{"repo":"r-pufky/wireguard-initramfs","free":true,"listed":false,"github":"https://github.com/r-pufky/wireguard-initramfs","clone":"git clone https://github.com/r-pufky/wireguard-initramfs.git","description":"Use dropbear over wireguard.","language":"Shell","stars":349,"topics":["debian","wireguard","dropbear","initramfs"],"license":"Unlicense","category":"networking-infra","readme_excerpt":"wireguard-initramfs Use dropbear over wireguard. Enables wireguard networking during kernel boot, before encrypted partitions are mounted. Combined with dropbear this can enable FULLY ENCRYPTED remote booting without storing key material or exposing ports on the remote network. An Internet connection simply needs to exist that can reach the wireguard server endpoint. Normal dropbear connections and DNS resolution can be used to find wireguard endpoints. This essentially enables the creation of a fully encrypted remote-managed node, with the ability to prevent all local access. Requirements Working knowledge of Linux. Understanding of networking and Wireguard. 1. Debian Bullseye/Bookworm (any version with wireguard support should work, but untested). 2. Wireguard installed, configured and in a \"known working\" state. Getting started Installation is supported via make. Download, extract and configure contents, and install on target machine. Download Grab the latest release, untarball. Configure configs/initramfs file contains variables based on your working wireguard connection. Refer to wg set man page for additional information. Installation :warning: Most installs do not currently encrypt /boot ; and therefore the client private key should be considered untrusted/compromised . It is highly recommended that a separate point-to-point wireguard network with proper port blocking is used for remote unlocking. Rebuild initramfs to use using any of these methods: Any static errors w","default_branch":null,"files":null,"tree":[],"storefront":"/r/r-pufky","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/r-pufky/wireguard-initramfs/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}