Add fail-closed WireGuard container gateway

This commit is contained in:
Mikei386
2026-08-22 20:48:49 +02:00
parent 2f3bdde8b0
commit 0e5876f1a9
17 changed files with 365 additions and 109 deletions
+9 -3
View File
@@ -3,7 +3,6 @@
AI_HOSTNAME=ki-host
ADMIN_USER=mike
AI_BIND_ADDRESS=10.77.0.2
MODEL_DIR=/srv/mike-ai/models
# Installing a new NVIDIA driver can require one reboot. In that case this
@@ -23,9 +22,16 @@ FLUX_MODEL_DIR=/data/models/FLUX.2-klein-4B
ENABLE_HARDWARE_WATCHDOG=true
PRIMARY_NETWORK_INTERFACE=enp7s0
WAKE_ON_LAN_INTERFACE=enp7s0
SSH_KEY_ONLY=true
# WireGuard client. The home peer must route 10.77.0.2/32 back to this host.
WIREGUARD_ENABLE=true
# WireGuard terminates in a dedicated Docker gateway. The Fritzbox export is a
# root-only deployment secret and must never be committed.
WIREGUARD_MODE=container
WIREGUARD_CONFIG_FILE=/etc/mike-ai/wireguard/fritz-athena.conf
WIREGUARD_ENABLE=false
# The values below are only used by the legacy host-terminated mode. The
# default container mode takes address, peer and routes from the Fritzbox file.
AI_BIND_ADDRESS=10.77.0.2
WG_INTERFACE=wg0
WG_ADDRESS=10.77.0.2/32
WG_HOME_SUBNET=192.168.1.0/24