Compare commits

...
Author SHA1 Message Date
13b20ff08c Update all stable non-major dependencies
Some checks failed
/ build (pull_request) Successful in 34s
/ Ansible Lint (pull_request) Failing after 2m35s
/ Ansible Lint (push) Failing after 2m41s
2026-08-02 16:16:21 +00:00
9266123f42 Explain that you can use a default route
Some checks failed
/ build (push) Successful in 28s
/ Ansible Lint (push) Failing after 2m17s
#133
2026-08-02 18:12:02 +02:00
24124e9f3d Document wg setup
Some checks failed
/ build (push) Successful in 29s
/ Ansible Lint (push) Failing after 2m24s
First step for #133
2026-08-02 18:09:29 +02:00
6 changed files with 44 additions and 8 deletions

View file

@ -0,0 +1,36 @@
---
title: "Wiregard Admin VPN"
summary: How to configure your Wireguard client to access the Z9 network
---
# Onboarding
tbd. where to add your key
# Local Client Configuration
## Example Config
```
[Interface]
PrivateKey = YOUR_PRIVATE_KEY
Address = 172.31.202.YOUR_IP/32
[Peer]
PublicKey = fmlxjh3iOfpgrHQQpK3dyOD0BvDppGCUkFuMSroqQR4=
AllowedIPs = 10.89.208.0/20, 2a07:c481:1::/48, 212.12.48.126/32, 2a00:14b0:42:100::/56, 2a00:14b0:4200:3000::/64
Endpoint = rt-wan.ccchh.net:51820
```
## AllowedIDs
The following prefixes should be tunneled to gain access to both CCCHH Z9 resources as well as Chaosknoten. It is also possible to run a default route through wireguard, but please do not abuse this as a general VPN for purposes other than admin tasks.
| Prefix | Description |
|--|--|
| [10.89.208.0/20](https://netbox.hamburg.ccc.de/ipam/prefixes/114/prefixes/) | prefix for CCCHH Z9 local networks |
| [2a07:c481:1::/48](https://netbox.hamburg.ccc.de/ipam/prefixes/50/) | prefix for CCCHH Z9 local networks |
| [212.12.48.126/32](https://netbox.hamburg.ccc.de/ipam/ip-addresses/30/) | public IP of chaosknoten |
| [2a00:14b0:4200:3000::126:1/128](https://netbox.hamburg.ccc.de/ipam/ip-addresses/255/) | public IP of chaosknoten |
| [2a00:14b0:42:100::/56/128](https://netbox.hamburg.ccc.de/ipam/prefixes/46/) | new IPv6 for VMs on chaosknoten |
| [2a00:14b0:4200:3000::/64](https://netbox.hamburg.ccc.de/ipam/prefixes/36/) | old IPv6 for VMs on chaosknoten |

View file

@ -1,5 +1,5 @@
# renovate: datasource=github-releases depName=netbox packageName=netbox-community/netbox
netbox__version: "v4.6.4"
netbox__version: "v4.6.7"
netbox__config: "{{ lookup('ansible.builtin.template', 'resources/chaosknoten/netbox/netbox/configuration.py.j2') }}"
netbox__custom_pipeline_oidc_group_and_role_mapping: true

View file

@ -2,7 +2,7 @@
services:
prometheus:
image: docker.io/prom/prometheus:v3.13.1
image: docker.io/prom/prometheus:v3.13.2
container_name: prometheus
command:
- '--config.file=/etc/prometheus/prometheus.yml'
@ -32,7 +32,7 @@ services:
- alertmanager_data:/alertmanager
grafana:
image: docker.io/grafana/grafana:13.1.0
image: docker.io/grafana/grafana:13.1.1
container_name: grafana
ports:
- 3000:3000
@ -59,7 +59,7 @@ services:
- /dev/null:/etc/prometheus/pve.yml
loki:
image: docker.io/grafana/loki:3.7.3
image: docker.io/grafana/loki:3.7.4
container_name: loki
ports:
- 13100:3100

View file

@ -1,7 +1,7 @@
---
services:
ntfy:
image: docker.io/binwiederhier/ntfy:v2.26.0
image: docker.io/binwiederhier/ntfy:v2.26.3
container_name: ntfy
command:
- serve

View file

@ -15,7 +15,7 @@ services:
- pretalx_net
redis:
image: docker.io/library/redis:8.8.0
image: docker.io/library/redis:8.10.0
restart: unless-stopped
volumes:
- redis:/data
@ -23,7 +23,7 @@ services:
- pretalx_net
static:
image: docker.io/library/nginx:1.31.2
image: docker.io/library/nginx:1.31.3
restart: unless-stopped
volumes:
- public:/usr/share/nginx/html

View file

@ -13,7 +13,7 @@ services:
restart: unless-stopped
redis:
image: docker.io/library/redis:8.8.0
image: docker.io/library/redis:8.10.0
ports:
- "6379:6379"
volumes: