Skip to content

enable openvpn-client on remaining hosts (batch 3, 7 nodes) - #39

Merged
bborbe merged 1 commit into
masterfrom
feature/openvpn-client-rest
Jul 21, 2026
Merged

enable openvpn-client on remaining hosts (batch 3, 7 nodes)#39
bborbe merged 1 commit into
masterfrom
feature/openvpn-client-rest

Conversation

@bborbe

@bborbe bborbe commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Final rollout batch (#37 bundle+canary, #38 k3s fleet — both applied clean, all tunnels uninterrupted).

Nodes

  • Online: nuke, co2wz, rasp3 — laptop PKI md5-identical to live files; client.conf + /etc/default/openvpn byte-identical to bundle. bw verify: nuke fully converged (0 changes); co2wz/rasp3 only systemctl enable openvpn@client (no restart).
  • Offline: fire, hell, sun, nuke-workspace — laptop PKI complete (all 4 files); bundle applies on their next boot/apply.

After this lands + applies, every world-managed VPN client is bw-owned → next PR removes openvpn from world entirely.

- online (nuke, co2wz, rasp3): laptop PKI md5-identical to live; nuke fully
  converged already, co2wz/rasp3 only need the persistent enable symlink
- offline (fire, hell, sun, nuke-workspace): laptop PKI complete; bundle
  applies whenever the hosts are next online

@ben-s-pull-request-reviewer ben-s-pull-request-reviewer Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

{
  "verdict": "approve",
  "summary": "PR enables openvpn-client on 7 remaining hosts (batch 3) following the established pattern from batches 1 and 2. All 7 files show consistent naming: the 'name' field matches the hostname prefix and dictionary key for each node. No security concerns — hostname values are static and not user-controlled. Pattern matches the prior openvpn-client adoptions already in master.",
  "comments": [],
  "concerns_addressed": [
    "security: openvpn-client enabled with hostnames derived from static hostname field, not user-controlled — confirmed",
    "correctness: name field matches actual hostname prefix across all 7 files (co2wz, fire, hell, nuke-workspace, nuke, rasp3, sun) — confirmed"
  ]
}

@bborbe
bborbe merged commit a34f7e5 into master Jul 21, 2026
2 checks passed
@bborbe
bborbe deleted the feature/openvpn-client-rest branch July 21, 2026 16:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant