Wireguard Edge Node #11961
-
|
I am going slightly crazy and wanted to double-check my plan is realistic before I go deeper... I have a hybrid cloud, or at least might have one. The goal is to connect edge nodes via Wireguard, and connect to all kubelet/discovery/talos api/etc connections over that wireguard interface. I am not using kubespan because of potential conflicts with Cilium. Is this the right way to go about it? I see in the logs that the wireguard interface is "reconfigured" but nothing beyond that. No wireguard packets are registered at the router (the other side of the link). Is there a way to increase wireguard log verbosity on the talos side? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 12 replies
-
|
KubeSpan might be easier, or Omni might be a better story for edge. But you can get wireguard details via |
Beta Was this translation helpful? Give feedback.



It was indeed a wireguard issue. Namely that routes are not automatically created for networks defined in Allowed addresses as they are when using wg-quick.
With no keepalive set and no routes the link remained dead and there was basically nothing to debug.
With the routes added the node joins as intended, and with a node ip on the wireguard subnet I have a node joined without needing to open extra ports.