feat(cloudflared): timeout+fallback for WG handshake (WG_HANDSHAKE_TIMEOUT) so tunnel still starts when VPN peer is down
This commit is contained in:
+14
-4
@@ -15,12 +15,22 @@ if [ -f /etc/wireguard/wg0.conf ]; then
|
||||
# wg-quick/resolvconf перезаписывает resolv.conf (убирает docker-DNS 127.0.0.11),
|
||||
# из-за чего внутреннее имя app не резолвится. Восстанавливаем прежний конфиг.
|
||||
cat /tmp/resolv.conf.default > /etc/resolv.conf
|
||||
echo "Waiting for WireGuard handshake..."
|
||||
echo "Waiting for WireGuard handshake (timeout: ${WG_HANDSHAKE_TIMEOUT:-60}s)..."
|
||||
# Формат `wg show wg0 latest-handshakes`: "<pubkey> <epoch-ts>"; 0 = handshake ещё не было.
|
||||
until wg show wg0 latest-handshakes | awk '{ if ($2 != 0) found=1 } END { exit !found }'; do
|
||||
sleep 2
|
||||
waited=0; handshake=0
|
||||
while [ "$handshake" -eq 0 ] && [ "$waited" -lt "${WG_HANDSHAKE_TIMEOUT:-60}" ]; do
|
||||
if wg show wg0 latest-handshakes | awk '{ if ($2 != 0) found=1 } END { exit !found }'; then
|
||||
handshake=1
|
||||
else
|
||||
sleep 2
|
||||
waited=$((waited + 2))
|
||||
fi
|
||||
done
|
||||
echo "WireGuard is up, starting Cloudflare tunnel through VPN..."
|
||||
if [ "$handshake" -eq 1 ]; then
|
||||
echo "WireGuard is up, starting Cloudflare tunnel through VPN..."
|
||||
else
|
||||
echo "WARNING: WireGuard handshake not established within ${WG_HANDSHAKE_TIMEOUT:-60}s; starting Cloudflare tunnel directly (no VPN egress)."
|
||||
fi
|
||||
else
|
||||
echo "No WireGuard config, starting Cloudflare tunnel directly..."
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user