diff options
author | Alex Auvolat <alex@adnab.me> | 2020-05-21 15:27:09 +0200 |
---|---|---|
committer | Alex Auvolat <alex@adnab.me> | 2020-07-15 16:03:33 +0200 |
commit | a4f9aa2d9830e9fdc3504a6d2842359ee4ab38f0 (patch) | |
tree | 3be24e19f8b7a88f36d49870b13f220a178b8f9f /ansible/roles/network | |
parent | 1a16fc7f9e54760cc09f676f0176b71654e32117 (diff) | |
download | infrastructure-a4f9aa2d9830e9fdc3504a6d2842359ee4ab38f0.tar.gz infrastructure-a4f9aa2d9830e9fdc3504a6d2842359ee4ab38f0.zip |
Set up wireguard in dev cluster
Diffstat (limited to 'ansible/roles/network')
-rw-r--r-- | ansible/roles/network/handlers/main.yml | 5 | ||||
-rw-r--r-- | ansible/roles/network/tasks/main.yml | 46 | ||||
-rw-r--r-- | ansible/roles/network/templates/rules.v4.j2 | 4 | ||||
-rw-r--r-- | ansible/roles/network/templates/wireguard.conf.j2 | 12 |
4 files changed, 65 insertions, 2 deletions
diff --git a/ansible/roles/network/handlers/main.yml b/ansible/roles/network/handlers/main.yml new file mode 100644 index 0000000..30bdf2b --- /dev/null +++ b/ansible/roles/network/handlers/main.yml @@ -0,0 +1,5 @@ +--- +- name: reload wireguard + service: + name: wg-quick@wgdeuxfleurs + state: restarted diff --git a/ansible/roles/network/tasks/main.yml b/ansible/roles/network/tasks/main.yml index 1443e0c..e8e059a 100644 --- a/ansible/roles/network/tasks/main.yml +++ b/ansible/roles/network/tasks/main.yml @@ -9,3 +9,49 @@ name: net.ipv4.ip_forward value: "1" sysctl_set: yes + +# Wireguard configuration +- name: "Enable backports repository" + apt_repository: + repo: deb http://deb.debian.org/debian buster-backports main + state: present + +- name: "Install wireguard" + apt: + name: + - wireguard + - wireguard-tools + - "linux-headers-{{ ansible_kernel }}" + state: present + +- name: "Create wireguard configuration direcetory" + file: path=/etc/wireguard/ state=directory + +- name: "Check if wireguard private key exists" + stat: path=/etc/wireguard/privkey + register: wireguard_privkey + +- name: "Create wireguard private key" + shell: wg genkey > /etc/wireguard/privkey + when: wireguard_privkey.stat.exists == false + notify: + - reload wireguard + +- name: "Secure wireguard private key" + file: path=/etc/wireguard/privkey mode=0600 + +- name: "Retrieve wireguard private key" + shell: cat /etc/wireguard/privkey + register: wireguard_privkey + +- name: "Retrieve wireguard public key" + shell: wg pubkey < /etc/wireguard/privkey + register: wireguard_pubkey + +- name: "Deploy wireguard configuration" + template: src=wireguard.conf.j2 dest=/etc/wireguard/wgdeuxfleurs.conf mode=0600 + notify: + - reload wireguard + +- name: "Enable Wireguard systemd service at boot" + service: name=wg-quick@wgdeuxfleurs state=started enabled=yes daemon_reload=yes diff --git a/ansible/roles/network/templates/rules.v4.j2 b/ansible/roles/network/templates/rules.v4.j2 index a446139..ef2cf64 100644 --- a/ansible/roles/network/templates/rules.v4.j2 +++ b/ansible/roles/network/templates/rules.v4.j2 @@ -10,8 +10,8 @@ -A INPUT -s 192.168.1.254 -j ACCEPT -A INPUT -s 82.253.205.190 -j ACCEPT {% for selected_host in groups['cluster_nodes'] %} --A INPUT -s {{ hostvars[selected_host]['public_ip'] }} -j ACCEPT --A INPUT -s {{ hostvars[selected_host]['private_ip'] }} -j ACCEPT +-A INPUT -s {{ hostvars[selected_host]['public_ip'] }} -p udp --dport 51820 -j ACCEPT +-A INPUT -s {{ hostvars[selected_host]['vpn_ip'] }} -j ACCEPT {% endfor %} # Local diff --git a/ansible/roles/network/templates/wireguard.conf.j2 b/ansible/roles/network/templates/wireguard.conf.j2 new file mode 100644 index 0000000..907d546 --- /dev/null +++ b/ansible/roles/network/templates/wireguard.conf.j2 @@ -0,0 +1,12 @@ +[Interface] +Address = {{ vpn_ip }} +PrivateKey = {{ wireguard_privkey.stdout }} +ListenPort = 51820 + +{% for selected_host in groups['cluster_nodes']|difference([inventory_hostname]) %} +[Peer] +PublicKey = {{ hostvars[selected_host].wireguard_pubkey.stdout }} +Endpoint = {{ hostvars[selected_host].public_ip }}:{{ hostvars[selected_host].public_vpn_port }} +AllowedIPs = {{ hostvars[selected_host].vpn_ip }}/32 +PersistentKeepalive = 25 +{% endfor %} |