Skip to content

Defguard-Edge (Addon) #2123

Description

@MickLesk

Name of the Script

Defguard-Edge

Script Type

CT (LXC Container)

Does this script support arm64?

arm64 supported

📋 Script Details

Defguard Edge is the public-facing component of a Defguard 2.x deployment (enrollment, password reset, desktop client onboarding). Companion to #2111 (Defguard Core).

Why this is needed: Defguard 2.x Core cannot finish its initial setup wizard without a reachable Edge — step 7 "Edge Component Adoption" probes it over gRPC and blocks until it answers. The Core issue's original note only mentioned the Gateway, which was incomplete; #2111 has been updated to point here.

  • Edge is the defguard-proxy package. There is no separate "edge" repo — confirmed via DefGuard/deployment → terraform2.0/modules/edge/setup.sh, which installs defguard-proxy and writes /etc/defguard/proxy.toml.
  • Stack: official Defguard apt repo via setup_deb822_repo "defguard" https://apt.defguard.net/defguard.asc https://apt.defguard.net "$(get_os_info codename)" release-2.0, then apt install defguard-proxy. The repo serves trixie and bookworm suites; the codename lookup picks the right one, which also avoids the GLIBC_2.39 mismatch upstream warns about.
  • Ports: 8080 HTTP, 8443 HTTPS (after Core provisions TLS), 50051 gRPC — that last one is what you enter in the Core wizard.
  • cert_dir = /etc/defguard/certs holds the mTLS certs provisioned during adoption; ownership handed to the defguard user the package creates.
  • Update path is apt-based.

Source: https://github.com/DefGuard/proxy

Activity

  1. changed the title [-]Defguard-Edge[/-] [+]Defguard-Edge (Addon)[/+] on Aug 3, 2026
  2. MickLesk commented on Aug 3, 2026

    @MickLesk
    MemberAuthor

    Revised: this is now an addon, not a standalone CT.

    Checked the apt repo — defguard, defguard-gateway and defguard-proxy are three separate packages in the same repo with separate systemd units, and the ports do not collide (Core 8000/50055, Edge 8080/8443/50051). So Core and Edge run happily in one container and a second LXC is unnecessary for the typical homelab.

    What changed:

    • ct/defguard-edge.sh and json/defguard-edge.json dropped in favour of tools/addon/defguard-edge.sh.
    • install/defguard-install.sh (Defguard #2111) now installs both defguard and defguard-proxy up front, so the setup wizard can be completed straight away with 127.0.0.1:50051 as the Edge address. No addon run needed for the default case.
    • The addon exists for upstream's segmented layout — Edge in a DMZ, Core internal. Run it in the second container and point the wizard at that host's IP:50051.
    • Core switched from the GitHub .deb to the official apt repo (apt.defguard.net, component release-2.0). Necessary for correctness: the addon adds that repo, and a later apt upgrade would otherwise pull defguard from it and diverge from the version check_for_gh_release was tracking. Both components now update through apt.

    Still open: the Gateway (defguard-gateway, also in that repo) — it belongs on the machine terminating the WireGuard tunnels, so it is a separate decision.

  3. MickLesk commented on Aug 3, 2026

    @MickLesk
    MemberAuthor

    Closing — Edge does not need its own script.

    defguard-proxy (= Edge) is now installed directly by install/defguard-install.sh alongside defguard, both from apt.defguard.net. Core and Edge share one container without port collisions (Core 8000/50055, Edge 8080/8443/50051), so the setup wizard is completed with 127.0.0.1:50051 and no extra step is required. Tracked under #2111.

    The addon variant I proposed in the comment above was removed as well: its guard required Core to be present, which contradicts the only case it would have served (Edge on a separate DMZ host, where Core is by definition absent). In the Core container it had nothing left to do either, since the install script already brings Edge. Anyone wanting the segmented layout can install defguard-proxy on that host and lift the ~20-line proxy.toml block from the install script — noted in json/defguard.json.

    Still genuinely open: the Gateway (defguard-gateway, same repo), which belongs on the machine terminating the WireGuard tunnels.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions