feat(wg): clusev-wg-gate.service — boot/docker-restart gate persistence
parent
8caa78b2b3
commit
1e9834fc0d
|
|
@ -0,0 +1,25 @@
|
|||
# Clusev WireGuard gate — persistence oneshot (HOST-side).
|
||||
#
|
||||
# Re-applies the CLUSEV-WG-GATE iptables chain after boot and after a Docker daemon restart (Docker
|
||||
# flushes DOCKER-USER). It is a no-op unless BOTH are true:
|
||||
# - wg0 is up (ConditionPathExists below — a failed wg0 on boot leaves the panel OPEN, not bricked)
|
||||
# - the gate marker (/etc/clusev/wg-gate.enabled, checked inside `clusev-wg.sh gate-apply`)
|
||||
# So `clusev wg down` (removes the marker) survives a reboot, and a tunnel that fails to come up never
|
||||
# drops the panel with no way in. install.sh rewrites the /home/nexxo/clusev paths to the real tree.
|
||||
[Unit]
|
||||
Description=Clusev WireGuard gate — re-apply the panel firewall when wg0 is up
|
||||
After=docker.service wg-quick@wg0.service
|
||||
Wants=docker.service
|
||||
ConditionPathExists=/sys/class/net/wg0
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
User=root
|
||||
Environment=CLUSEV_DIR=/home/nexxo/clusev
|
||||
WorkingDirectory=/home/nexxo/clusev
|
||||
ExecStart=/home/nexxo/clusev/docker/wg/clusev-wg.sh gate-apply
|
||||
|
||||
[Install]
|
||||
# Pulled in when docker.service starts (boot AND `systemctl restart docker`), so a Docker restart
|
||||
# that flushes DOCKER-USER re-applies the gate.
|
||||
WantedBy=docker.service
|
||||
Loading…
Reference in New Issue