The following Bash script automates the process of:
add_vpn_user.sh#!/bin/bash
WG_CONFIG="/etc/wireguard/wg0.conf"
WG_INTERFACE="wg0"
WG_SUBNET="10.50.0.0/24"
echo "=== New VPN User Setup ==="
read -p "Username: " USERNAME
read -p "Full name: " FULLNAME
read -p "VPN IP (example 10.50.0.5): " VPN_IP
echo "Paste SSH public key:"
read SSH_KEY
echo "Paste WireGuard public key:"
read WG_KEY
echo ""
echo "Creating user..."
sudo adduser --gecos "$FULLNAME,,,," $USERNAME
echo "Setting up SSH..."
sudo mkdir -p /home/$USERNAME/.ssh
echo "$SSH_KEY" | sudo tee /home/$USERNAME/.ssh/authorized_keys > /dev/null
sudo chown -R $USERNAME:$USERNAME /home/$USERNAME/.ssh
sudo chmod 700 /home/$USERNAME/.ssh
sudo chmod 600 /home/$USERNAME/.ssh/authorized_keys
echo "Adding WireGuard peer..."
sudo bash -c "cat >> $WG_CONFIG <<EOF
[Peer]
# $USERNAME
PublicKey = $WG_KEY
AllowedIPs = $VPN_IP/32
EOF"
echo "Reloading WireGuard..."
sudo wg syncconf $WG_INTERFACE <(wg-quick strip $WG_INTERFACE)
echo ""
echo "User $USERNAME created successfully!"
echo "VPN IP: $VPN_IP"
The script performs the following steps:
adduser..ssh directory for the user.authorized_keys.wg0.conf.After execution, the following entry will be appended to:
/etc/wireguard/wg0.conf
Example:
[Peer]
# alice
PublicKey = AbCDeFg1234567890...
AllowedIPs = 10.50.0.5/32
If you'd like, I can also show you a much more professional Markdown version suitable for a cybersecurity report, including: