Compare commits

..

2 Commits

Author SHA1 Message Date
8629a36278 fix: allow WireGuard road-warrior clients to reach DNS on minisforum
Some checks failed
validate / lint (push) Failing after 2s
UFW allowed 53/udp+tcp from every other internal subnet but not from
10.10.0.0/24 (the WireGuard client subnet), so once the tunnel itself
was reachable, decrypted DNS queries still got dropped at minisforum's
own INPUT chain before reaching Technitium.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-26 20:45:09 +09:00
b37a816b3e fix: route home LAN through mac WireGuard client, fix broken bool conditionals
AllowedIPs for the mac road-warrior peer was missing 10.10.40.0/24, so
DNS (10.10.40.53) and other home-LAN hosts were unreachable over the
tunnel. Also fixes the same string-vs-bool `when:` failure already
patched in e757850 (recent ansible-core rejects a `-e ...=true` CLI
string in a boolean conditional) for the client-config display tasks.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-26 20:45:09 +09:00
2 changed files with 7 additions and 5 deletions

View File

@ -25,6 +25,8 @@ ufw_allowed_ports:
- { port: 6443, proto: tcp, comment: K3s API server }
- { port: 10250, proto: tcp, comment: Kubelet, src: 10.10.40.0/24 }
- { port: 8472, proto: udp, comment: Flannel VXLAN, src: 10.10.40.0/24 }
- { port: 53, proto: udp, comment: WireGuard road-warrior DNS, src: 10.10.0.0/24 }
- { port: 53, proto: tcp, comment: WireGuard road-warrior DNS, src: 10.10.0.0/24 }
data_dirs:
- /data/gitea

View File

@ -163,27 +163,27 @@
[Peer]
PublicKey = {{ server_public_key.stdout }}
Endpoint = {{ wireguard_endpoint }}:51820
AllowedIPs = 192.168.7.0/24, 10.10.0.0/24
AllowedIPs = 192.168.7.0/24, 10.10.40.0/24, 10.10.0.0/24
PersistentKeepalive = 25
- name: Display mac client config
ansible.builtin.shell: cat /etc/wireguard/mac-client.conf
register: mac_conf
changed_when: false
when: wireguard_show_client_configs | default(false)
when: wireguard_show_client_configs | default(false) | bool
- name: Show mac client config
ansible.builtin.debug:
msg: "{{ mac_conf.stdout_lines }}"
when: wireguard_show_client_configs | default(false)
when: wireguard_show_client_configs | default(false) | bool
- name: Generate QR code for phone
ansible.builtin.shell: qrencode -t ansiutf8 < /etc/wireguard/phone-client.conf
register: phone_qr
changed_when: false
when: wireguard_show_client_configs | default(false)
when: wireguard_show_client_configs | default(false) | bool
- name: Display phone QR code
ansible.builtin.debug:
msg: "{{ phone_qr.stdout_lines }}"
when: wireguard_show_client_configs | default(false)
when: wireguard_show_client_configs | default(false) | bool