Skip to main content

Configures wireguard using information received from keymaster-server

Project description

keymaster-client

keymaster-client is the client portion of the keymaster wireguard key distribution solution. This readme is limited to configuration of the keymaster-client daemon; for an overview and general information please see the keymaster-server repo.

Installation & Usage

To install keymaster-client:

pip install keymaster-client

To run keymaster-client, first create a configuration (see below) and then run:

keymaster_client

Configuration

By default, keymaster-client looks for configuration at the path /etc/keymaster_client.yaml. You can change this by passing the desired path in the -f or --path-to-config flags.

Example Configuration

---
keymasterServer:
  url: https://example.com:5300
  token: a-fake-token
wg:
  configDir: /var/different/directory/
syncPeriod: 30

Configuration Reference

keymasterServer

If present, indicates that the keymasterServer ConfigSource is to be used. Cannot be used at the same time as the uDPUAPI ConfigSource.


keymasterServer.url

Required if keymasterServer is specified. The complete URL of the keymaster-server deployment.


keymasterServer.token

Required if keymasterServer is specified. The token to use in requests to the keymaster-server deployment. This token can be obtained from the keymaster-server web UI.


uDPUAPI

A ConfigSource for a proprietary system. Cannot be used at the same time as the keymasterServer ConfigSource.


uDPUAPI.url

Required if uDPUAPI is specified. The complete URL of the uDPU API deployment.


uDPUAPI.networkName

Required if uDPUAPI is specified. The network name to request config for on the uDPU API.


uci

A ConfigScheme that uses OpenWrt's UCI (Universal Configuration Interface) to configure wireguard interfaces. Has no options. Cannot be used at the same time as the wg ConfigScheme. For more information on UCI please see the OpenWrt wiki.


wg

A ConfigScheme that uses the ip and wg commands to configure wireguard interfaces on the host running keymaster-client. Cannot be used at the same time as the wg ConfigScheme.


wg.configDir

Optional. Default: /var/lib/keymaster_client/

The directory in which configuration is stored after syncing with the ConfigSource.


privateKey

Optional.

Allows you to specify the private key that this deployment of keymaster-client will configure all interfaces with. This value takes precedence over any values that otherwise would be generated by keymaster-client. This setting is useful if you have multiple non-endpoint interfaces behind a load balancer that you want to appear as a single highly-available interface to any endpoint interfaces connecting to them.


syncPeriod

Optional. Default: 60

Lets you specify the interval, in seconds, at which keymaster-client requests configuration from the ConfigSource.

Extending

keymaster-client provides two interfaces that make it easy to modify:

A ConfigScheme specifies how wireguard configurations are written to, and read from, the Node.

A ConfigSource tells keymaster-client how to get configuration of wireguard interfaces. This can take the form of a local file, a remote server, or anything else you can imagine.

For more information, please see the code.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distributions

No source distribution files available for this release.See tutorial on generating distribution archives.

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

keymaster_client-1.0.3-py2.py3-none-any.whl (16.2 kB view details)

Uploaded Python 2Python 3

File details

Details for the file keymaster_client-1.0.3-py2.py3-none-any.whl.

File metadata

  • Download URL: keymaster_client-1.0.3-py2.py3-none-any.whl
  • Upload date:
  • Size: 16.2 kB
  • Tags: Python 2, Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.3.0 pkginfo/1.6.1 requests/2.25.1 setuptools/49.2.1 requests-toolbelt/0.9.1 tqdm/4.55.1 CPython/3.8.6

File hashes

Hashes for keymaster_client-1.0.3-py2.py3-none-any.whl
Algorithm Hash digest
SHA256 afad14650decafa7e5ff9b69aea53ca51b95e3250dfd3d7ac49272431dd11bb1
MD5 d900c12ee53f8955581cc15ec3955f7b
BLAKE2b-256 e75cac6a76efeda40148fe406f3d70e5c44996bf9ef2fc750d854d5ed00c7151

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page