Repository navigation
Defguard-Edge (Addon) #2123
Description
Activity
Revised: this is now an addon, not a standalone CT.
Checked the apt repo —
defguard,defguard-gatewayanddefguard-proxyare three separate packages in the same repo with separate systemd units, and the ports do not collide (Core 8000/50055, Edge 8080/8443/50051). So Core and Edge run happily in one container and a second LXC is unnecessary for the typical homelab.What changed:
ct/defguard-edge.shandjson/defguard-edge.jsondropped in favour oftools/addon/defguard-edge.sh.install/defguard-install.sh(Defguard #2111) now installs bothdefguardanddefguard-proxyup front, so the setup wizard can be completed straight away with127.0.0.1:50051as the Edge address. No addon run needed for the default case.- The addon exists for upstream's segmented layout — Edge in a DMZ, Core internal. Run it in the second container and point the wizard at that host's
IP:50051. - Core switched from the GitHub
.debto the official apt repo (apt.defguard.net, componentrelease-2.0). Necessary for correctness: the addon adds that repo, and a laterapt upgradewould otherwise pulldefguardfrom it and diverge from the versioncheck_for_gh_releasewas tracking. Both components now update through apt.
Still open: the Gateway (
defguard-gateway, also in that repo) — it belongs on the machine terminating the WireGuard tunnels, so it is a separate decision.Closing — Edge does not need its own script.
defguard-proxy(= Edge) is now installed directly byinstall/defguard-install.shalongsidedefguard, both from apt.defguard.net. Core and Edge share one container without port collisions (Core 8000/50055, Edge 8080/8443/50051), so the setup wizard is completed with127.0.0.1:50051and no extra step is required. Tracked under #2111.The addon variant I proposed in the comment above was removed as well: its guard required Core to be present, which contradicts the only case it would have served (Edge on a separate DMZ host, where Core is by definition absent). In the Core container it had nothing left to do either, since the install script already brings Edge. Anyone wanting the segmented layout can install
defguard-proxyon that host and lift the ~20-lineproxy.tomlblock from the install script — noted injson/defguard.json.Still genuinely open: the Gateway (
defguard-gateway, same repo), which belongs on the machine terminating the WireGuard tunnels.
Name of the Script
Defguard-Edge
Script Type
CT (LXC Container)
Does this script support arm64?
arm64 supported
📋 Script Details
Defguard Edge is the public-facing component of a Defguard 2.x deployment (enrollment, password reset, desktop client onboarding). Companion to #2111 (Defguard Core).
Why this is needed: Defguard 2.x Core cannot finish its initial setup wizard without a reachable Edge — step 7 "Edge Component Adoption" probes it over gRPC and blocks until it answers. The Core issue's original note only mentioned the Gateway, which was incomplete; #2111 has been updated to point here.
defguard-proxypackage. There is no separate "edge" repo — confirmed viaDefGuard/deployment→terraform2.0/modules/edge/setup.sh, which installsdefguard-proxyand writes/etc/defguard/proxy.toml.setup_deb822_repo "defguard" https://apt.defguard.net/defguard.asc https://apt.defguard.net "$(get_os_info codename)" release-2.0, thenapt install defguard-proxy. The repo servestrixieandbookwormsuites; the codename lookup picks the right one, which also avoids the GLIBC_2.39 mismatch upstream warns about.cert_dir = /etc/defguard/certsholds the mTLS certs provisioned during adoption; ownership handed to thedefguarduser the package creates.Source: https://github.com/DefGuard/proxy