Skip to content

Painless deployment of wireguard on kubernetes

License

Notifications You must be signed in to change notification settings

uhthomas/wireguard-operator

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

8565ade · May 3, 2024
Apr 2, 2024
Sep 2, 2023
Sep 2, 2023
Nov 15, 2023
Sep 2, 2023
Dec 19, 2021
Feb 11, 2024
Sep 2, 2023
Nov 15, 2023
Feb 20, 2022
Dec 19, 2021
May 18, 2023
May 14, 2023
May 3, 2024
Feb 20, 2022
Feb 20, 2022
Feb 20, 2022
Feb 28, 2024
Sep 2, 2023
Sep 2, 2023
May 16, 2023
May 3, 2024
May 3, 2024
Sep 2, 2023
May 14, 2023

Repository files navigation

Wireguard Operator

Screenshot 2022-02-26 at 02 05 29

Painless deployment of wireguard on kubernetes

Support and discussions

If you are facing any problems please open an issue or start a discussion

Tested with

  • IBM Cloud Kubernetes Service
  • Gcore Labs KMP
    • requires spec.enableIpForwardOnPodInit: true
  • Google Kubernetes Engine
    • requires spec.mtu: "1380"
    • Not compatible with "Container-Optimized OS with containerd" node images
    • Not compatible with autopilot
  • DigitalOcean Kubernetes
    • requires spec.serviceType: "NodePort". DigitalOcean LoadBalancer does not support UDP.
  • Amazon EKS
  • Azure Kubernetes Service
  • ...?

Architecture

alt text

Features

  • Falls back to userspace implementation of wireguard wireguard-go if wireguard kernal module is missing
  • Automatic key generation
  • Automatic IP allocation
  • Does not need persistance. peer/server keys are stored as k8s secrets and loaded into the wireguard pod
  • Exposes a metrics endpoint by utilizing prometheus_wireguard_exporter

Example

Server

apiVersion: vpn.wireguard-operator.io/v1alpha1
kind: Wireguard
metadata:
  name: "my-cool-vpn"
spec:
  mtu: "1380"

Peer

apiVersion: vpn.wireguard-operator.io/v1alpha1
kind: WireguardPeer
metadata:
  name: peer1
spec:
  wireguardRef: "my-cool-vpn"

Peer configuration

Peer configuration can be retrieved using the following command:

kubectl get wireguardpeer peer1 --template={{.status.config}} | bash

After executing it, something similar to the following will be shown. Use this config snippet to configure your preferred Wireguard client:

[Interface]
PrivateKey = WOhR7uTMAqmZamc1umzfwm8o4ZxLdR5LjDcUYaW/PH8=
Address = 10.8.0.3
DNS = 10.48.0.10, default.svc.cluster.local
MTU = 1380

[Peer]
PublicKey = sO3ZWhnIT8owcdsfwiMRu2D8LzKmae2gUAxAmhx5GTg=
AllowedIPs = 0.0.0.0/0
Endpoint = 32.121.45.102:51820

How to deploy

kubectl apply -f https://github.com/jodevsa/wireguard-operator/releases/download/v2.0.0/release.yaml

How to remove

kubectl delete -f https://github.com/jodevsa/wireguard-operator/releases/download/v2.0.0/release.yaml

How to collaborate

This project is done on top of Kubebuilder, so read about that project before collaborating. Of course, we are open to external collaborations for this project. For doing it you must fork the repository, make your changes to the code and open a PR. The code will be reviewed and tested (always)

We are developers and hate bad code. For that reason we ask you the highest quality on each line of code to improve this project on each iteration.

About

Painless deployment of wireguard on kubernetes

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Go 89.1%
  • Makefile 7.6%
  • Dockerfile 3.3%