ansible/host_vars/vpn-ovh-ng.auro.re.yml

26 lines
569 B
YAML
Raw Normal View History

---
wireguard_endpoints:
2021-02-20 23:41:10 +01:00
- name: saclay
addrs:
2021-02-20 23:41:10 +01:00
- 192.168.0.1/28
listen_port: 5412
2021-02-20 23:41:10 +01:00
private_key: "{{ vault_wireguard_secrets.ovh.private }}"
peers:
2021-02-20 23:41:10 +01:00
- public_key: "{{ vault_wireguard_secrets.gs.public }}"
allowed_addrs:
2021-02-20 23:41:10 +01:00
- 192.168.0.2/32
keepalive: 5
- public_key: "{{ vault_wireguard_secrets.edc.public }}"
allowed_addrs:
- 192.168.0.3/32
keepalive: 5
nftables_basic_input_rules:
- proto: tcp
port: 22
verdict: accept
- proto: udp
port: 5412
verdict: accept
...