Files
watchtower-observability-stack/ansible/roles/observability/templates/wg-easy.container.j2
T

38 lines
1.1 KiB
Django/Jinja

[Unit]
Description=wg-easy WireGuard peer management
# wg-easy manages the host wg0 interface directly; it must start after the
# network is up but has no dependency on any observability container.
Wants=network-online.target
After=network-online.target
[Container]
Image={{ image_wg_easy }}
ContainerName=wg-easy
# Host network required so wg-easy can create/configure the wg0 interface on
# the real host namespace. Container network isolation is intentionally bypassed.
Network=host
# Capabilities for WireGuard interface management
AddCapability=NET_ADMIN
AddCapability=NET_RAW
AddCapability=SYS_MODULE
# Disable SELinux labelling — the container needs to write /etc/wireguard on
# the host and bind /dev/net/tun; the default container policy would deny this.
SecurityLabelDisable=true
# /etc/wireguard is bind-mounted WITHOUT :Z so the host directory keeps its
# original SELinux context and `wg` tooling outside the container still works.
Volume=/etc/wireguard:/etc/wireguard
EnvironmentFile={{ observability_secrets_dir }}/wg-easy.env
[Service]
Restart=on-failure
RestartSec=10
TimeoutStartSec=120
[Install]
WantedBy=multi-user.target default.target