On a server running pivpn's WireGuard, a new install offers to take it
over: the server key, port, MTU, tunnel networks, endpoint, DNS,
AllowedIPs and keepalive, and every client with its public key,
preshared key and addresses. Devices keep their configs. Clients pivpn
switched off are imported switched off, with the note "Imported from
pivpn". Client private keys in /etc/wireguard/configs are not read.
- Install notes which peers are connected, stops wg-quick@wg0, starts
GHOSTWIRE on the same wg0 and waits up to 30 s for those peers. The
wait only reports; idle devices reconnect when they next send.
- If the service does not stay running, install removes what it set up,
including config.json, and starts pivpn's WireGuard again.
- Without a terminal the takeover needs -import-pivpn; install refuses
to run next to pivpn otherwise, and the flag is refused on an
existing install.
- Names GHOSTWIRE does not accept are renamed and listed in the
summary. An IPv6 address that differs from the mapped one is kept on
the peer until its config is issued again.
- uninstall without a config of its own (e.g. after a takeover was
undone) leaves the WireGuard interface alone and removes only the
firewall table.
- README: "Coming from pivpn?" under the intro, a Features entry and a
"Moving from pivpn" section.
Tested end to end on Ubuntu 24.04 with pivpn aa96de7.
A config can now be handed over as a one-time link, valid for 1 h, 24 h or
7 days and protected by a PIN by default. Keys are made only when the link
is opened; the link works once and is revoked after 5 wrong PINs. Issuing a
new config offers the same choice, and the current config keeps working
until the link is used.
Remove the option to paste a client's public key, in the web UI, the API
and the iOS app.