diff options
| -rw-r--r-- | assets/wireguard-config/.gitignore | 5 | ||||
| -rw-r--r-- | assets/wireguard-config/README.org | 19 |
2 files changed, 24 insertions, 0 deletions
diff --git a/assets/wireguard-config/.gitignore b/assets/wireguard-config/.gitignore new file mode 100644 index 0000000..d5e34ab --- /dev/null +++ b/assets/wireguard-config/.gitignore @@ -0,0 +1,5 @@ +# This repo is PUBLIC (cgit at git.cjennings.net serves it unauthenticated). +# NEVER commit plaintext WireGuard configs here — they carry live PrivateKeys. +# Ship configs gpg-encrypted (*.conf.gpg) only; the installer decrypts at import. +*.conf +!*.conf.gpg diff --git a/assets/wireguard-config/README.org b/assets/wireguard-config/README.org new file mode 100644 index 0000000..3bcf327 --- /dev/null +++ b/assets/wireguard-config/README.org @@ -0,0 +1,19 @@ +#+TITLE: WireGuard configs — encrypted only +#+AUTHOR: Craig Jennings + +This directory holds WireGuard VPN configs for the installer's +=import-wireguard-configs.sh=. + +*This repo is public* (cgit at git.cjennings.net serves it over +unauthenticated HTTPS). Plaintext =*.conf= files carry live Proton +=PrivateKey= material and MUST NOT be committed — they are gitignored here. + +Workflow: +- Store configs gpg-encrypted only: =gpg -e --default-recipient-self wg-XX.conf= + produces =wg-XX.conf.gpg=, safe to track in a public repo. +- The installer decrypts =*.conf.gpg= to a private temp dir at import time, + imports, then wipes the plaintext. (Re-architecture tracked in todo.org.) + +History note: three plaintext configs were committed 2026-07-05 (c7b7d16) and +were publicly exposed until 2026-07-20, when the keys were rotated at Proton +and the files were purged from history. |
