#!/usr/bin/env bash # netvm-new-identity.sh — HUMAN-RUN ONLY, on the node itself. # # Generates a fresh Warp WireGuard identity and installs it at # /etc/netvm/.conf (root-owned, 0600). # # This script handles a credential (the Warp private key). It must be run # by the human on the node — never by an operator agent, never over a # relayed session. Agents must not execute it, copy its outputs, or read # /etc/netvm. (The operator sudoers allowlist deliberately excludes it.) set -euo pipefail NODE="${1:?usage: netvm-new-identity.sh }" CONF="/etc/netvm/${NODE}.conf" [ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; } if ! command -v wgcf >/dev/null 2>&1; then echo "installing wgcf..." if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf else echo "install wgcf manually, then re-run"; exit 1; fi fi WORK="$(mktemp -d)" trap 'rm -rf "$WORK"' EXIT cd "$WORK" echo "registering Warp identity..." wgcf register --accept-tos echo "generating WireGuard profile..." wgcf generate sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF" echo "installed $CONF (root-owned, 0600); working copies removed"