Files
infrastructure/docs/wireguard.md
Kristian Klausen 2f9c41ab0a docs: Document how to get the WG public key from systemd-creds
Also rearranged the documentation a bit.

Fixes: 27553ab3 ("Remove the WG private keys from the vault and store them only on the servers")
2025-03-02 17:53:49 +01:00

1.0 KiB

WireGuard

Many of our servers communicate through wireguard VPN with each others. If you need to collect logs with loki and metrics with prometheus for dashboards you need to have a wiregauard IP.

Setting up

  1. For a new server add a new unused wireguard IP and set the following in host_vars/<fqdn>/misc

    wireguard_address: <wg-ip>
    wireguard_public_key: <wg-pubkey>
    
  2. Generate the private key on the server with wg genkey | systemd-creds encrypt - /etc/credstore.encrypted/network.wireguard.private.wg0 and restart systemd-networkd with systemctl restart systemd-networkd

  3. Get public key with: systemd-creds decrypt /etc/credstore.encrypted/network.wireguard.private.wg0 - | wg pubkey

  4. Execute wireguard and prometheus roles on monitoring.archlinux.org.yml playbook to get data from the server

Tips: