| 1 | --- |
| 2 | # SPDX-License-Identifier: AGPL-3.0-or-later |
| 3 | # WireGuard peer config — droplet ↔ bare-metal monitoring host. |
| 4 | - name: WireGuard — install |
| 5 | apt: { name: wireguard, state: present } |
| 6 | |
| 7 | - name: wg0.conf — render |
| 8 | template: |
| 9 | src: "{{ playbook_dir }}/../wireguard/wg0.conf.j2" |
| 10 | dest: /etc/wireguard/wg0.conf |
| 11 | mode: "0600" |
| 12 | notify: restart wg-quick |
| 13 | |
| 14 | - name: wg-quick@wg0 — enabled + started |
| 15 | systemd: { name: wg-quick@wg0, state: started, enabled: yes } |
| 16 |