diff options
Diffstat (limited to 'ansible/roles/network/templates')
-rw-r--r-- | ansible/roles/network/templates/rules.v4.j2 | 4 | ||||
-rw-r--r-- | ansible/roles/network/templates/wireguard.conf.j2 | 12 |
2 files changed, 14 insertions, 2 deletions
diff --git a/ansible/roles/network/templates/rules.v4.j2 b/ansible/roles/network/templates/rules.v4.j2 index a446139..ef2cf64 100644 --- a/ansible/roles/network/templates/rules.v4.j2 +++ b/ansible/roles/network/templates/rules.v4.j2 @@ -10,8 +10,8 @@ -A INPUT -s 192.168.1.254 -j ACCEPT -A INPUT -s 82.253.205.190 -j ACCEPT {% for selected_host in groups['cluster_nodes'] %} --A INPUT -s {{ hostvars[selected_host]['public_ip'] }} -j ACCEPT --A INPUT -s {{ hostvars[selected_host]['private_ip'] }} -j ACCEPT +-A INPUT -s {{ hostvars[selected_host]['public_ip'] }} -p udp --dport 51820 -j ACCEPT +-A INPUT -s {{ hostvars[selected_host]['vpn_ip'] }} -j ACCEPT {% endfor %} # Local diff --git a/ansible/roles/network/templates/wireguard.conf.j2 b/ansible/roles/network/templates/wireguard.conf.j2 new file mode 100644 index 0000000..907d546 --- /dev/null +++ b/ansible/roles/network/templates/wireguard.conf.j2 @@ -0,0 +1,12 @@ +[Interface] +Address = {{ vpn_ip }} +PrivateKey = {{ wireguard_privkey.stdout }} +ListenPort = 51820 + +{% for selected_host in groups['cluster_nodes']|difference([inventory_hostname]) %} +[Peer] +PublicKey = {{ hostvars[selected_host].wireguard_pubkey.stdout }} +Endpoint = {{ hostvars[selected_host].public_ip }}:{{ hostvars[selected_host].public_vpn_port }} +AllowedIPs = {{ hostvars[selected_host].vpn_ip }}/32 +PersistentKeepalive = 25 +{% endfor %} |