Wireguard with dynamic setup for iot

Viewed 379

At the moment we have multiple raspberry pies placed at different locations on different networks. Our current solution to be able to reach them if something goes wrong is auto-ssh with jump host.

Recently I stumbled on Wireguard which could be another more slim way to solve the calling home problem.

The problem is that we would like the setup phase to be more dynamic, we don't want to do special configuration per node we have out there, we just want them to call home with a key and then be apart of the network.

Two questions:

Is Wireguard for us or are there other problems that I can't foresee here. Is there a way to set it up dynamically with one key and let the clients get random ips?

1 Answers

wireguard always needs a unique keypair / host. So not what you are looking for.

If you just want a phone home option with ip connectivity I would suggest an openvpn server and client. If you use a username/password config (not using certificates), you can reuse the config on multiple clients. Openvpn will act as an dhcp server.

an howto: https://openvpn.net/community-resources/how-to/ search for:

client-cert-not-required

The option that Maxim Sagaydachny is also valid for command access, an alternative to salt could be puppet with mco/bolt.

On any option you choose, be sure that the daemon restarts when it crashes, reboots, fails...

for systemd services this would be an override with:

[service]
restart=always
Related