NetVM: document 1:1 profile:node mapping and launch flow

This commit is contained in:
Antigravity Agent
2026-10-03 00:44:49 -04:00
parent b86b6fa4b5
commit 65f0c57ba4
+20 -6
View File
@@ -61,20 +61,34 @@ Two ways to get per-node Warp egress were considered:
Upgrade path if pool IPs prove too fluid: Cloudflare Zero Trust dedicated Upgrade path if pool IPs prove too fluid: Cloudflare Zero Trust dedicated
egress (true static IPs, paid). egress (true static IPs, paid).
## Mapping: 1:1 profile = node = warp identity = egress IP
Each chrome-box profile with auth gets its own dedicated Warp
credentials and its own stable egress IP. The profile name IS the node
name. One account always on one stable IP is the most human-like
pattern — it's IP hopping that trips provider alarms.
Interface names are hashed (`wb-<tag>`, `ve-<tag>`) because Linux
interface names max out at 15 chars; the netns keeps the full
`warp-<node>` name. See `bin/netvm-names.sh`.
## Provisioning a node ## Provisioning a node
Identity creation is the human's job; lifecycle is scriptable: Identity creation is the human's job; lifecycle is scriptable:
1. Human: run `bin/netvm-new-identity.sh <node>` ON the node — it 1. Human: `chrome-box create <profile>` (browser profile).
registers the Warp identity and installs /etc/netvm/<node>.conf 2. Human: run `bin/netvm-new-identity.sh <profile>` ON the node — it
registers the Warp identity and installs /etc/netvm/<profile>.conf
(root-owned, 0600). This file is a credential — agents never create, (root-owned, 0600). This file is a credential — agents never create,
read, or copy it, and the script is excluded from the operator sudoers read, or copy it, and the script is excluded from the operator sudoers
allowlist. allowlist.
2. sudo bin/netvm-node-up.sh <node> — creates netns warp-<node>, raises 3. Human (or operator over the tailnet): `bin/netvm-chrome.sh <profile> [url]`
the wg interface inside it, verifies egress, prints the result. — ensures the tunnel is up, enters netns `warp-<profile>`, bind-mounts
3. chrome-box launches the client's Chromium inside that netns. a working resolv.conf (the host's systemd-resolved stub is unreachable
in the netns), drops to the invoking user, launches the profile's
Chromium. Browser runs as the user, never as root.
Tear down: sudo bin/netvm-node-down.sh <node>. Tear down: `bin/netvm-node-down.sh <node>` (sudo).
## Files ## Files