feat: allow to customise WireGuard listen port with --wg-port for machine init/add (#366)

This commit is contained in:
Aaron Echols
2026-05-19 16:55:55 +10:00
committed by GitHub
parent c95136eae6
commit 424263bdd4
17 changed files with 388 additions and 176 deletions
+1 -1
View File
@@ -6,7 +6,7 @@ import (
)
// ConfigureIptablesChains is a stub for Darwin.
func ConfigureIptablesChains(machineIP netip.Addr) error {
func ConfigureIptablesChains(machineIP netip.Addr, wgPort int) error {
return fmt.Errorf("not supported on Darwin")
}
+2 -2
View File
@@ -19,7 +19,7 @@ const (
)
// ConfigureIptablesChains sets up custom iptables chains and initial firewall rules for Uncloud networking.
func ConfigureIptablesChains(machineIP netip.Addr) error {
func ConfigureIptablesChains(machineIP netip.Addr, wgPort int) error {
if err := createIptablesChains(); err != nil {
return err
}
@@ -30,7 +30,7 @@ func ConfigureIptablesChains(machineIP netip.Addr) error {
// Allow WireGuard traffic to the machine.
acceptWireGuardRule := []string{
"-p", "udp",
"--dport", strconv.Itoa(network.WireGuardPort),
"--dport", strconv.Itoa(wgPort),
"-j", "ACCEPT",
}
// Allow cluster machines to access the unregistry (embedded image registry) on the machine to push/pull images.