summaryrefslogtreecommitdiffstats
path: root/roles/wireguard
diff options
context:
space:
mode:
authorAhmed AbdelHalim <[email protected]>2025-08-20 23:37:21 +0200
committerAhmed AbdelHalim <[email protected]>2025-08-21 00:46:50 +0200
commitb8be9cf4e3203490f73835c04c9b97814a61a3d6 (patch)
tree96bb58b08b54997669e6a9c415a53a7f4d1bd277 /roles/wireguard
parent5e80f0bc555ffbe7203d0ab7dac0e759e0f3a217 (diff)
Add wireguard role and fix testing
The testing was failing because the use of the example files with the same domain names, resulted in the files and the molecule variable were being merged and therefore running tasks that would fail on test (example, setting a fake VPN connection that wouldn't start).
Diffstat (limited to 'roles/wireguard')
-rw-r--r--roles/wireguard/defaults/main.yml3
-rw-r--r--roles/wireguard/meta/argument_specs.yml18
-rw-r--r--roles/wireguard/meta/main.yml19
-rw-r--r--roles/wireguard/tasks/main.yml54
-rw-r--r--roles/wireguard/vars/archlinux.yml4
-rw-r--r--roles/wireguard/vars/debian.yml4
6 files changed, 102 insertions, 0 deletions
diff --git a/roles/wireguard/defaults/main.yml b/roles/wireguard/defaults/main.yml
new file mode 100644
index 00000000..7b1d98b9
--- /dev/null
+++ b/roles/wireguard/defaults/main.yml
@@ -0,0 +1,3 @@
+---
+wireguard_connections: {}
+wireguard_autostart_connection: ""
diff --git a/roles/wireguard/meta/argument_specs.yml b/roles/wireguard/meta/argument_specs.yml
new file mode 100644
index 00000000..68e0e821
--- /dev/null
+++ b/roles/wireguard/meta/argument_specs.yml
@@ -0,0 +1,18 @@
+---
+argument_specs:
+ main:
+ short_description: "Install and configure WireGuard VPN connections"
+ description:
+ - "Installs WireGuard package and tools"
+ - "Deploys WireGuard configuration files from dictionary"
+ - "Optionally auto-starts a specific connection on boot"
+ author: "a14m"
+ options:
+ wireguard_connections:
+ description: "Dictionary of WireGuard connection configurations"
+ type: "dict"
+ default: {}
+ wireguard_autostart_connection:
+ description: "Name of connection to automatically start on boot"
+ type: "str"
+ default: ""
diff --git a/roles/wireguard/meta/main.yml b/roles/wireguard/meta/main.yml
new file mode 100644
index 00000000..22da6ddd
--- /dev/null
+++ b/roles/wireguard/meta/main.yml
@@ -0,0 +1,19 @@
+---
+dependencies: []
+
+galaxy_info:
+ author: "a14m"
+ description: "Install and configure WireGuard VPN connections"
+ company: "kartoffeln.work GmbH."
+ license: "MIT"
+ min_ansible_version: "2.18"
+ platforms:
+ - name: "ArchLinux"
+ versions:
+ - "all"
+ - name: "Ubuntu"
+ versions:
+ - "noble"
+ - name: "Debian"
+ versions:
+ - "bookworm"
diff --git a/roles/wireguard/tasks/main.yml b/roles/wireguard/tasks/main.yml
new file mode 100644
index 00000000..45011ea1
--- /dev/null
+++ b/roles/wireguard/tasks/main.yml
@@ -0,0 +1,54 @@
+---
+- name: "Include OS-specific variables"
+ ansible.builtin.include_vars: "{{ ansible_os_family | lower }}.yml"
+
+- name: "Ensure wireguard is installed"
+ become: true
+ ansible.builtin.package:
+ name: "{{ wireguard_pkgs }}"
+ state: "present"
+
+- name: "Create wireguard configuration directory"
+ become: true
+ ansible.builtin.file:
+ path: "/etc/wireguard"
+ state: "directory"
+ owner: "root"
+ group: "root"
+ mode: "0700"
+
+- name: "Deploy WireGuard configurations"
+ become: true
+ ansible.builtin.copy:
+ content: "{{ wireguard_connections[item] }}"
+ dest: "/etc/wireguard/{{ item }}.conf"
+ owner: "root"
+ group: "root"
+ mode: "0600"
+ backup: true
+ with_items: "{{ wireguard_connections }}"
+ when: wireguard_connections | length > 0
+
+- name: "Configure autostart connection"
+ become: true
+ block:
+ - name: "Ensure all wireguard connections are stopped"
+ ansible.builtin.systemd:
+ name: "wg-quick@{{ item }}"
+ enabled: false
+ state: "stopped"
+ with_items: "{{ wireguard_connections.keys() | list }}"
+
+ - name: "Ensure all wireguard interfaces are down"
+ ansible.builtin.command:
+ cmd: "wg-quick down {{ item }}"
+ with_items: "{{ wireguard_connections.keys() | list }}"
+ changed_when: true
+ failed_when: false
+
+ - name: "Enable and start wg-quick service for connection {{ wireguard_autostart_connection }}"
+ ansible.builtin.systemd:
+ name: "wg-quick@{{ wireguard_autostart_connection }}"
+ enabled: true
+ state: "started"
+ when: wireguard_autostart_connection != ""
diff --git a/roles/wireguard/vars/archlinux.yml b/roles/wireguard/vars/archlinux.yml
new file mode 100644
index 00000000..9afa94e4
--- /dev/null
+++ b/roles/wireguard/vars/archlinux.yml
@@ -0,0 +1,4 @@
+---
+wireguard_pkgs:
+ - "wireguard-tools"
+ - "systemd-resolvconf"
diff --git a/roles/wireguard/vars/debian.yml b/roles/wireguard/vars/debian.yml
new file mode 100644
index 00000000..f9c5f5f7
--- /dev/null
+++ b/roles/wireguard/vars/debian.yml
@@ -0,0 +1,4 @@
+---
+wireguard_pkgs:
+ - "wireguard"
+ - "resolvconf"