network/roles
Timotej Lazar 6840838978 firewall: ensure wireguard egress traffic uses the anycast source IP
Before we relied on the IP being first in the interfaces file, which
is less than optimal. Now we use nftables to ensure the correct source
IP is set only for the (fwmarked) wireguard traffic.

Also remove iface hints from interfaces configuration as they are not
needed with ifupdown-ng.
2025-07-18 18:35:36 +02:00
..
access access: filter some more non-changes from config diff 2025-07-01 09:37:13 +02:00
exit exit: import firewalls’ addresses into inside VRFs 2025-07-18 15:20:32 +02:00
fabric fabric: make some space 2025-04-03 18:42:23 +02:00
facts/tasks exit: support custom VRF imports 2024-07-15 14:22:42 +02:00
firewall firewall: ensure wireguard egress traffic uses the anycast source IP 2025-07-18 18:35:36 +02:00
leaf leaf: consolidate IPv4 and IPv6 address families for BGP 2025-03-26 01:33:33 +01:00
spine Initial commit, squashed 2023-12-18 12:55:47 +01:00