fix(deploy): guard the WireGuard peer units too, not just the interface #103

Merged
padreug merged 1 commit from fix/wg-peer-units-guard into dev 2026-09-22 18:43:54 +00:00
Owner

#101 skipped wireguard-wg0 when no key is provisioned, but the module emits one unit per peer alongside it, and a condition-skipped unit is not a failed dependency. The peer unit still ran and died on "Unable to modify interface: No such device", producing the same exit 4 from a different unit, so an unprovisioned machine still reports a failed auto-upgrade. Seen on sintra today.

Peer units are now guarded on the same key. Names come from the module's own peers..name option rather than re-deriving its escaping, with the -refresh suffix following nixpkgs' peerUnitServiceName. Verified by evaluation that every wireguard- unit in the installed config carries the condition, each is a real unit with an ExecStart, and the live image still gets none.

Refs #98

#101 skipped wireguard-wg0 when no key is provisioned, but the module emits one unit per peer alongside it, and a condition-skipped unit is not a failed dependency. The peer unit still ran and died on "Unable to modify interface: No such device", producing the same exit 4 from a different unit, so an unprovisioned machine still reports a failed auto-upgrade. Seen on sintra today. Peer units are now guarded on the same key. Names come from the module's own peers.*.name option rather than re-deriving its escaping, with the -refresh suffix following nixpkgs' peerUnitServiceName. Verified by evaluation that every wireguard-* unit in the installed config carries the condition, each is a real unit with an ExecStart, and the live image still gets none. Refs #98
#101 skipped wireguard-wg0 when no key is provisioned, but the module
emits one unit per peer alongside it, and a condition-skipped unit is
not a failed dependency — so the peer unit still ran and died on
'Unable to modify interface: No such device'. Same exit 4 from
switch-to-configuration, different unit, so the nightly auto-upgrade is
still marked failed on an unprovisioned machine (seen on sintra today).

Guard the peers on the same key. Unit names come from the module's own
peers.*.name option rather than re-deriving its escaping here, with the
-refresh suffix following nixpkgs' peerUnitServiceName (a peer's null
interval falls back to the interface's). Verified by evaluation that
every wireguard-* unit in the installed config now carries the
condition, that each is a real unit with an ExecStart, and that the live
image — which mkForce's the interfaces away — still gets none.

Refs #98

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
padreug deleted branch fix/wg-peer-units-guard 2026-09-22 18:43:54 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/bitspire!103
No description provided.