#!/usr/bin/env bash # Wire the private-network mode after the servers exist (create.sh calls this; it can be re-run at any time): # ./net/setup.sh every zone: the 0.0.0.0/0 route to the gateway, the gateway's NAT and port forwards, # every private node's uplink check # ./net/setup.sh gateways gateways only ./net/setup.sh nodes private nodes only # Needs nodes.tsv (7 columns). Hetzner only; NET_MODE=public has nothing to do here. . "$(dirname "$0")/../lib/common.sh" require_nodes what="${1:-all}" [ "$NET_MODE" = private ] || { log "NET_MODE=$NET_MODE: nothing to set up"; exit 0; } need hcloud "brew install hcloud" if [ "$what" = all ] || [ "$what" = gateways ]; then for z in $(cut -f3 "$NODES_FILE" | while read -r r; do zone_of_region "$r"; done | sort -u); do gw=$(gateway_of_zone "$z"); [ -n "$gw" ] || die "zone $z has no public node in $NODES_FILE" gwip=$(node_ip "$gw"); gwpub=$(node_pub "$gw"); net=$(network_name "$z") if ! hcloud network describe "$net" -o json | python3 -c 'import json,sys; r=json.load(sys.stdin)["routes"]; sys.exit(0 if any(x["destination"]=="0.0.0.0/0" for x in r) else 1)'; then hcloud network add-route "$net" --destination 0.0.0.0/0 --gateway "$gwip" >/dev/null && log "$net: route 0.0.0.0/0 via $gwip ($gw)" fi fwd=$(awk -F'\t' -v z="$z" -v gw="$gw" '$5 == "private" { print $7 ":" $4 "\t" $3 }' "$NODES_FILE" | while IFS=$'\t' read -r pair r; do if [ "$(zone_of_region "$r")" = "$z" ]; then printf '%s ' "$pair"; fi; done; true) nscp "$HERE/net/gateway.sh" "$SSH_USER@$gwip:/root/gateway.sh" # shellcheck disable=SC2086 nssh "$gwip" "P2P_PORT=$P2P_PORT bash /root/gateway.sh '$NET_PREFIX.0.0/16' '$(zone_hetzner_gw "$z")' '$gwpub' $fwd" &1 | sed "s/^/[$gw] /" done fi if [ "$what" = all ] || [ "$what" = nodes ]; then bad=0 while IFS=$'\t' read -r -u 3 name idx reg ip access pub port; do [ "$access" = private ] || continue router=$(zone_hetzner_gw "$(zone_of_region "$reg")") ( nscp "$HERE/net/private-node.sh" "$SSH_USER@$ip:/root/private-node.sh" &1