feat(backend): add OPNsense backend (#743)
Docker / Build and Push (push) Canceled after 0s
github-pages / deploy (push) Canceled after 0s
Test / make test (push) Canceled after 0s
Docker / release (push) Canceled after 0s

Manages interfaces and peers on OPNsense through the WireGuard API in
OPNsense core, so a stock appliance needs nothing installed. OPNsense
calls a tunnel a "server" and a peer on it a "client"; those map to
PhysicalInterface and PhysicalPeer.

Reads go through searchXxx because getXxx returns select fields as
{value, selected} maps that cannot be posted back to a write. Validation
failures arrive as HTTP 200 with a "result": "failed" body, so the body
is checked and not the status code.

Firewall rules are not managed, matching the pfSense backend: a new
tunnel handshakes but carries no traffic until a pass rule exists.

Alpha, and documented as such.

Signed-off-by: clark-ja <37738506+clark-ja@users.noreply.github.com>
This commit is contained in:
Jacopo Clark
2026-09-10 22:27:17 +02:00
committed by GitHub
parent 32ef6048fb
commit 7f5786f40f
14 changed files with 2855 additions and 14 deletions
+19
View File
@@ -6,6 +6,7 @@ const (
ControllerTypeMikrotik = "mikrotik"
ControllerTypeLocal = "wgctrl"
ControllerTypePfsense = "pfsense"
ControllerTypeOpnsense = "opnsense"
)
// Controller extras can be used to store additional information available for specific controllers only.
@@ -49,3 +50,21 @@ type PfsensePeerExtras struct {
ClientDns string
ClientKeepalive int
}
type OpnsenseInterfaceExtras struct {
Uuid string // internal OPNsense UUID of the WireGuard "server" (tunnel)
Instance string // the wg instance number; OPNsense derives the device name (wg0) from it
Comment string
Disabled bool
}
type OpnsensePeerExtras struct {
Uuid string // internal OPNsense UUID of the WireGuard "client" (peer)
Name string
Comment string
Disabled bool
ClientEndpoint string
ClientAddress string
ClientDns string
ClientKeepalive int
}