4 Commits

Author SHA1 Message Date
36862c86a5 feat(wireguard): allow WireGuard UDP port globally via firewalld
Removes the IP-based firewall rich rule that restricted WireGuard UDP
access to specific admin CIDRs. This change configures firewalld to allow
the WireGuard port globally, relying on WireGuard's internal cryptographic
key authentication for access control.
2026-07-10 13:54:59 +03:00
8dae045682 fix(wireguard): resolve docker forward drop and firewalld interface binding issues 2026-06-21 20:20:36 +03:00
17be81a66e feat(db): align WireGuard DB access with standard ports
- switch WireGuard DB access defaults from proxy ports to 5432/27017

- remove obsolete db stack template for proxy-based DB access

- clean roadmap wording around deprecated DB proxy services
2026-05-19 17:47:23 +03:00
ed51b6eedd feat(vpn): add WireGuard and DB proxy services for secure management
- Add new Ansible role `wireguard` to set up WireGuard VPN server on
  DB node with key generation, firewalld rules, and client peer config.
- Introduce `pg-proxy` and `mongo-proxy` socat containers in db_stack
  to expose PostgreSQL (15432) and MongoDB (17017) on host ports,
  restricted to WireGuard subnet via firewalld.
- Update test environment group_vars with WireGuard client entry for
  `murat-inspiron-15-3525`.
- Modify act_runner config: set `docker_host` to unix socket, remove
  explicit socket mount from options, and change runner label image to
  `catthehacker/ubuntu:act-22.04`.
- Open UDP port 51820 in Hetzner firewall for WireGuard inbound.
- Adjust test-db-post-stack playbook to include wireguard role (tagged).
- Update roadmap document with APISIX init step order.
2026-05-13 18:50:07 +03:00