Conversation
nftables-based gateway that SNATs customer fdac addresses into the tenant-0 mesh. No custom eBPF; conntrack handles the return path.
fdac address layout, peer render and sync over SSH, and the gateway provisioner. Tenant-wide access only.
Gateway lifecycle with Desk create, archive, and peer resync actions. Peer records are managed through the gateway API so every change syncs.
Publish the wg-gateway service package, add its Atlas Settings fields, and retry pending gateway provisioning every minute.
parse_ndp added an unbounded packet length to a packet pointer. The byteswap wipes the register range, so kernels like 6.8 reject the object with 'math between pkt pointer and register with unbounded min value'. Cap the payload at the minimum IPv6 MTU before the pointer arithmetic. NDP lives on a link and never exceeds it. Verified with bpftool prog load on 6.8.0-88-generic and by running the rebuilt gateway on a live metal host.
Atlas boots the guest kernel from outside the root file system, so the image can miss these modules. Install them for the running kernel and persist them across reboots.
The gateway uses kernel WireGuard and nftables only. No BPF programs are attached anywhere in this path.
# Conflicts: # atlas/service/SPEC.md # services/wg-mesh/bpf/mesh.h
Frappe has no Sidebar doctype and no importer for <app>/<app>/sidebar/, so the fixture never loaded. The Service sidebar lives as a Workspace Sidebar record created directly during development.
This reverts commit d70edb7.
Frappe 16 has no Sidebar doctype and no importer for <app>/<app>/sidebar/, so atlas/atlas/sidebar/atlas/atlas.json never loaded. The Service sidebar is a Workspace Sidebar record instead.
This reverts commit 68251d3.
…ge test get_download_url now refuses a File without a URL, which the test never provided, so install_package raised before it could take the early return.
The gateway SPEC still pointed at the deleted wg_gateway/address.py and claimed Atlas owns the peer list, which the daemon took over. The repository, app, and operator docs never listed the component at all.
Contributor
Author
|
@greptile review |
Add the wireguard-gateway route scope. Metal converges a scoped route in the VM namespace on the host but keeps it out of the guest metadata, so the routes inside the VM never change. The host sync reports each VM desired routes.
Give each gateway its own fdac /48 with the gateway ID in the address layout. Replace the nftables tenant filter and SNAT with tc ingress programs on wg0 and eth0 that check the tenant without address translation.
Enable the network gateway role so WG Mesh carries client source addresses without translation, and pass the gateway ID to the installer. Send guest IPv6 traffic to the host by default, and describe the gateway lifecycle and return routes.
Converge the scoped return routes of every Active gateway inside the existing server sync, using the per-VM routes the host reports. The sync owns the scoped subset and skips the normal routes, and the Edit Routes action preserves the scoped subset.
Derive the gateway access flag from the scoped routes Metal holds, and show the scoped routes in a separate gateway routes field. Toggle access through an action that installs or removes the gateway routes, like Edit Routes.
tanmoysrt
marked this pull request as draft
October 2, 2026 08:54
Member
|
There are couple of changes for region lockdown. |
Member
|
Moved here : #314 |
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WireGuard Gateway Server
Customers reach their own tenant's private
fdaa::/16VMs through a WireGuard gateway. The client holds anfdacaddress from the gateway's own/48, the gateway forwards it without address translation, and WG Mesh carries the packet to the VM.Why
What changed
services/wg-gateway/):setup.shinstalls wireguard-tools and the eBPF toolchain, assigns the gateway itsfdac:<region>:<gateway ID>::1/128onwg0with its/48route, compilesbpf/gateway.c, and attaches the tenant filter to thewg0andeth0ingress paths.systemd/re-applies the interface, addresses, routes, and filters on boot.fdac | region 16 | gateway ID 16 | tenant ID 32 | client ID 32 | zero 16. Each gateway owns one/48.services/wg-gateway/daemon/): serves peers, config, and health on the gateway mesh address at port 80. Ownspeers.json; every change rewritespeers.confand applies it withwg setconf.gateway.bpf.o):wg0ingress admits only this gateway's client sources toward same-region, same-tenantfdaadestinations;eth0ingress admits only matching replies tofdac. Mismatches drop; the client source is preserved end to end.atlas/service/doctype/wireguard_gateway_server/): onewg-gateway-NNNrecord owns the VM and the daemon credential. Creation needs an enabled Available System image, a reserved tenant-0 IPv4 allocation, a listen port, and an Active Proxy Server, and returns the daemon URL, token audience, public IPv4, listen port, and region ID. Provisioning enables the network gateway role and installs with the numeric record suffix asGATEWAY_ID. Archive removes the proxy route and terminates the VM./48is installed, scopedwireguard-gateway, only in VMs with Accessible via WireGuard Gateway enabled. The scope keeps the route in the VM namespace on the host; guest metadata never lists it. The existing server sync converges the set; Edit Routes never touches it.atlas-wg-gateway:<region>audience, validated against the Atlas JWKS. The key ID prefix selects the issuer, atenantclaim is refused, and the scopes are*,peers:*,peers:read,peers:update,gateway:read. No shared secret; Central reaches the daemon through the<gateway>.<wildcard-domain>proxy route.