feat(vpn): expose Athena services directly over WireGuard
This commit is contained in:
@@ -46,7 +46,7 @@ ip -4 route replace default dev wg0
|
||||
ip -6 route replace default dev wg0 2>/dev/null || true
|
||||
|
||||
cleanup() {
|
||||
kill "${proxy_ui_pid:-}" "${proxy_router_pid:-}" "${proxy_ssh_pid:-}" 2>/dev/null || true
|
||||
[ -z "${proxy_pids:-}" ] || kill $proxy_pids 2>/dev/null || true
|
||||
wg-quick down "$RUNTIME" 2>/dev/null || true
|
||||
}
|
||||
trap cleanup EXIT INT TERM
|
||||
@@ -58,20 +58,42 @@ iptables -A FORWARD -o wg0 -j ACCEPT
|
||||
iptables -A FORWARD -i wg0 -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
|
||||
iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE
|
||||
|
||||
# Nothing is published on the physical host. These listeners exist only in
|
||||
# the WireGuard container namespace and forward VPN clients to internal names.
|
||||
socat TCP-LISTEN:8080,bind=0.0.0.0,reuseaddr,fork TCP:open-webui:8080 &
|
||||
proxy_ui_pid=$!
|
||||
socat TCP-LISTEN:8081,bind=0.0.0.0,reuseaddr,fork TCP:router:8081 &
|
||||
proxy_router_pid=$!
|
||||
|
||||
# Emergency SSH path for unattended operation. Bind explicitly to WireGuard's
|
||||
# IPv4 address, never to a Docker-facing interface or the physical host. The
|
||||
# target is the host-side gateway of the fixed frontend bridge. Host sshd still
|
||||
# enforces its normal key-only authentication policy.
|
||||
wg_ipv4=$(ip -4 -o address show dev wg0 | awk 'NR == 1 { split($4, address, "/"); print address[1] }')
|
||||
[ -n "$wg_ipv4" ] || { echo "WireGuard IPv4 address is missing" >&2; exit 1; }
|
||||
socat TCP-LISTEN:22,bind="$wg_ipv4",reuseaddr,fork TCP:172.30.10.1:22 &
|
||||
proxy_ssh_pid=$!
|
||||
|
||||
wait "$proxy_ui_pid"
|
||||
# The VPN is Athena's normal application network. Nothing below is published
|
||||
# on the physical university interface: every listener is bound inside this
|
||||
# namespace to the Fritzbox-assigned WireGuard address. Clients on the home
|
||||
# VPN may use OpenWebUI, the router and every useful MCP directly.
|
||||
proxy_pids=""
|
||||
start_proxy() {
|
||||
listen_port=$1
|
||||
target=$2
|
||||
socat "TCP-LISTEN:${listen_port},bind=${wg_ipv4},reuseaddr,fork" "TCP:${target}" &
|
||||
proxy_pids="$proxy_pids $!"
|
||||
}
|
||||
|
||||
start_proxy 22 172.30.10.1:22
|
||||
start_proxy 8080 open-webui:8080
|
||||
start_proxy 8081 router:8081
|
||||
start_proxy 8085 tts-gateway:8085
|
||||
start_proxy 8091 piper:8085
|
||||
start_proxy 8092 xtts:80
|
||||
|
||||
# MCP endpoints. Optional services keep their listener even while stopped and
|
||||
# begin working automatically as soon as their container is started.
|
||||
start_proxy 8201 mcp-platform-context:8000
|
||||
start_proxy 8202 mcp-athena-operator:8000
|
||||
start_proxy 8203 mcp-web:8000
|
||||
start_proxy 8204 mcp-github:8000
|
||||
start_proxy 8205 mcp-homeassistant:8000
|
||||
start_proxy 8206 mcp-arr:8000
|
||||
start_proxy 8207 mcp-navidrome:3000
|
||||
start_proxy 8208 mcp-unraid-ssh:8000
|
||||
|
||||
# Search backends are also directly available for diagnostics and alternative
|
||||
# clients. Normal chat clients should prefer the MCP endpoint on 8203.
|
||||
start_proxy 8210 searxng:8080
|
||||
start_proxy 8211 tinysearch:8000
|
||||
|
||||
wait $(printf '%s\n' "$proxy_pids" | awk '{print $2}')
|
||||
|
||||
Reference in New Issue
Block a user