Repository navigation
feat(wireguard): restore PSK on main + PresharedKey/default-route in client configs - #3
Merged
Merged
Conversation
…client configs main (noden.11 / #2 "order-independent key provenance") had unintentionally dropped the preshared-key feature that the deployed noden.10 release carries, and the generated client configs never emitted PresharedKey or a usable AllowedIPs. This re-integrates the PSK feature on top of #2's provenance model and fixes the downloadable client configs. Server side (parity with deployed noden.10, layered on #2): - api: re-add the in-memory WireguardPeerSpec.PresharedKey field (populated by the controller from the `<name>-peer` convention Secret's `presharedKey` key; never patched back / non-persistent). Regenerated CRD + deepcopy. - wireguard.go: emit `PresharedKey = <v>` in the server-side [Peer] block when resolved (absent => byte-identical to before). +2 unit tests. - wireguard_controller.go: read `presharedKey` from `<name>-peer` into agent state; add the server-keypair fail-closed check main was missing (curve25519 derive vs stored publicKey -> Degraded). Did NOT port noden.10's peer-level fail-closed check: #2's provenance (generated keys yield, hard-set fail closed) supersedes it. Client side (the bug that broke michael-hobl/pivit): - emit `PresharedKey` in all three generated client templates (read from the same `<name>-peer` Secret) so the handshake isn't silently dropped. - AllowedIPs: always hand out a full-tunnel default route instead of the peer's own <addr>/32 (which routed nothing into the tunnel). build/vet/gofmt clean; controller envtest suite (incl. #2 provenance specs) + ipam/iptables/resources/wireguard packages all green.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
noden/main(noden.11 / #2 "order-independent key provenance") unintentionally dropped the preshared-key feature that the deployednoden.10release carries — deploying it as-is would remove server-side PSK rendering and break every migrated peer's handshake. Separately, the generated client configs in<wg>-peer-configsnever emittedPresharedKeyor a usableAllowedIPs, so a freshly-built client config (e.g. michael-hobl/pivit) fails its handshake silently.This makes
mainencompass everything:#2's provenance work + the PSK feature + correct client configs.Server side (parity with deployed
noden.10, layered on#2)WireguardPeerSpec.PresharedKey(populated from the<name>-peerconvention Secret'spresharedKeykey; never patched back). Regenerated CRD + deepcopy.PresharedKeyin the server[Peer]block when resolved (absent ⇒ byte-identical). +2 unit tests.presharedKeyfrom<name>-peerinto agent state; add the server-keypair fail-closed check main was missing.noden.10's peer-level fail-closed check —#2's provenance (generated keys yield, hard-set fail closed) supersedes it and porting it would fight "generated keys yield."Client side (the bug)
PresharedKeyin all three generated client templates.AllowedIPs: always hand out a full-tunnel default route instead of the peer's own<addr>/32.Tests
build/vet/gofmt clean; controller envtest suite (incl.
#2provenance specs) + ipam/iptables/resources/wireguard packages all green.Follow-up
After merge, the plan is to retire the
noden-vX.Y.Z-noden.Ntag-release structure and point the cluster atmain's image.