#!/usr/bin/env bash # Bring up a node's Warp egress. Run as root. # The WireGuard config at /etc/netvm/.conf is human-generated # (a credential). This script manages lifecycle only — it never creates # or copies identities. set -euo pipefail NODE="${1:?usage: netvm-node-up.sh }" NETNS="warp-${NODE}" CONF="/etc/netvm/${NODE}.conf" [ -f "$CONF" ] || { echo "missing $CONF — human generates it once (wgcf), root-owned 0600"; exit 1; } chmod 600 "$CONF" ip netns add "$NETNS" 2>/dev/null || true ip link add "wg-${NODE}" type wireguard 2>/dev/null || true ip link set "wg-${NODE}" netns "$NETNS" ip netns exec "$NETNS" wg setconf "wg-${NODE}" "$CONF" ip netns exec "$NETNS" ip link set lo up ip netns exec "$NETNS" ip link set "wg-${NODE}" up # NOTE: addresses/routes come from the generated config (wgcf carries them). EGRESS=$(ip netns exec "$NETNS" curl -s --max-time 15 ifconfig.me || true) echo "node=$NODE netns=$NETNS egress=${EGRESS:-UNREACHABLE}" [ -n "$EGRESS" ] || { echo "egress check failed"; exit 1; }