NetVM: veth+NAT plumbing for isolated netns (endpoint bypass, no routing loop)
This commit is contained in:
@@ -1,8 +1,14 @@
|
||||
#!/usr/bin/env bash
|
||||
# Tear down a node's Warp egress. Run as root.
|
||||
# netvm-node-down.sh <node> — tear down a node's Warp egress. Run as root.
|
||||
set -euo pipefail
|
||||
NODE="${1:?usage: netvm-node-down.sh <node>}"
|
||||
NETNS="warp-${NODE}"
|
||||
ip netns exec "$NETNS" ip link set "wg-${NODE}" down 2>/dev/null || true
|
||||
VETH="veth-${NODE}"
|
||||
IDX=$(( $(echo -n "$NODE" | cksum | cut -d' ' -f1) % 60 + 10 ))
|
||||
SUB="10.201.${IDX}.0/30"
|
||||
nsexec() { ip netns exec "$NETNS" "$@"; }
|
||||
nsexec ip link set "wg-${NODE}" down 2>/dev/null || true
|
||||
ip link del "$VETH" 2>/dev/null || true # also drops the netns-side peer
|
||||
iptables -t nat -D POSTROUTING -s "$SUB" -j MASQUERADE 2>/dev/null || true
|
||||
ip netns del "$NETNS" 2>/dev/null || true
|
||||
echo "node=$NODE down"
|
||||
|
||||
Reference in New Issue
Block a user