Skip to content
 
 

Latest commit

 

History

562 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Wireguard Operator

Grafana dashboard screenshot

Painless deployment of wireguard on kubernetes

Support

If you are facing any problems please open an issue

Tested with

  • IBM Cloud Kubernetes Service
  • Gcore Labs KMP
    • requires spec.enableIpForwardOnPodInit: true
  • Google Kubernetes Engine
    • requires spec.mtu: "1380"
    • Not compatible with "Container-Optimized OS with containerd" node images
    • Not compatible with autopilot
  • DigitalOcean Kubernetes
    • requires spec.serviceType: "NodePort". DigitalOcean LoadBalancer does not support UDP.
  • Amazon EKS
  • Azure Kubernetes Service
  • ...?

Architecture

alt text

Features

  • Falls back to userspace implementation of wireguard wireguard-go if wireguard kernal module is missing
  • Automatic key generation
  • Automatic IP allocation
  • Does not need persistance. peer/server keys are stored as k8s secrets and loaded into the wireguard pod
  • Exposes a metrics endpoint
  • Supports tunneling/traffic obfuscation using wstunnel
  • IPv6 support, including IPv6-only peers, through spec.peerCIDRv6 and spec.ipv6Only
  • Per-peer egress network policies through WireguardPeer.spec.egressNetworkPolicies

Example

Server

apiVersion: vpn.wireguard-operator.io/v1alpha1
kind: Wireguard
metadata:
  name: "my-cool-vpn"
spec:
  mtu: "1380"

Peer

apiVersion: vpn.wireguard-operator.io/v1alpha1
kind: WireguardPeer
metadata:
  name: peer1
spec:
  wireguardRef: "my-cool-vpn"

Peer configuration

Peer configurations are stored in a Secret named <wireguard-name>-peer-configs, one key per peer. Retrieve and decode like this:

kubectl get secret my-cool-vpn-peer-configs -o jsonpath='{.data.peer1}' | base64 -d

Use the output to configure your preferred Wireguard client:

[Interface]
PrivateKey = WOhR7uTMAqmZamc1umzfwm8o4ZxLdR5LjDcUYaW/PH8=
Address = 10.8.0.3
DNS = 10.48.0.10, default.svc.cluster.local
MTU = 1380

[Peer]
PublicKey = sO3ZWhnIT8owcdsfwiMRu2D8LzKmae2gUAxAmhx5GTg=
AllowedIPs = 0.0.0.0/0
Endpoint = 32.121.45.102:51820
PersistentKeepalive = 25

PersistentKeepalive defaults to 25 seconds and is configurable through Wireguard.Spec.PersistentKeepalive. Set it to 0 to omit it.

How to deploy

Note: this fork has not published an install artifact yet. An OCI Helm chart is the planned install path, tracked in #48. Until it ships, deploy from source.

Earlier revisions of this README pointed at upstream's release and chart. Those install the diverging upstream operator, which does not carry this fork's features — spec.persistentKeepalive, for example — so they have been removed rather than repointed.

make deploy

How to remove

make undeploy

How to collaborate

This project is done on top of Kubebuilder, so read about that project before collaborating. Of course, we are open to external collaborations for this project. For doing it you must fork the repository, make your changes to the code and open a PR. The code will be reviewed and tested (always)

We are developers and hate bad code. For that reason we ask you the highest quality on each line of code to improve this project on each iteration.

About

An operator that manages deployment of Wireguard on Kubernetes

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages