Skip to content

feat(atlas): Give customer devices WireGuard access to tenant VMs - #314

Merged
tanmoysrt merged 83 commits into
feat/warpgate-integrationfrom
feat/wireguard-gateway
Oct 2, 2026
Merged

tanmoysrt merged 83 commits into
feat/warpgate-integrationfrom
feat/wireguard-gateway

Conversation

@tanmoysrt

@tanmoysrt tanmoysrt commented Oct 2, 2026 •

Copy link
Copy Markdown
Member

Summary

Customer devices reach the private addresses of their tenant's VMs through a regional cluster of WireGuard gateway nodes. Central registers a device through one endpoint and gets its WireGuard settings back.

This PR carries #289 by @20vikash and the follow-up changes on top.

Why

One gateway VM was a single point of failure and kept its peer list only on itself. A replicated cluster keeps the device table on every node, so any node accepts a write and a lost node is rebuilt with the same identity. Atlas stores no devices.

What changed

  • Gateway nodes form one cluster. wireguard.<wildcard> is the API name, and each node serves its own devices at wireguard-NNN.<wildcard>.
  • Device API: register, list, restore, and remove. A new device goes to the serving node with the fewest devices.
  • Host sync carries the gateway return routes. A VM opts in with Enable WireGuard Gateway Access. Guest routes do not change.
  • Authentication and clustering move from the HTTP proxy into a shared control-cluster package that both daemons use.
  • Archive and Rebuild drain a node before the cluster drops it, and both can run again after a failure.
  • The gateway VM gets a firewall: the tunnel port, the API, ICMP, and the region mesh only.
  • Metal skips WG Mesh syncs for VMs whose network did not change.

Related issues

Refs #289

nftables-based gateway that SNATs customer fdac addresses into the
tenant-0 mesh. No custom eBPF; conntrack handles the return path.
fdac address layout, peer render and sync over SSH, and the gateway
provisioner. Tenant-wide access only.
Gateway lifecycle with Desk create, archive, and peer resync actions.
Peer records are managed through the gateway API so every change syncs.
Publish the wg-gateway service package, add its Atlas Settings fields,
and retry pending gateway provisioning every minute.
parse_ndp added an unbounded packet length to a packet pointer. The
byteswap wipes the register range, so kernels like 6.8 reject the
object with 'math between pkt pointer and register with unbounded
min value'. Cap the payload at the minimum IPv6 MTU before the
pointer arithmetic. NDP lives on a link and never exceeds it.

Verified with bpftool prog load on 6.8.0-88-generic and by running
the rebuilt gateway on a live metal host.
Atlas boots the guest kernel from outside the root file system, so the
image can miss these modules. Install them for the running kernel and
persist them across reboots.
The gateway uses kernel WireGuard and nftables only. No BPF programs
are attached anywhere in this path.
@tanmoysrt
tanmoysrt merged commit 6dd7b41 into develop Oct 2, 2026
9 checks passed
@tanmoysrt
tanmoysrt deleted the feat/wireguard-gateway branch October 2, 2026 17:44
@tanmoysrt tanmoysrt mentioned this pull request Oct 2, 2026
3 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants