up.sh <node>}"
|
||||
NETNS="warp-${NODE}"
|
||||
CONF="/etc/netvm/${NODE}.conf"
|
||||
[ -f "$CONF" ] || { echo "missing $CONF — human generates it once (wgcf), root-owned 0600"; exit 1; }
|
||||
chmod 600 "$CONF"
|
||||
ip netns add "$NETNS" 2>/dev/null || true
|
||||
ip link add "wg-${NODE}" type wireguard 2>/dev/null || true
|
||||
ip link set "wg-${NODE}" netns "$NETNS"
|
||||
ip netns exec "$NETNS" wg setconf "wg-${NODE}" < "$CONF"
|
||||
ip netns exec "$NETNS" ip link set lo up
|
||||
ip netns exec "$NETNS" ip link set "wg-${NODE}" up
|
||||
# NOTE: addresses/routes come from the generated config (wgcf carries them).
|
||||
EGRESS=$(ip netns exec "$NETNS" curl -s --max-time 15 ifconfig.me || true)
|
||||
echo "node=$NODE netns=$NETNS egress=${EGRESS:-UNREACHABLE}"
|
||||
[ -n "$EGRESS" ] || { echo "egress check failed"; exit 1; }
|
||||
Reference in New Issue
Block a user