Files
box/bin/netvm-node-up.sh
T
2026-10-03 00:33:37 -04:00

22 lines
1.0 KiB
Bash
Executable File

#!/usr/bin/env bash
# Bring up a node's Warp egress. Run as root.
# The WireGuard config at /etc/netvm/<node>.conf is human-generated
# (a credential). This script manages lifecycle only — it never creates
# or copies identities.
set -euo pipefail
NODE="${1:?usage: netvm-node-up.sh <node>}"
NETNS="warp-${NODE}"
CONF="/etc/netvm/${NODE}.conf"
[ -f "$CONF" ] || { echo "missing $CONF — human generates it once (wgcf), root-owned 0600"; exit 1; }
chmod 600 "$CONF"
ip netns add "$NETNS" 2>/dev/null || true
ip link add "wg-${NODE}" type wireguard 2>/dev/null || true
ip link set "wg-${NODE}" netns "$NETNS"
ip netns exec "$NETNS" wg setconf "wg-${NODE}" "$CONF"
ip netns exec "$NETNS" ip link set lo up
ip netns exec "$NETNS" ip link set "wg-${NODE}" up
# NOTE: addresses/routes come from the generated config (wgcf carries them).
EGRESS=$(ip netns exec "$NETNS" curl -s --max-time 15 ifconfig.me || true)
echo "node=$NODE netns=$NETNS egress=${EGRESS:-UNREACHABLE}"
[ -n "$EGRESS" ] || { echo "egress check failed"; exit 1; }