NetVM: human-run identity script (netvm-new-identity.sh)

This commit is contained in:
Antigravity Agent
2026-10-03 00:10:52 -04:00
parent e20f6cf665
commit 324d1c654f
2 changed files with 34 additions and 4 deletions
+5 -4
View File
@@ -65,10 +65,11 @@ egress (true static IPs, paid).
Identity creation is the human's job; lifecycle is scriptable:
1. Human: generate the node's WireGuard config once (wgcf register +
wgcf generate, or warp-cli equivalent) and place it at
/etc/netvm/<node>.conf (root-owned, 0600). This file is a credential —
agents never create, read, or copy it.
1. Human: run `bin/netvm-new-identity.sh <node>` ON the node — it
registers the Warp identity and installs /etc/netvm/<node>.conf
(root-owned, 0600). This file is a credential — agents never create,
read, or copy it, and the script is excluded from the operator sudoers
allowlist.
2. sudo bin/netvm-node-up.sh <node> — creates netns warp-<node>, raises
the wg interface inside it, verifies egress, prints the result.
3. chrome-box launches the client's Chromium inside that netns.