Add VPN documentation and WireGuard templates
This commit is contained in:
@@ -0,0 +1,24 @@
|
||||
# VPN Infrastructure
|
||||
|
||||
This directory documents the WireGuard tunnel between:
|
||||
|
||||
- `edge01` — DreamHost VPS
|
||||
- `infra01` — Home network tunnel endpoint
|
||||
|
||||
## Goals
|
||||
|
||||
- Secure bidirectional connectivity between edge01 and the home network
|
||||
- Allow selected services on the home network to be reached through edge01
|
||||
- Keep configuration reproducible
|
||||
- Never store private keys or pre-shared keys in Git
|
||||
|
||||
## Security
|
||||
|
||||
The following must never be committed:
|
||||
|
||||
- WireGuard private keys
|
||||
- Pre-shared keys
|
||||
- Complete production configuration files containing secrets
|
||||
- Passwords, API tokens, or credentials
|
||||
|
||||
Only sanitized configuration templates and public keys may be stored here.
|
||||
Reference in New Issue
Block a user