moving vpn to direct configuration
This commit is contained in:
parent
18d4c99571
commit
93e5d39c7b
6 changed files with 64 additions and 7 deletions
|
|
@ -120,8 +120,7 @@ ALTER ROLE
|
|||
#+BEGIN_SRC sh
|
||||
psql postgresql://uncloud@2a0a-e5c0-0013-0000-9f4b-e619-efe5-a4ac.has-a.name/uncloud?sslmode
|
||||
=require
|
||||
#+END_SRC
|
||||
|
||||
g #+END_SRC
|
||||
|
||||
** Bootstrap
|
||||
- Login via a user so that the user object gets created
|
||||
|
|
@ -145,6 +144,25 @@ psql postgresql://uncloud@2a0a-e5c0-0013-0000-9f4b-e619-efe5-a4ac.has-a.name/unc
|
|||
python manage.py import-vat-rates
|
||||
#+END_SRC
|
||||
|
||||
** Worker nodes
|
||||
Nodes that realise services (VMHosts, VPNHosts, etc.) need to be
|
||||
accessible from the main node and also need access to the database.
|
||||
|
||||
Workers usually should have an "uncloud" user account, even though
|
||||
strictly speaking the username can be any.
|
||||
|
||||
*** WireGuardVPN Server
|
||||
- Allow write access to /etc/wireguard for uncloud user
|
||||
- Allow sudo access to "ip" and "wg"
|
||||
|
||||
#+BEGIN_SRC sh
|
||||
chown uncloud /etc/wireguard/
|
||||
[14:30] vpn-2a0ae5c1200:/etc/sudoers.d# cat uncloud
|
||||
app ALL=(ALL) NOPASSWD:/sbin/ip
|
||||
app ALL=(ALL) NOPASSWD:/usr/bin/wg
|
||||
#+END_SRC
|
||||
|
||||
|
||||
* Testing / CLI Access
|
||||
Access via the commandline (CLI) can be done using curl or
|
||||
httpie. In our examples we will use httpie.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue