NetVM: human-run identity script (netvm-new-identity.sh)
This commit is contained in:
@@ -65,10 +65,11 @@ egress (true static IPs, paid).
|
||||
|
||||
Identity creation is the human's job; lifecycle is scriptable:
|
||||
|
||||
1. Human: generate the node's WireGuard config once (wgcf register +
|
||||
wgcf generate, or warp-cli equivalent) and place it at
|
||||
/etc/netvm/<node>.conf (root-owned, 0600). This file is a credential —
|
||||
agents never create, read, or copy it.
|
||||
1. Human: run `bin/netvm-new-identity.sh <node>` ON the node — it
|
||||
registers the Warp identity and installs /etc/netvm/<node>.conf
|
||||
(root-owned, 0600). This file is a credential — agents never create,
|
||||
read, or copy it, and the script is excluded from the operator sudoers
|
||||
allowlist.
|
||||
2. sudo bin/netvm-node-up.sh <node> — creates netns warp-<node>, raises
|
||||
the wg interface inside it, verifies egress, prints the result.
|
||||
3. chrome-box launches the client's Chromium inside that netns.
|
||||
|
||||
Reference in New Issue
Block a user