wg-easy + Traefik docker-compose stack (Phase 1) plus a stdlib-only control-plane API for box registration, WireGuard peer provisioning via wg-easy, and per-box route publish/unpublish backed by Traefik's file provider (Phase 2, single-tenant mode). SQLite holds accounts/boxes/routes so a later multi-tenant shared instance is the same schema with more rows, not a reshape. wg-easy's actual REST API was verified against its source rather than assumed: it has no bearer-token auth (session-cookie login via POST /api/auth/password) and no way to accept an externally-generated public key (it always mints the keypair itself, private key included) — both corrected from the original plan during implementation.
21 lines
497 B
Python
21 lines
497 B
Python
import os
|
|
from pathlib import Path
|
|
|
|
DEFAULT_STATE_DIR = Path("/var/lib/furtka-gateway")
|
|
DEFAULT_DYNAMIC_DIR = Path("/var/lib/furtka-gateway/dynamic")
|
|
|
|
|
|
def state_dir() -> Path:
|
|
return Path(os.environ.get("GATEWAY_STATE_DIR", DEFAULT_STATE_DIR))
|
|
|
|
|
|
def dynamic_dir() -> Path:
|
|
return Path(os.environ.get("GATEWAY_DYNAMIC_DIR", DEFAULT_DYNAMIC_DIR))
|
|
|
|
|
|
def db_path() -> Path:
|
|
return state_dir() / "gateway.db"
|
|
|
|
|
|
def deploy_state_file() -> Path:
|
|
return state_dir() / "deploy-state.json"
|