Add fail-closed WireGuard container gateway

This commit is contained in:
Mikei386
2026-08-22 20:48:49 +02:00
parent 2f3bdde8b0
commit 0e5876f1a9
17 changed files with 365 additions and 109 deletions
+6 -2
View File
@@ -114,13 +114,17 @@ Zielmatrix:
| Port | Zugriff |
|---:|---|
| 22 | nur Administration |
| 8080 | localhost |
| 8081 | vertrauenswürdiges LAN/VPN |
| 8080 | ausschließlich WireGuard-Gateway (Open WebUI) |
| 8081 | ausschließlich WireGuard-Gateway (Router) |
| 8084 | localhost |
| 8085 | localhost |
| 8000 | localhost |
| 5240 | optional nur Administration |
Open WebUI und Router selbst besitzen keine Host-Portfreigaben. Zusätzlich zum
Repository muss die verschlüsselt gesicherte Fritzbox-Clientdatei als
`/etc/mike-ai/wireguard/fritz-athena.conf` (0600) wiederhergestellt werden.
## 6. Speicherlayout – offen
Vor dem Neuaufbau festlegen: