NetVM: human-run identity script (netvm-new-identity.sh)

This commit is contained in:
Antigravity Agent
2026-10-03 00:10:52 -04:00
parent e20f6cf665
commit 324d1c654f
2 changed files with 34 additions and 4 deletions
+5 -4
View File
@@ -65,10 +65,11 @@ egress (true static IPs, paid).
Identity creation is the human's job; lifecycle is scriptable: Identity creation is the human's job; lifecycle is scriptable:
1. Human: generate the node's WireGuard config once (wgcf register + 1. Human: run `bin/netvm-new-identity.sh <node>` ON the node — it
wgcf generate, or warp-cli equivalent) and place it at registers the Warp identity and installs /etc/netvm/<node>.conf
/etc/netvm/<node>.conf (root-owned, 0600). This file is a credential — (root-owned, 0600). This file is a credential — agents never create,
agents never create, read, or copy it. read, or copy it, and the script is excluded from the operator sudoers
allowlist.
2. sudo bin/netvm-node-up.sh <node> — creates netns warp-<node>, raises 2. sudo bin/netvm-node-up.sh <node> — creates netns warp-<node>, raises
the wg interface inside it, verifies egress, prints the result. the wg interface inside it, verifies egress, prints the result.
3. chrome-box launches the client's Chromium inside that netns. 3. chrome-box launches the client's Chromium inside that netns.
+29
View File
@@ -0,0 +1,29 @@
#!/usr/bin/env bash
# netvm-new-identity.sh <node> — HUMAN-RUN ONLY, on the node itself.
#
# Generates a fresh Warp WireGuard identity and installs it at
# /etc/netvm/<node>.conf (root-owned, 0600).
#
# This script handles a credential (the Warp private key). It must be run
# by the human on the node — never by an operator agent, never over a
# relayed session. Agents must not execute it, copy its outputs, or read
# /etc/netvm. (The operator sudoers allowlist deliberately excludes it.)
set -euo pipefail
NODE="${1:?usage: netvm-new-identity.sh <node>}"
CONF="/etc/netvm/${NODE}.conf"
[ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; }
if ! command -v wgcf >/dev/null 2>&1; then
echo "installing wgcf..."
if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf
elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf
else echo "install wgcf manually, then re-run"; exit 1; fi
fi
WORK="$(mktemp -d)"
trap 'rm -rf "$WORK"' EXIT
cd "$WORK"
echo "registering Warp identity..."
wgcf register --accept-tos
echo "generating WireGuard profile..."
wgcf generate
sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF"
echo "installed $CONF (root-owned, 0600); working copies removed"