Refactor WireGuard entrypoint script to capture and restore original default route and gateway. Introduce wg_up_manual function for improved tunnel setup, replacing previous wg-quick commands.
Build and Push Docker Images / build-and-push (push) Successful in 19s
Build and Push Docker Images / build-and-push (push) Successful in 19s
This commit is contained in:
@@ -21,6 +21,9 @@ pf_pid=""
|
|||||||
current_region=""
|
current_region=""
|
||||||
current_wg_ip=""
|
current_wg_ip=""
|
||||||
current_wg_cn=""
|
current_wg_cn=""
|
||||||
|
orig_default_route=""
|
||||||
|
orig_default_gw=""
|
||||||
|
orig_default_dev=""
|
||||||
|
|
||||||
cleanup() {
|
cleanup() {
|
||||||
set +e
|
set +e
|
||||||
@@ -32,7 +35,10 @@ cleanup() {
|
|||||||
iptables -D OUTPUT -j PIA_KILLSWITCH 2>/dev/null || true
|
iptables -D OUTPUT -j PIA_KILLSWITCH 2>/dev/null || true
|
||||||
iptables -F PIA_KILLSWITCH 2>/dev/null || true
|
iptables -F PIA_KILLSWITCH 2>/dev/null || true
|
||||||
iptables -X PIA_KILLSWITCH 2>/dev/null || true
|
iptables -X PIA_KILLSWITCH 2>/dev/null || true
|
||||||
wg-quick down "$PIA_IFACE" 2>/dev/null || true
|
ip link del "$PIA_IFACE" 2>/dev/null || true
|
||||||
|
if [[ -n "${orig_default_route:-}" ]]; then
|
||||||
|
ip route replace $orig_default_route 2>/dev/null || true
|
||||||
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
trap cleanup EXIT INT TERM
|
trap cleanup EXIT INT TERM
|
||||||
@@ -73,6 +79,45 @@ setup_killswitch() {
|
|||||||
iptables -C OUTPUT -j PIA_KILLSWITCH 2>/dev/null || iptables -I OUTPUT 1 -j PIA_KILLSWITCH
|
iptables -C OUTPUT -j PIA_KILLSWITCH 2>/dev/null || iptables -I OUTPUT 1 -j PIA_KILLSWITCH
|
||||||
}
|
}
|
||||||
|
|
||||||
|
capture_default_route() {
|
||||||
|
# Save original default route so we can restore on exit/reconnect.
|
||||||
|
if [[ -n "${orig_default_route:-}" ]]; then
|
||||||
|
return
|
||||||
|
fi
|
||||||
|
orig_default_route="$(ip -4 route show default | head -n1 || true)"
|
||||||
|
orig_default_gw="$(awk '{for (i=1;i<=NF;i++) if ($i=="via") print $(i+1)}' <<<"$orig_default_route")"
|
||||||
|
orig_default_dev="$(awk '{for (i=1;i<=NF;i++) if ($i=="dev") print $(i+1)}' <<<"$orig_default_route")"
|
||||||
|
}
|
||||||
|
|
||||||
|
wg_up_manual() {
|
||||||
|
local iface="$1"
|
||||||
|
local addr="$2"
|
||||||
|
local privkey="$3"
|
||||||
|
local endpoint_ip="$4"
|
||||||
|
local endpoint_port="$5"
|
||||||
|
local server_pubkey="$6"
|
||||||
|
|
||||||
|
capture_default_route
|
||||||
|
if [[ -z "${orig_default_gw:-}" || -z "${orig_default_dev:-}" ]]; then
|
||||||
|
>&2 echo "Could not determine original default gateway/device."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ip link del "$iface" 2>/dev/null || true
|
||||||
|
ip link add "$iface" type wireguard
|
||||||
|
ip -4 address add "$addr" dev "$iface"
|
||||||
|
ip link set mtu 1420 up dev "$iface"
|
||||||
|
|
||||||
|
wg set "$iface" private-key <(printf '%s' "$privkey")
|
||||||
|
wg set "$iface" peer "$server_pubkey" persistent-keepalive 25 allowed-ips 0.0.0.0/0 endpoint "${endpoint_ip}:${endpoint_port}"
|
||||||
|
|
||||||
|
# Ensure endpoint traffic keeps going out via the original gateway.
|
||||||
|
ip -4 route replace "${endpoint_ip}/32" via "$orig_default_gw" dev "$orig_default_dev"
|
||||||
|
|
||||||
|
# Route all egress through the tunnel (main table; avoids wg-quick sysctl/policy routing).
|
||||||
|
ip -4 route replace default dev "$iface"
|
||||||
|
}
|
||||||
|
|
||||||
is_tunnel_healthy() {
|
is_tunnel_healthy() {
|
||||||
if ! wg show "$PIA_IFACE" >/dev/null 2>&1; then
|
if ! wg show "$PIA_IFACE" >/dev/null 2>&1; then
|
||||||
return 1
|
return 1
|
||||||
@@ -180,21 +225,7 @@ connect_region() {
|
|||||||
write_resolv_conf "$PIA_DNS_PRE_VPN"
|
write_resolv_conf "$PIA_DNS_PRE_VPN"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
mkdir -p /etc/wireguard
|
wg_up_manual "$PIA_IFACE" "$peer_ip" "$privKey" "$wg_ip" "$server_port" "$server_key"
|
||||||
cat >"/etc/wireguard/${PIA_IFACE}.conf" <<EOF
|
|
||||||
[Interface]
|
|
||||||
Address = ${peer_ip}
|
|
||||||
PrivateKey = ${privKey}
|
|
||||||
|
|
||||||
[Peer]
|
|
||||||
PersistentKeepalive = 25
|
|
||||||
PublicKey = ${server_key}
|
|
||||||
AllowedIPs = 0.0.0.0/0
|
|
||||||
Endpoint = ${wg_ip}:${server_port}
|
|
||||||
EOF
|
|
||||||
|
|
||||||
wg-quick down "$PIA_IFACE" 2>/dev/null || true
|
|
||||||
wg-quick up "$PIA_IFACE"
|
|
||||||
|
|
||||||
if [[ "$PIA_DNS_ENABLE" == "true" ]]; then
|
if [[ "$PIA_DNS_ENABLE" == "true" ]]; then
|
||||||
write_resolv_conf "$dns_server"
|
write_resolv_conf "$dns_server"
|
||||||
|
|||||||
Reference in New Issue
Block a user