public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: Re: [RFC manager/network/proxmox{,-ve-rs,-perl-rs} v2 00/25] Add WireGuard as protocol to SDN fabrics
Date: Mon, 4 May 2026 17:01:27 +0200	[thread overview]
Message-ID: <6e6c5f96-3c42-40d3-8c67-95ab6dde60d7@proxmox.com> (raw)
In-Reply-To: <gint4hx5agabyyxvgcm47ogcgntlcojqs66n5m3moegjrrw2sk@glj5se4ts3gl>

On 4/2/26 3:57 PM, Gabriel Goller wrote:
> Will have a look at the code later, but some high-level (mostly ui) stuff in
> the meantime:
> 
>  * when deleting a node referenced as a peer by another node, one gets this
>    confusing message: "deleting node failed: peer configuration references
>    non-existing interface (500)" (maybe include which node uses the peer)

done

>  * "Endpoint" is a bit confusing, maybe add a tooltip or default text (same on "Allowed IPs")

done, added a default text on both

>  * maybe a nicer error message when the first wg command (wg genkey) fails
>    (mention that wireguard-tools has to be installed)

done

>  * would it be possible (and sensible) that a peer is autoselected so
>    bidirectional traffic is possible by default. e.g. when creating a node and
>    adding a peer, the new node is added as a peer in the existing nodes (which have
>    been selected as peers from the new node). Otherwise it's quite exhausting
>    right now adding a new node, selecting all the peers and then needing to go
>    through and edit all the other existing nodes and checking the newly
>    added peer. Of course it's maybe a bit magicky, but at least it improves the
>    usability?

I guess it makes sense, but isn't necessarily required? I'd rather keep
the current behavior and implement something like the "auto-fullmeshify"
UI function mentioned in the cover letter in PVE/PDM.

>  * when generating the ifupdown2 config, a newline above `auto wg0` would be nice.

done

>  * when setting an ipv6 address we need to add a warning "enable ipv6 forwarding
>    globally" like in the other fabrics.

It isn't unconditionally required, since if you just configure a subnet
on the interface and only want to reach the hosts inside that subnet
forwarding doesn't need to be enabled. It could actually be a bit of a
security issues then imo if some less-knowledgable users see the warning
and then enabling routing for IPv6 on their hosts even if it isn't
required. Showing this conditionally (only if required) could also be
hard in the UI :/. Potentially add this to the documentation instead?




  reply	other threads:[~2026-05-04 15:02 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-04-02  8:11 [RFC manager/network/proxmox{,-ve-rs,-perl-rs} v2 00/25] Add WireGuard as protocol to SDN fabrics Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox v2 01/25] wireguard: skip serializing preshared_key if unset Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox v2 02/25] wireguard: implement ApiType for endpoints and hostnames Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 03/25] sdn-types: add wireguard-specific PersistentKeepalive api type Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 04/25] ve-config: fabrics: split interface name regex into two parts Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 05/25] ve-config: fabric: refactor fabric config entry impl using macro Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 06/25] ve-config: fabrics: add protocol-specific properties for wireguard Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 07/25] ve-config: sdn: fabrics: add wireguard to the fabric config Stefan Hanreich
2026-05-04 16:00   ` Hannes Laimer
2026-05-04 16:20     ` Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 08/25] ve-config: fabrics: wireguard add validation for wireguard config Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-ve-rs v2 09/25] ve-config: fabrics: implement wireguard config generation Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-perl-rs v2 10/25] pve-rs: fabrics: wireguard: generate ifupdown2 configuration Stefan Hanreich
2026-04-02  8:11 ` [PATCH proxmox-perl-rs v2 11/25] pve-rs: fabrics: add helpers for parsing interface property strings Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-network v2 12/25] sdn: add wireguard helper module Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-network v2 13/25] fabrics: wireguard: add schema definitions for wireguard Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-network v2 14/25] fabrics: wireguard: implement wireguard key auto-generation Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 15/25] network: sdn: generate wireguard configuration on apply Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 16/25] ui: fix parsing of property-strings when values contain = Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 17/25] ui: fabrics: i18n: make node loading string translatable Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 18/25] ui: fabrics: split node selector creation and config Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 19/25] ui: fabrics: edit: make ipv4/6 support generic over fabric panels Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 20/25] ui: fabrics: node: make ipv4/6 support generic over edit panels Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 21/25] ui: fabrics: interface: " Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 22/25] ui: fabrics: wireguard: add interface edit panel Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 23/25] ui: fabrics: wireguard: add node " Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 24/25] ui: fabrics: wireguard: add fabric " Stefan Hanreich
2026-04-02  8:11 ` [PATCH pve-manager v2 25/25] ui: fabrics: hook up wireguard components Stefan Hanreich
2026-04-02 13:58 ` [RFC manager/network/proxmox{,-ve-rs,-perl-rs} v2 00/25] Add WireGuard as protocol to SDN fabrics Gabriel Goller
2026-05-04 15:01   ` Stefan Hanreich [this message]
2026-05-04 16:21 ` superseded: " Stefan Hanreich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6e6c5f96-3c42-40d3-8c67-95ab6dde60d7@proxmox.com \
    --to=s.hanreich@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal