Repository navigation
feat(atlas): Give customer devices WireGuard access to tenant VMs - #314
Merged
Merged
Conversation
nftables-based gateway that SNATs customer fdac addresses into the tenant-0 mesh. No custom eBPF; conntrack handles the return path.
fdac address layout, peer render and sync over SSH, and the gateway provisioner. Tenant-wide access only.
Gateway lifecycle with Desk create, archive, and peer resync actions. Peer records are managed through the gateway API so every change syncs.
Publish the wg-gateway service package, add its Atlas Settings fields, and retry pending gateway provisioning every minute.
parse_ndp added an unbounded packet length to a packet pointer. The byteswap wipes the register range, so kernels like 6.8 reject the object with 'math between pkt pointer and register with unbounded min value'. Cap the payload at the minimum IPv6 MTU before the pointer arithmetic. NDP lives on a link and never exceeds it. Verified with bpftool prog load on 6.8.0-88-generic and by running the rebuilt gateway on a live metal host.
Atlas boots the guest kernel from outside the root file system, so the image can miss these modules. Install them for the running kernel and persist them across reboots.
The gateway uses kernel WireGuard and nftables only. No BPF programs are attached anywhere in this path.
Derive the gateway access flag from the scoped routes Metal holds, and show the scoped routes in a separate gateway routes field. Toggle access through an action that installs or removes the gateway routes, like Edit Routes.
tanmoysrt
added this pull request to stack #313
October 2, 2026 13:18
VirtualMachineImage.get_latest_base_image picks the Ubuntu base image with the highest version, then the newest build. Create and Rebuild use it, so the gateway record no longer stores an image. The record also drops its copied Metal Server field.
3 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Customer devices reach the private addresses of their tenant's VMs through a regional cluster of WireGuard gateway nodes. Central registers a device through one endpoint and gets its WireGuard settings back.
This PR carries #289 by @20vikash and the follow-up changes on top.
Why
One gateway VM was a single point of failure and kept its peer list only on itself. A replicated cluster keeps the device table on every node, so any node accepts a write and a lost node is rebuilt with the same identity. Atlas stores no devices.
What changed
wireguard.<wildcard>is the API name, and each node serves its own devices atwireguard-NNN.<wildcard>.control-clusterpackage that both daemons use.Related issues
Refs #289