#!/usr/bin/env python3 """Align RB4011 WireGuard private key with Wifi-Otantik DB (no key printing).""" from __future__ import annotations import sys from pathlib import Path sys.path.insert(0, str(Path(__file__).resolve().parent)) import vps_ssh from mk_rb4011_exec import run as mk_run vps_ssh.put(str(Path(__file__).resolve().parent / "_tmp_wo_peer_keys.py"), "/tmp/wo_peer_keys.py") code, out = vps_ssh.run("python3 /tmp/wo_peer_keys.py") if code != 0: raise SystemExit("db: " + out[-200:]) parts = out.strip().split() if len(parts) < 2: raise SystemExit("no keys") pub, priv = parts[0], parts[1] # Router currently uses a different keypair; set SaaS key so VPS peer matches. esc = priv.replace("\\", "\\\\").replace('"', '\\"') result = mk_run( f'/interface wireguard set [find name=wg-otantik] private-key="{esc}"', timeout=30, ) print("wg-set-ok", "error" not in result.lower()) print("pub-prefix", pub[:8]) ping = mk_run("/ping 10.88.0.1 count=4", timeout=25) # do not include keys print(ping.replace(priv, "***").replace(pub, pub[:8] + "...")) print(mk_run("/interface wireguard peers print where interface=wg-otantik", timeout=20))