WireGuard With A Kept Key And A Checked Config
WireGuard from AppStream: a wg-quick interface whose private key is generated once and kept in its own file, never in the config, peers from a variable, and each config loaded into a throwaway interface first. The live test pings through the tunnel from a peer in another network namespace while an unlisted key gets no reply. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-wireguard?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [WireGuard With A Kept Key And A Checked Config](https://www.iac-bazaar.com/catalog/ansible-wireguard?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# WireGuard With A Kept Key And A Checked Config: https://www.iac-bazaar.com/catalog/ansible-wireguard (download from your IaC Bazaar account)
```Preview:
Documentation
wireguard
WireGuard from AppStream: a wg-quick interface with a private key generated once on the host and kept (its public key published beside it for your peers), your peers listed from a variable, and the configuration loaded into a throwaway interface before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages wireguard, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
A UDP port on every address, by design. WireGuard cannot bind one address:
measured, the kernel listens on 0.0.0.0:51820 and [::]:51820. Restrict
who reaches the port with a firewall; inside the tunnel, a peer whose key is
not listed gets no reply at all. wg-quick@wg0 is a oneshot unit, so systemd
itself waits for the interface to come up.
Checked by WireGuard itself, with no secret in the file. wg-quick strip
passes a file whatever its keys look like; wg setconf refuses a malformed
key ("Key is not the correct length or format", measured). The role loads
every new configuration into a throwaway interface in a throwaway network
namespace before writing it. The private key is not in that file: it stays in
wg0.key (0600) and PostUp loads it, so the configuration can be shown,
diffed and checked without exposing it - and a key you supply is refused by
wg pubkey when it is malformed.
Proven by a tunnel. The live test builds a peer in its own network namespace, joined to the host by a veth pair, lists its key on the server at runtime, and pings the server through the tunnel - three replies and a handshake. The same peer with a key the server does not list gets none. The directory is 0700 and the configuration and key are 0600, read back.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-squid
The stock squid.conf allows localhost before it denies loopback destinations, so a local client can proxy into loopback services. This role puts every deny first and binds loopback. The live test fetches a page through it, then sees squid itself refuse loopback, 169.254.169.254, an unsafe port, CONNECT to 25 and a non-loopback client. Original role, live-tested on Rocky Linux 10.
ansible-consul-server
HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.
ansible-frr
FRR from AppStream: BGP that announces only your prefixes, accepts from each neighbour only what you list for it, signs sessions with TCP MD5, and applies a change without dropping them. The live test peers with a real BGP speaker in its own namespace; a filtered prefix stays out of the kernel and a wrong password keeps the session down. Original role, live-tested on Rocky Linux 10.
ansible-headscale
Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.