fix(deploy): guard the WireGuard peer units too, not just the interface #103
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/wg-peer-units-guard"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
#101 skipped wireguard-wg0 when no key is provisioned, but the module emits one unit per peer alongside it, and a condition-skipped unit is not a failed dependency. The peer unit still ran and died on "Unable to modify interface: No such device", producing the same exit 4 from a different unit, so an unprovisioned machine still reports a failed auto-upgrade. Seen on sintra today.
Peer units are now guarded on the same key. Names come from the module's own peers..name option rather than re-deriving its escaping, with the -refresh suffix following nixpkgs' peerUnitServiceName. Verified by evaluation that every wireguard- unit in the installed config carries the condition, each is a real unit with an ExecStart, and the live image still gets none.
Refs #98