network/roles/firewall
Timotej Lazar 6840838978 firewall: ensure wireguard egress traffic uses the anycast source IP
Before we relied on the IP being first in the interfaces file, which
is less than optimal. Now we use nftables to ensure the correct source
IP is set only for the (fwmarked) wireguard traffic.

Also remove iface hints from interfaces configuration as they are not
needed with ifupdown-ng.
2025-07-18 18:35:36 +02:00
..
files firewall: reload nftables in mgmt VRF 2024-08-19 13:54:01 +02:00
handlers firewall: use a handler to reboot 2024-05-19 10:10:02 +02:00
tasks firewall: set up resolv.conf 2025-03-26 12:32:54 +01:00
templates firewall: ensure wireguard egress traffic uses the anycast source IP 2025-07-18 18:35:36 +02:00