30 lines
1.3 KiB
Bash
Executable File
30 lines
1.3 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# netvm-new-identity.sh <node> — HUMAN-RUN ONLY, on the node itself.
|
|
#
|
|
# Generates a fresh Warp WireGuard identity and installs it at
|
|
# /etc/netvm/<node>.conf (root-owned, 0600).
|
|
#
|
|
# This script handles a credential (the Warp private key). It must be run
|
|
# by the human on the node — never by an operator agent, never over a
|
|
# relayed session. Agents must not execute it, copy its outputs, or read
|
|
# /etc/netvm. (The operator sudoers allowlist deliberately excludes it.)
|
|
set -euo pipefail
|
|
NODE="${1:?usage: netvm-new-identity.sh <node>}"
|
|
CONF="/etc/netvm/${NODE}.conf"
|
|
[ -f "$CONF" ] && { echo "refusing: $CONF exists (remove manually to rotate)"; exit 1; }
|
|
if ! command -v wgcf >/dev/null 2>&1; then
|
|
echo "installing wgcf..."
|
|
if command -v pacman >/dev/null 2>&1; then sudo pacman -S --noconfirm --needed wgcf
|
|
elif command -v apt-get >/dev/null 2>&1; then sudo apt-get update && sudo apt-get install -y wgcf
|
|
else echo "install wgcf manually, then re-run"; exit 1; fi
|
|
fi
|
|
WORK="$(mktemp -d)"
|
|
trap 'rm -rf "$WORK"' EXIT
|
|
cd "$WORK"
|
|
echo "registering Warp identity..."
|
|
wgcf register --accept-tos
|
|
echo "generating WireGuard profile..."
|
|
wgcf generate
|
|
sudo install -m 600 -o root -g root wgcf-profile.conf "$CONF"
|
|
echo "installed $CONF (root-owned, 0600); working copies removed"
|