From 324d1c654fa5b06890f1010f025ae722f6051270 Mon Sep 17 00:00:00 2001 From: Antigravity Agent Date: Sat, 3 Oct 2026 00:10:52 -0400 Subject: [PATCH] NetVM: human-run identity script (netvm-new-identity.sh) --- README.md | 9 +++++---- bin/netvm-new-identity.sh | 29 +++++++++++++++++++++++++++++ 2 files changed, 34 insertions(+), 4 deletions(-) create mode 100755 bin/netvm-new-identity.sh diff --git a/README.md b/README.md index 5a79d16..c36edae 100644 --- a/README.md +++ b/README.md @@ -65,10 +65,11 @@ egress (true static IPs, paid). Identity creation is the human's job; lifecycle is scriptable: -1. Human: generate the node's WireGuard config once (wgcf register + - wgcf generate, or warp-cli equivalent) and place it at - /etc/netvm/.conf (root-owned, 0600). This file is a credential — - agents never create, read, or copy it. +1. Human: run `bin/netvm-new-identity.sh ` ON the node — it + registers the Warp identity and installs /etc/netvm/.conf + (root-owned, 0600). This file is a credential — agents never create, + read, or copy it, and the script is excluded from the operator sudoers + allowlist. 2. sudo bin/netvm-node-up.sh — creates netns warp-, raises the wg interface inside it, verifies egress, prints the result. 3. chrome-box launches the client's Chromium inside that netns. diff --git a/bin/netvm-new-identity.sh b/bin/netvm-new-identity.sh new file mode 100755 index 0000000..7e26264 --- /dev/null +++ b/bin/netvm-new-identity.sh @@ -0,0 +1,29 @@ +#!/usr/bin/env bash +# netvm-new-identity.sh — HUMAN-RUN ONLY, on the node itself. +# +# Generates a fresh Warp WireGuard identity and installs it at +# /etc/netvm/.conf (root-owned, 0600). +# +# This script handles a credential (the Warp private key). It must be run +# by the human on the node — never by an operator agent, never over a +# relayed session. Agents must not execute it, copy its outputs, or read +# /etc/netvm. (The operator sudoers allowlist deliberately excludes it.) +set -euo pipefail +NODE="${1:?usage: netvm-new-identity.sh }" +CONF="/etc/netvm/${NODE}.conf" +[ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; } +if ! command -v wgcf >/dev/null 2>&1; then + echo "installing wgcf..." + if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf + elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf + else echo "install wgcf manually, then re-run"; exit 1; fi +fi +WORK="$(mktemp -d)" +trap 'rm -rf "$WORK"' EXIT +cd "$WORK" +echo "registering Warp identity..." +wgcf register --accept-tos +echo "generating WireGuard profile..." +wgcf generate +sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF" +echo "installed $CONF (root-owned, 0600); working copies removed"