NetVM: human-run identity script (netvm-new-identity.sh)
This commit is contained in:
Executable
+29
@@ -0,0 +1,29 @@
|
||||
#!/usr/bin/env bash
|
||||
# netvm-new-identity.sh <node> — HUMAN-RUN ONLY, on the node itself.
|
||||
#
|
||||
# Generates a fresh Warp WireGuard identity and installs it at
|
||||
# /etc/netvm/<node>.conf (root-owned, 0600).
|
||||
#
|
||||
# This script handles a credential (the Warp private key). It must be run
|
||||
# by the human on the node — never by an operator agent, never over a
|
||||
# relayed session. Agents must not execute it, copy its outputs, or read
|
||||
# /etc/netvm. (The operator sudoers allowlist deliberately excludes it.)
|
||||
set -euo pipefail
|
||||
NODE="${1:?usage: netvm-new-identity.sh <node>}"
|
||||
CONF="/etc/netvm/${NODE}.conf"
|
||||
[ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; }
|
||||
if ! command -v wgcf >/dev/null 2>&1; then
|
||||
echo "installing wgcf..."
|
||||
if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf
|
||||
elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf
|
||||
else echo "install wgcf manually, then re-run"; exit 1; fi
|
||||
fi
|
||||
WORK="$(mktemp -d)"
|
||||
trap 'rm -rf "$WORK"' EXIT
|
||||
cd "$WORK"
|
||||
echo "registering Warp identity..."
|
||||
wgcf register --accept-tos
|
||||
echo "generating WireGuard profile..."
|
||||
wgcf generate
|
||||
sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF"
|
||||
echo "installed $CONF (root-owned, 0600); working copies removed"
|
||||
Reference in New Issue
Block a user