Skip to content

feat(wireguard): restore PSK on main + PresharedKey/default-route in client configs - #3

Merged
mxhob1 merged 1 commit into
noden/mainfrom
feat/wg-main-encompass-psk-clientcfg
Jun 5, 2026
Merged

mxhob1 merged 1 commit into
noden/mainfrom
feat/wg-main-encompass-psk-clientcfg

Conversation

@mxhob1

@mxhob1 mxhob1 commented Jun 5, 2026

Copy link
Copy Markdown
Member

Why

noden/main (noden.11 / #2 "order-independent key provenance") unintentionally dropped the preshared-key feature that the deployed noden.10 release carries — deploying it as-is would remove server-side PSK rendering and break every migrated peer's handshake. Separately, the generated client configs in <wg>-peer-configs never emitted PresharedKey or a usable AllowedIPs, so a freshly-built client config (e.g. michael-hobl/pivit) fails its handshake silently.

This makes main encompass everything: #2's provenance work + the PSK feature + correct client configs.

Server side (parity with deployed noden.10, layered on #2)

  • api/CRD: re-add in-memory WireguardPeerSpec.PresharedKey (populated from the <name>-peer convention Secret's presharedKey key; never patched back). Regenerated CRD + deepcopy.
  • wireguard.go: emit PresharedKey in the server [Peer] block when resolved (absent ⇒ byte-identical). +2 unit tests.
  • wireguard_controller.go: read presharedKey from <name>-peer into agent state; add the server-keypair fail-closed check main was missing.
  • Deliberately did not port noden.10's peer-level fail-closed check — #2's provenance (generated keys yield, hard-set fail closed) supersedes it and porting it would fight "generated keys yield."

Client side (the bug)

  • emit PresharedKey in all three generated client templates.
  • AllowedIPs: always hand out a full-tunnel default route instead of the peer's own <addr>/32.

Tests

build/vet/gofmt clean; controller envtest suite (incl. #2 provenance specs) + ipam/iptables/resources/wireguard packages all green.

Follow-up

After merge, the plan is to retire the noden-vX.Y.Z-noden.N tag-release structure and point the cluster at main's image.

…client configs

main (noden.11 / #2 "order-independent key provenance") had unintentionally
dropped the preshared-key feature that the deployed noden.10 release carries,
and the generated client configs never emitted PresharedKey or a usable
AllowedIPs. This re-integrates the PSK feature on top of #2's provenance model
and fixes the downloadable client configs.

Server side (parity with deployed noden.10, layered on #2):
- api: re-add the in-memory WireguardPeerSpec.PresharedKey field (populated by
  the controller from the `<name>-peer` convention Secret's `presharedKey` key;
  never patched back / non-persistent). Regenerated CRD + deepcopy.
- wireguard.go: emit `PresharedKey = <v>` in the server-side [Peer] block when
  resolved (absent => byte-identical to before). +2 unit tests.
- wireguard_controller.go: read `presharedKey` from `<name>-peer` into agent
  state; add the server-keypair fail-closed check main was missing (curve25519
  derive vs stored publicKey -> Degraded). Did NOT port noden.10's peer-level
  fail-closed check: #2's provenance (generated keys yield, hard-set fail
  closed) supersedes it.

Client side (the bug that broke michael-hobl/pivit):
- emit `PresharedKey` in all three generated client templates (read from the
  same `<name>-peer` Secret) so the handshake isn't silently dropped.
- AllowedIPs: always hand out a full-tunnel default route instead of the
  peer's own <addr>/32 (which routed nothing into the tunnel).

build/vet/gofmt clean; controller envtest suite (incl. #2 provenance specs) +
ipam/iptables/resources/wireguard packages all green.
@mxhob1
mxhob1 merged commit a9d15f0 into noden/main Jun 5, 2026
7 of 8 checks passed
@mxhob1
mxhob1 deleted the feat/wg-main-encompass-psk-clientcfg branch June 5, 2026 06:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant