feat: Dynamic tunnel IP from cloud heartbeat for multi-bumblebee support

vpn-tunnel reads IP from /etc/parahub/tunnel_ip instead of hardcoded
172.16.0.2. On first boot, calls heartbeat synchronously to get assignment.
Heartbeat parses tunnel_ip from response and restarts vpn-tunnel on change.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
2026-02-10 20:28:26 +00:00
parent f9c2e97ec6
commit f96a455dc8
2 changed files with 43 additions and 6 deletions

View File

@@ -3,6 +3,9 @@
# Runs after yggdrasil (START=95). OpenWrt 25.x lacks the netifd grev6 protocol
# handler, so we create the tunnel manually with ip6gre.
#
# Tunnel IP is assigned by Django and stored in /etc/parahub/tunnel_ip.
# If the file doesn't exist (first boot), heartbeat is called synchronously to get it.
#
# IMPORTANT: encaplimit must be "none" — Yggdrasil drops IPv6 packets with
# Destination Options extension headers (added by default encaplimit 4).
@@ -10,8 +13,8 @@ START=96
STOP=10
VPS_YGG="200:39f1:6a26:328a:d901:fbd2:d30d:faef"
GRE_LOCAL_IP="172.16.0.2"
GRE_GATEWAY="172.16.0.1"
TUNNEL_IP_FILE="/etc/parahub/tunnel_ip"
start() {
# Only for Bumblebee role
@@ -31,12 +34,27 @@ start() {
return 1
fi
# Get tunnel IP — from file, or request via heartbeat on first boot
local gre_local_ip
gre_local_ip=$(cat "$TUNNEL_IP_FILE" 2>/dev/null)
if [ -z "$gre_local_ip" ]; then
logger -t parahub-vpn "No tunnel IP file, calling heartbeat to get assignment..."
HEARTBEAT_CURL_TIMEOUT=30 /usr/bin/parahub-heartbeat
gre_local_ip=$(cat "$TUNNEL_IP_FILE" 2>/dev/null)
fi
if [ -z "$gre_local_ip" ]; then
logger -t parahub-vpn "Failed to get tunnel IP from heartbeat, falling back to 172.16.0.2"
gre_local_ip="172.16.0.2"
fi
# Create GRE6 tunnel (encaplimit none — critical for Yggdrasil compatibility)
ip -6 tunnel add gre6-vpn mode ip6gre \
remote "$VPS_YGG" \
local "$ygg_addr" \
encaplimit none
ip addr add ${GRE_LOCAL_IP}/24 dev gre6-vpn
ip addr add ${gre_local_ip}/24 dev gre6-vpn
ip link set gre6-vpn mtu 1400 up
# Default route through GRE (table 100 — used by guest policy routing)
@@ -69,7 +87,7 @@ start() {
# Reload firewall so vpn_tunnel zone picks up gre6-vpn device
/etc/init.d/firewall reload 2>/dev/null &
logger -t parahub-vpn "GRE6 tunnel up: ${GRE_LOCAL_IP} → ${VPS_YGG} via $ygg_addr (encaplimit none)"
logger -t parahub-vpn "GRE6 tunnel up: ${gre_local_ip} → ${VPS_YGG} via $ygg_addr (encaplimit none)"
}
stop() {