-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathgenerate-env.sh
executable file
·139 lines (113 loc) · 3.76 KB
/
generate-env.sh
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
#!/bin/bash
set -e
set -u
# Generate .env
(
set -e
set -u
if [ -f ".env" ]; then
echo "Found .env, skipping generation"
exit 0
fi
NETWORK_OWN_PRIVATE="$(wg genkey)"
NETWORK_OWN_PUBLIC="$(echo $NETWORK_OWN_PRIVATE | wg pubkey)"
NETWORK_PEER_PRIVATE="$(wg genkey)"
NETWORK_PEER_PUBLIC="$(echo $NETWORK_PEER_PRIVATE | wg pubkey)"
PROXY_OWN_PRIVATE="$(wg genkey)"
PROXY_OWN_PUBLIC="$(echo $PROXY_OWN_PRIVATE | wg pubkey)"
PROXY_PEER_PRIVATE="$(wg genkey)"
PROXY_PEER_PUBLIC="$(echo $PROXY_PEER_PRIVATE | wg pubkey)"
cat <<EOF >.env
# To make sure logging output works
PYTHONUNBUFFERED=1
# For CTFs: fill in the gamenet config here
NETWORK_OWN_PRIVATE="$NETWORK_OWN_PRIVATE"
NETWORK_OWN_PUBLIC="$NETWORK_OWN_PUBLIC"
# peer private key is only used for testing
NETWORK_PEER_PRIVATE="$NETWORK_PEER_PRIVATE"
NETWORK_PEER_PUBLIC="$NETWORK_PEER_PUBLIC"
# Use this to start yampa without a fixed endpoint
#NETWORK_PEER_ENDPOINT="testclient:51820"
# For CTFs: fill in the connection to the vulnbox here
PROXY_OWN_PRIVATE="$PROXY_OWN_PRIVATE"
PROXY_OWN_PUBLIC="$PROXY_OWN_PUBLIC"
# peer private key is only used for testing
PROXY_PEER_PRIVATE="$PROXY_PEER_PRIVATE"
PROXY_PEER_PUBLIC="$PROXY_PEER_PUBLIC"
# Use this to start yampa without a fixed endpoint
#PROXY_PEER_ENDPOINT="testserver:51820"
EOF
cat <<EOF
.env generated. For local testing use e.g. following wireguard config
---------------------------------------------------------
Network:
---------------------------------------------------------
[Interface]
PrivateKey = $NETWORK_PEER_PRIVATE
Address = 10.0.0.1/32
MTU = 1420
[Peer]
PublicKey = $NETWORK_OWN_PUBLIC
AllowedIPs = 10.0.0.0/24
Endpoint = 127.0.0.1:51820
PersistentKeepalive = 1
---------------------------------------------------------
Proxy:
---------------------------------------------------------
[Interface]
PrivateKey = $PROXY_PEER_PRIVATE
Address = 10.0.0.2/32
MTU = 1420
[Peer]
PublicKey = $PROXY_OWN_PUBLIC
AllowedIPs = 10.0.0.0/24
Endpoint = 127.0.0.1:51821
PersistentKeepalive = 1
---------------------------------------------------------
and connect anywhere into the listed allowed ips
EOF
)
# Generate .env-test
(
set -e
set -u
if [ -f ".env-test" ]; then
echo "Found .env-test, skipping generation"
exit 0
fi
NETWORK_OWN_PRIVATE="$(wg genkey)"
NETWORK_OWN_PUBLIC="$(echo $NETWORK_OWN_PRIVATE | wg pubkey)"
NETWORK_PEER_PRIVATE="$(wg genkey)"
NETWORK_PEER_PUBLIC="$(echo $NETWORK_PEER_PRIVATE | wg pubkey)"
PROXY_OWN_PRIVATE="$(wg genkey)"
PROXY_OWN_PUBLIC="$(echo $PROXY_OWN_PRIVATE | wg pubkey)"
PROXY_PEER_PRIVATE="$(wg genkey)"
PROXY_PEER_PUBLIC="$(echo $PROXY_PEER_PRIVATE | wg pubkey)"
DIR="$(mktemp -d)"
openssl req -x509 -newkey rsa:4096 -keyout "$DIR"/key.pem -out "$DIR"/cert.pem -nodes -subj '/CN=localhost' -addext "subjectAltName = DNS:testserver,IP:10.2.3.4" -sha256 -days 3650
HTTPS_CERTIFICATE="$(cat "$DIR"/cert.pem)"
HTTPS_KEY="$(cat "$DIR"/key.pem)"
rm -rf "$DIR"
cat <<EOF >.env-test
# To make sure logging output works
PYTHONUNBUFFERED=1
# For CTFs: fill in the gamenet config here
NETWORK_OWN_PRIVATE="$NETWORK_OWN_PRIVATE"
NETWORK_OWN_PUBLIC="$NETWORK_OWN_PUBLIC"
# peer private key is only used for testing
NETWORK_PEER_PRIVATE="$NETWORK_PEER_PRIVATE"
NETWORK_PEER_PUBLIC="$NETWORK_PEER_PUBLIC"
# Use this to start yampa without a fixed endpoint
NETWORK_PEER_ENDPOINT="testclient:51820"
# For CTFs: fill in the connection to the vulnbox here
PROXY_OWN_PRIVATE="$PROXY_OWN_PRIVATE"
PROXY_OWN_PUBLIC="$PROXY_OWN_PUBLIC"
# peer private key is only used for testing
PROXY_PEER_PRIVATE="$PROXY_PEER_PRIVATE"
PROXY_PEER_PUBLIC="$PROXY_PEER_PUBLIC"
# Use this to start yampa without a fixed endpoint
PROXY_PEER_ENDPOINT="testserver:51820"
HTTPS_CERTIFICATE="$HTTPS_CERTIFICATE"
HTTPS_KEY="$HTTPS_KEY"
EOF
)