ansible/host_vars/vpn-ovh-ng.auro.re.yml

32 lines
726 B
YAML
Raw Normal View History

---
wireguard_endpoints:
- name: gs
addr: 192.168.0.1/31
listen_port: 5412
private_key: "{{ vault_wireguard_secrets.ovh_gs.private }}"
peer:
public_key: "{{ vault_wireguard_secrets.gs.public }}"
allowed_addrs:
- 192.168.0.0/32
- 10.128.0.0/16
keepalive: 5
- name: edc
addr: 192.168.0.3/31
listen_port: 5413
private_key: "{{ vault_wireguard_secrets.ovh_edc.private }}"
peer:
public_key: "{{ vault_wireguard_secrets.edc.public }}"
allowed_addrs:
- 192.168.0.2/32
- 10.128.0.0/16
keepalive: 5
nftables_basic_input_rules:
- proto: tcp
port: 22
verdict: accept
- proto: udp
port: 5412
verdict: accept
...