Compare commits
8 Commits
role_wireg
...
role_kuber
| Author | SHA1 | Date | |
|---|---|---|---|
| b8ae38bab8 | |||
| 093612f3a7 | |||
| a92409c56f | |||
| f50e3ac33c | |||
| 668ff23ee6 | |||
| c2c6a2872f | |||
| c1c7ec9e56 | |||
| 550f6868ff |
@@ -1,3 +0,0 @@
|
|||||||
---
|
|
||||||
dependencies: []
|
|
||||||
#- role: docker
|
|
||||||
@@ -1,8 +0,0 @@
|
|||||||
- import_tasks: ./certs.yml
|
|
||||||
|
|
||||||
- import_tasks: ./install.yml
|
|
||||||
|
|
||||||
- import_tasks: ./join-network.yml
|
|
||||||
|
|
||||||
- name: Gather facts to get changes
|
|
||||||
ansible.builtin.gather_facts:
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
ipv6_stable_secret: 1111:2222:3333:4444:5555:6666:7777:8888
|
|
||||||
@@ -5,5 +5,3 @@
|
|||||||
- import_tasks: ./packages.yml
|
- import_tasks: ./packages.yml
|
||||||
|
|
||||||
- import_tasks: ./aliases.yml
|
- import_tasks: ./aliases.yml
|
||||||
|
|
||||||
- import_tasks: ./networking.yml
|
|
||||||
|
|||||||
@@ -1,22 +0,0 @@
|
|||||||
- name: Set sysctl settings for ip-forwarding
|
|
||||||
copy:
|
|
||||||
dest: "/etc/sysctl.d/ip-forwarding.conf"
|
|
||||||
content: |
|
|
||||||
net.ipv4.ip_forward = 1
|
|
||||||
net.ipv6.conf.all.forwarding = 1
|
|
||||||
notify: reload_sysctl
|
|
||||||
|
|
||||||
- name: Set sysctl settings for ipv6-address-generation
|
|
||||||
copy:
|
|
||||||
dest: "/etc/sysctl.d/ipv6-slaac-address-generation.conf"
|
|
||||||
content: |
|
|
||||||
net.ipv6.conf.default.addr_gen_mode = 2
|
|
||||||
net.ipv6.conf.default.stable_secret = {{ ipv6_stable_secret }}
|
|
||||||
notify: reload_sysctl
|
|
||||||
|
|
||||||
- name: Set sysctl settings to override ipv6-slaac with enabled forwarding
|
|
||||||
copy:
|
|
||||||
dest: "/etc/sysctl.d/ipv6-slaac-override.conf"
|
|
||||||
content: |
|
|
||||||
net.ipv6.conf.all.accept_ra = 2
|
|
||||||
notify: reload_sysctl
|
|
||||||
@@ -1,13 +1,12 @@
|
|||||||
- name: Install K3s agent
|
- name: Install K3s agent
|
||||||
command: /root/k3s_install.sh {{ type }}
|
command: /root/k3s_install.sh {{ type }}
|
||||||
register: command
|
register: command
|
||||||
changed_when: "'No change detected' in command.stdout"
|
changed_when: "'No change detected' not in command.stdout"
|
||||||
until: "command is not failed"
|
until: "command is not failed"
|
||||||
retries: 2
|
retries: 2
|
||||||
delay: 10
|
delay: 10
|
||||||
|
|
||||||
- name: Restart when config changed, but install already done
|
- name: Make sure service is started / restarted on config change
|
||||||
service:
|
service:
|
||||||
name: k3s
|
name: k3s-agent
|
||||||
status: restarted
|
state: "{{ 'restarted' if not command.changed and config.changed else 'started' }}"
|
||||||
when: "inventory_hostname != groups['kubernetes'][0] and not command.changed and config.changed"
|
|
||||||
|
|||||||
@@ -2,17 +2,17 @@
|
|||||||
command: /root/k3s_install.sh {{ type }}
|
command: /root/k3s_install.sh {{ type }}
|
||||||
when: "inventory_hostname == groups['kubernetes'][0]"
|
when: "inventory_hostname == groups['kubernetes'][0]"
|
||||||
register: command
|
register: command
|
||||||
changed_when: "'No change detected' in command.stdout"
|
changed_when: "'No change detected' not in command.stdout"
|
||||||
|
|
||||||
- name: Restart when config changed, but install already done
|
- name: Make sure service is started / restarted on config change
|
||||||
service:
|
service:
|
||||||
name: k3s
|
name: k3s
|
||||||
status: restarted
|
state: "{{ 'restarted' if not command.changed and config.changed else 'started' }}"
|
||||||
when: "inventory_hostname == groups['kubernetes'][0] and not command.changed and config.changed"
|
when: "inventory_hostname == groups['kubernetes'][0]"
|
||||||
|
|
||||||
- name: Waiting for K3s-server to accept connections
|
- name: Waiting for K3s-server to accept connections
|
||||||
ansible.builtin.wait_for:
|
ansible.builtin.wait_for:
|
||||||
host: "{{ inventory_hostname }}"
|
host: "127.0.0.1"
|
||||||
port: 6443
|
port: 6443
|
||||||
state: started
|
state: started
|
||||||
when: "inventory_hostname == groups['kubernetes'][0]"
|
when: "inventory_hostname == groups['kubernetes'][0]"
|
||||||
@@ -21,20 +21,20 @@
|
|||||||
command: /root/k3s_install.sh {{ type }}
|
command: /root/k3s_install.sh {{ type }}
|
||||||
when: "inventory_hostname != groups['kubernetes'][0]"
|
when: "inventory_hostname != groups['kubernetes'][0]"
|
||||||
register: command
|
register: command
|
||||||
changed_when: "'No change detected' in command.stdout"
|
changed_when: "'No change detected' not in command.stdout"
|
||||||
until: "command is not failed"
|
until: "command is not failed"
|
||||||
retries: 2
|
retries: 2
|
||||||
delay: 10
|
delay: 10
|
||||||
|
|
||||||
- name: Restart when config changed, but install already done
|
- name: Make sure service is started / restarted on config change
|
||||||
service:
|
service:
|
||||||
name: k3s
|
name: k3s
|
||||||
status: restarted
|
state: "{{ 'restarted' if not command.changed and config.changed else 'started' }}"
|
||||||
when: "inventory_hostname != groups['kubernetes'][0] and not command.changed and config.changed"
|
when: "inventory_hostname != groups['kubernetes'][0]"
|
||||||
|
|
||||||
- name: Waiting for K3s-server to accept connections on other nodes
|
- name: Waiting for K3s-server to accept connections on other nodes
|
||||||
ansible.builtin.wait_for:
|
ansible.builtin.wait_for:
|
||||||
host: "{{ inventory_hostname }}"
|
host: "127.0.0.1"
|
||||||
port: 6443
|
port: 6443
|
||||||
state: started
|
state: started
|
||||||
when: "inventory_hostname != groups['kubernetes'][0]"
|
when: "inventory_hostname != groups['kubernetes'][0]"
|
||||||
|
|||||||
@@ -3,6 +3,8 @@
|
|||||||
register: command
|
register: command
|
||||||
changed_when: "'created' in command.stdout"
|
changed_when: "'created' in command.stdout"
|
||||||
run_once: true
|
run_once: true
|
||||||
|
failed_when:
|
||||||
|
- "command.rc == 1 and 'AlreadyExists' not in command.stderr"
|
||||||
|
|
||||||
- name: Deploy calico ressource template
|
- name: Deploy calico ressource template
|
||||||
ansible.builtin.template:
|
ansible.builtin.template:
|
||||||
|
|||||||
@@ -1,11 +1,8 @@
|
|||||||
server: https://{{ kubernetes.control_plane.dns_name }}:6443
|
server: https://{{ hostvars[groups['kubernetes'][0]]['nodeip_ipv4'] }}:6443
|
||||||
token: '{{ kubernetes.token }}'
|
token: '{{ kubernetes.token }}'
|
||||||
|
|
||||||
{% if nodeip_ipv6 != "" and kubernetes.ipPool.ipv6 is defined %}
|
{% if nodeip_ipv6 != "" and kubernetes.ipPool.ipv6 is defined %}
|
||||||
node-ip: {{ nodeip_ipv4 }},{{ nodeip_ipv6 }}
|
node-ip: {{ nodeip_ipv4 }},{{ nodeip_ipv6 }}
|
||||||
|
|
||||||
# FIXME: Workaround for bug in Kubernetes 1.24/1.25 ignoring node IPv6 addresses
|
|
||||||
kubelet-arg: "--node-ip=0.0.0.0"
|
|
||||||
{% else %}
|
{% else %}
|
||||||
node-ip: {{ nodeip_ipv4 }}
|
node-ip: {{ nodeip_ipv4 }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
|
|||||||
@@ -15,9 +15,6 @@ tls-san:
|
|||||||
node-ip: {{ nodeip_ipv4 }},{{ nodeip_ipv6 }}
|
node-ip: {{ nodeip_ipv4 }},{{ nodeip_ipv6 }}
|
||||||
cluster-cidr: {{ kubernetes.ipPool.ipv4.cluster_cidr }},{{ kubernetes.ipPool.ipv6.cluster_cidr }}
|
cluster-cidr: {{ kubernetes.ipPool.ipv4.cluster_cidr }},{{ kubernetes.ipPool.ipv6.cluster_cidr }}
|
||||||
service-cidr: {{ kubernetes.ipPool.ipv4.service_cidr }},{{ kubernetes.ipPool.ipv6.service_cidr }}
|
service-cidr: {{ kubernetes.ipPool.ipv4.service_cidr }},{{ kubernetes.ipPool.ipv6.service_cidr }}
|
||||||
|
|
||||||
# FIXME: Workaround for bug in Kubernetes 1.24/1.25 ignoring node IPv6 addresses
|
|
||||||
kubelet-arg: "--node-ip=0.0.0.0"
|
|
||||||
{% else %}
|
{% else %}
|
||||||
node-ip: {{ nodeip_ipv4 }}
|
node-ip: {{ nodeip_ipv4 }}
|
||||||
cluster-cidr: {{ kubernetes.ipPool.ipv4.cluster_cidr }}
|
cluster-cidr: {{ kubernetes.ipPool.ipv4.cluster_cidr }}
|
||||||
@@ -27,7 +24,7 @@ service-cidr: {{ kubernetes.ipPool.ipv4.service_cidr }}
|
|||||||
egress-selector-mode: disabled
|
egress-selector-mode: disabled
|
||||||
|
|
||||||
# Network-plugin
|
# Network-plugin
|
||||||
{% if kubernetes.network_plugin == "flannel" %}
|
{% if kubernetes.network.plugin == "flannel" %}
|
||||||
flannel-backend: vxlan
|
flannel-backend: vxlan
|
||||||
{% else %}
|
{% else %}
|
||||||
disable-network-policy: true
|
disable-network-policy: true
|
||||||
|
|||||||
@@ -1,6 +0,0 @@
|
|||||||
netbird_client:
|
|
||||||
# Key and url to join a network
|
|
||||||
# leave empty to ignore
|
|
||||||
join_network:
|
|
||||||
setup_key:
|
|
||||||
management_url:
|
|
||||||
@@ -1,26 +0,0 @@
|
|||||||
- name: Install Packages
|
|
||||||
# when: docker_file.stat.exists == False
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- ca-certificates
|
|
||||||
- curl
|
|
||||||
- gnupg
|
|
||||||
|
|
||||||
- name: Add netbird-key
|
|
||||||
apt_key:
|
|
||||||
url: https://pkgs.wiretrustee.com/debian/public.key
|
|
||||||
state: present
|
|
||||||
|
|
||||||
- name: Add netbird-repository
|
|
||||||
apt_repository:
|
|
||||||
repo: "deb https://pkgs.wiretrustee.com/debian stable main"
|
|
||||||
state: present
|
|
||||||
filename: netbird
|
|
||||||
update_cache: yes
|
|
||||||
|
|
||||||
- name: Install wireguard & netbird
|
|
||||||
package:
|
|
||||||
name:
|
|
||||||
- wireguard
|
|
||||||
- netbird
|
|
||||||
state: latest
|
|
||||||
@@ -1,16 +0,0 @@
|
|||||||
- name: Join netbird-network
|
|
||||||
when: "netbird_client.join_network.setup_key is defined"
|
|
||||||
command: "netbird up --management-url {{ netbird_client.join_network.management_url }} --setup-key {{ netbird_client.join_network.setup_key }}"
|
|
||||||
failed_when: command.rc != 0
|
|
||||||
changed_when: "'Connected' in command.stdout"
|
|
||||||
register: command
|
|
||||||
|
|
||||||
- name: Wait for netbird-interface to exist
|
|
||||||
wait_for:
|
|
||||||
path: "/sys/class/net/wt0"
|
|
||||||
state: present
|
|
||||||
when: command.changed
|
|
||||||
|
|
||||||
- name: Gather facts to get changes
|
|
||||||
ansible.builtin.gather_facts:
|
|
||||||
when: command.changed
|
|
||||||
3
netmaker/meta/main.yml
Normal file
3
netmaker/meta/main.yml
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
---
|
||||||
|
dependencies:
|
||||||
|
- role: docker
|
||||||
@@ -2,6 +2,4 @@
|
|||||||
when: "netclient.join_network_token is defined"
|
when: "netclient.join_network_token is defined"
|
||||||
command: "netclient join -t {{ netclient.join_network_token }}"
|
command: "netclient join -t {{ netclient.join_network_token }}"
|
||||||
failed_when: command.rc != 0
|
failed_when: command.rc != 0
|
||||||
changed_when: "'starting wireguard' in command.stdout"
|
|
||||||
register: command
|
register: command
|
||||||
throttle: 1
|
|
||||||
@@ -1,4 +1,5 @@
|
|||||||
|
- import_tasks: ./certs.yml
|
||||||
|
|
||||||
- import_tasks: ./install.yml
|
- import_tasks: ./install.yml
|
||||||
|
|
||||||
- import_tasks: ./join-network.yml
|
- import_tasks: ./join-network.yml
|
||||||
|
|
||||||
@@ -30,7 +30,7 @@ component netmaker_server {
|
|||||||
component nm_api
|
component nm_api
|
||||||
nm_api -down- nm_api_http
|
nm_api -down- nm_api_http
|
||||||
ng_http --( nm_api_http
|
ng_http --( nm_api_http
|
||||||
nm_api .up.( ng_TLS : db-connection to rqlite-master
|
nm_api -up-( ng_TLS : db-connection to rqlite-master
|
||||||
nm_api --( mq_plain
|
nm_api --( mq_plain
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1,11 +1,11 @@
|
|||||||
per_listener_settings false
|
per_listener_settings false
|
||||||
|
|
||||||
listener 8883
|
listener 8883
|
||||||
protocol websockets
|
|
||||||
allow_anonymous false
|
allow_anonymous false
|
||||||
|
certfile /certs/node.crt
|
||||||
|
keyfile /certs/node.key
|
||||||
|
|
||||||
listener 1883
|
listener 1883
|
||||||
protocol websockets
|
|
||||||
allow_anonymous false
|
allow_anonymous false
|
||||||
|
|
||||||
plugin /usr/lib/mosquitto_dynamic_security.so
|
plugin /usr/lib/mosquitto_dynamic_security.so
|
||||||
@@ -30,7 +30,7 @@
|
|||||||
headers:
|
headers:
|
||||||
Authorization: 'Bearer {{ netmaker_creds.master_key }}'
|
Authorization: 'Bearer {{ netmaker_creds.master_key }}'
|
||||||
Content-Type: application/json
|
Content-Type: application/json
|
||||||
when: "inventory_hostname == groups['netmaker_server'][0]"
|
when: "inventory_hostname == groups['netmaker'][0]"
|
||||||
register: default_mesh
|
register: default_mesh
|
||||||
until: "default_mesh is not failed"
|
until: "default_mesh is not failed"
|
||||||
retries: 2
|
retries: 2
|
||||||
@@ -50,7 +50,7 @@
|
|||||||
headers:
|
headers:
|
||||||
Authorization: 'Bearer {{ netmaker_creds.master_key }}'
|
Authorization: 'Bearer {{ netmaker_creds.master_key }}'
|
||||||
Content-Type: application/json
|
Content-Type: application/json
|
||||||
when: "inventory_hostname == groups['netmaker_server'][0]"
|
when: "inventory_hostname == groups['netmaker'][0]"
|
||||||
register: default_mesh_key
|
register: default_mesh_key
|
||||||
until: "default_mesh_key is not failed"
|
until: "default_mesh_key is not failed"
|
||||||
retries: 2
|
retries: 2
|
||||||
@@ -33,15 +33,15 @@ services:
|
|||||||
|
|
||||||
-auth /config.json
|
-auth /config.json
|
||||||
|
|
||||||
{% if inventory_hostname != groups['netmaker_server'][0] %}
|
{% if inventory_hostname != groups['netmaker'][0] %}
|
||||||
-join-as netmaker
|
-join-as netmaker
|
||||||
-join https://{{ netmaker_rqlite.http_host }}.{{ groups['netmaker_server'][0] }}:{{ netmaker_nginx.advertise_port }}
|
-join https://{{ netmaker_rqlite.http_host }}.{{ groups['netmaker'][0] }}:{{ netmaker_nginx.advertise_port }}
|
||||||
{% endif %}
|
{% endif %}
|
||||||
"
|
"
|
||||||
# FIXME: /\ \/ Change http -> https
|
# FIXME: /\ \/ Change http -> https
|
||||||
|
|
||||||
netmaker: # The Primary Server for running Netmaker
|
netmaker: # The Primary Server for running Netmaker
|
||||||
image: gravitl/netmaker:v0.17.1
|
image: gravitl/netmaker:v0.16.1
|
||||||
depends_on:
|
depends_on:
|
||||||
- rqlite
|
- rqlite
|
||||||
cap_add:
|
cap_add:
|
||||||
@@ -104,7 +104,7 @@ services:
|
|||||||
- "51821-51830:51821-51830/udp" # wireguard ports
|
- "51821-51830:51821-51830/udp" # wireguard ports
|
||||||
|
|
||||||
netmaker-ui: # The Netmaker UI Component
|
netmaker-ui: # The Netmaker UI Component
|
||||||
image: gravitl/netmaker-ui:v0.17.1
|
image: gravitl/netmaker-ui:v0.16.1
|
||||||
depends_on:
|
depends_on:
|
||||||
- netmaker
|
- netmaker
|
||||||
links:
|
links:
|
||||||
@@ -120,6 +120,7 @@ services:
|
|||||||
- ./mosquitto/config:/mosquitto/config
|
- ./mosquitto/config:/mosquitto/config
|
||||||
- ./mosquitto/data:/mosquitto/data
|
- ./mosquitto/data:/mosquitto/data
|
||||||
- ./mosquitto/logs:/mosquitto/log
|
- ./mosquitto/logs:/mosquitto/log
|
||||||
|
- "./certs:/certs:ro"
|
||||||
depends_on:
|
depends_on:
|
||||||
- netmaker
|
- netmaker
|
||||||
command: ["/mosquitto/config/wait.sh"]
|
command: ["/mosquitto/config/wait.sh"]
|
||||||
@@ -6,7 +6,7 @@ stream{
|
|||||||
{{ netmaker_ui.host }}.{{ netmaker_base_domain }} 127.0.0.1:8443;
|
{{ netmaker_ui.host }}.{{ netmaker_base_domain }} 127.0.0.1:8443;
|
||||||
{{ netmaker_api.host }}.{{ netmaker_base_domain }} 127.0.0.1:8443;
|
{{ netmaker_api.host }}.{{ netmaker_base_domain }} 127.0.0.1:8443;
|
||||||
|
|
||||||
{{ netmaker_broker.tls_host }}.{{ netmaker_base_domain }} 127.0.0.1:8443;
|
{{ netmaker_broker.tls_host }}.{{ netmaker_base_domain }} mosquitto:8883; # todo: tls-terminate?
|
||||||
|
|
||||||
{{ netmaker_rqlite.http_host }}.{{ ansible_facts.nodename }} 127.0.0.1:8443;
|
{{ netmaker_rqlite.http_host }}.{{ ansible_facts.nodename }} 127.0.0.1:8443;
|
||||||
{{ netmaker_rqlite.cluster_host }}.{{ ansible_facts.nodename }} rqlite:4002;
|
{{ netmaker_rqlite.cluster_host }}.{{ ansible_facts.nodename }} rqlite:4002;
|
||||||
@@ -4,8 +4,6 @@ map $host $proxy_name {
|
|||||||
{{ netmaker_ui.host }}.{{ netmaker_base_domain }} netmaker-ui:80;
|
{{ netmaker_ui.host }}.{{ netmaker_base_domain }} netmaker-ui:80;
|
||||||
{{ netmaker_api.host }}.{{ netmaker_base_domain }} netmaker:8081;
|
{{ netmaker_api.host }}.{{ netmaker_base_domain }} netmaker:8081;
|
||||||
|
|
||||||
{{ netmaker_broker.tls_host }}.{{ netmaker_base_domain }} mosquitto:8883;
|
|
||||||
|
|
||||||
{{ netmaker_rqlite.http_host }}.{{ ansible_facts.nodename }} rqlite:4001;
|
{{ netmaker_rqlite.http_host }}.{{ ansible_facts.nodename }} rqlite:4001;
|
||||||
|
|
||||||
default 444;
|
default 444;
|
||||||
@@ -1,12 +0,0 @@
|
|||||||
wireguard_ipv6_converter:
|
|
||||||
version: latest
|
|
||||||
|
|
||||||
# see https://github.com/Ruakij/wg-ipv6-converter#31-environment
|
|
||||||
setup:
|
|
||||||
interface: wg0
|
|
||||||
#ipv6_format: fc12::%02x%02x:%02x%02x/%d
|
|
||||||
#filter_prefix: 100.100
|
|
||||||
#recheck_interval: 60s
|
|
||||||
|
|
||||||
service:
|
|
||||||
#bindTo: netbird.service
|
|
||||||
@@ -1,11 +0,0 @@
|
|||||||
- name: Get architecture
|
|
||||||
set_fact:
|
|
||||||
arch: "{{ 'amd64' if ansible_architecture == 'x86_64' else 'arm64' }}"
|
|
||||||
versionUri: "{% if wireguard_ipv6_converter.version == 'latest' %}latest/download{% else %}download/{{ wireguard_ipv6_converter.version }}{% endif %}"
|
|
||||||
|
|
||||||
- name: Download binary
|
|
||||||
get_url:
|
|
||||||
url: https://github.com/Ruakij/wg-ipv6-converter/releases/{{ versionUri }}/wg-ipv6-converter_{{ arch }}
|
|
||||||
dest: /usr/local/bin/wg-ipv6-converter
|
|
||||||
mode: "744"
|
|
||||||
register: deployDownload
|
|
||||||
@@ -1,3 +0,0 @@
|
|||||||
- import_tasks: ./deploy.yml
|
|
||||||
|
|
||||||
- import_tasks: ./setup-service.yml
|
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
- name: Deploy service
|
|
||||||
ansible.builtin.template:
|
|
||||||
src: wg-ipv6-conv.service.jinja2
|
|
||||||
dest: /etc/systemd/system/wg-ipv6-converter_{{ wireguard_ipv6_converter.setup.interface }}.service
|
|
||||||
register: serviceFile
|
|
||||||
|
|
||||||
- name: Enable service
|
|
||||||
ansible.builtin.service:
|
|
||||||
name: wg-ipv6-converter_{{ wireguard_ipv6_converter.setup.interface }}
|
|
||||||
daemon-reload: true
|
|
||||||
enabled: true
|
|
||||||
|
|
||||||
- name: Start service if interface exists already
|
|
||||||
ansible.builtin.service:
|
|
||||||
name: wg-ipv6-converter_{{ wireguard_ipv6_converter.setup.interface }}
|
|
||||||
state: "{{ 'restarted' if deployDownload.changed or serviceFile.changed else 'started' }}"
|
|
||||||
register: service
|
|
||||||
when: "wireguard_ipv6_converter.setup.interface in ansible_interfaces"
|
|
||||||
|
|
||||||
- name: Pause for 5s to wait for program to have run
|
|
||||||
ansible.builtin.pause:
|
|
||||||
seconds: 5
|
|
||||||
when: "service.changed"
|
|
||||||
|
|
||||||
- name: Gather facts to get changes
|
|
||||||
ansible.builtin.gather_facts:
|
|
||||||
when: "service.changed"
|
|
||||||
@@ -1,29 +0,0 @@
|
|||||||
[Unit]
|
|
||||||
Description=WireGuard IPv6 converter for {{ wireguard_ipv6_converter.setup.interface }}
|
|
||||||
{% if wireguard_ipv6_converter.service.bindTo is defined %}
|
|
||||||
BindsTo={{ wireguard_ipv6_converter.service.bindTo }}
|
|
||||||
After={{ wireguard_ipv6_converter.service.bindTo }}
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=simple
|
|
||||||
{% if wireguard_ipv6_converter.service.bindTo is defined %}
|
|
||||||
ExecStartPre=/bin/sleep 10
|
|
||||||
{% endif %}
|
|
||||||
ExecStart=/usr/local/bin/wg-ipv6-converter
|
|
||||||
Restart=always
|
|
||||||
RestartSec=30
|
|
||||||
|
|
||||||
Environment="INTERFACE={{ wireguard_ipv6_converter.setup.interface }}"
|
|
||||||
{% if wireguard_ipv6_converter.setup.ipv6_format is defined %}
|
|
||||||
Environment="IPV6_FORMAT={{ wireguard_ipv6_converter.setup.ipv6_format }}"
|
|
||||||
{% endif %}
|
|
||||||
{% if wireguard_ipv6_converter.setup.filter_prefix is defined %}
|
|
||||||
Environment="FILTER_PREFIX={{ wireguard_ipv6_converter.setup.filter_prefix }}"
|
|
||||||
{% endif %}
|
|
||||||
{% if wireguard_ipv6_converter.setup.recheck_interval is defined %}
|
|
||||||
Environment="RECHECK_INTERVAL={{ wireguard_ipv6_converter.setup.recheck_interval }}"
|
|
||||||
{% endif %}
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=multi-user.target
|
|
||||||
Reference in New Issue
Block a user