The protonvpn provider mode uses gluetun's embedded server database which
doesn't contain US-TX#253 or US-TX#34. Our WireGuard keys are registered
for specific ProtonVPN servers, so connecting to other servers (US-TX#179,
US-TX#220) results in successful WireGuard handshake but ProtonVPN drops all
internet-bound traffic.
Fix: use VPN_SERVICE_PROVIDER=custom to directly configure the correct server
peer public key and endpoint IP for each worker. ExternalSecrets updated to
also pull public_key and endpoint_ip from Vault.
- tx253: endpoint=95.173.217.29, peer=mngiSxBpH7GU24nnWdBEcnhDnCPn2jq5+ZP3zwPwISA=
- tx34: endpoint=146.70.58.130, peer=wqJcz4akzVFxx35aJ5B7G/IJ9qsRvpcGNub3rLHcqXo=
Two initial Fornax distributed torrent workers, each a gluetun+qBittorrent+natpmpc-helper
pod on a different ProtonVPN TX server with NAT-PMP enabled. VPN private keys stored in
Vault at secret/fornax/worker-tx253 and secret/fornax/worker-tx34, surfaced via
ExternalSecrets. Workers share the media-data PVC; each has its own config PVC.
Services: fornax-worker-tx253:8080 and fornax-worker-tx34:8080 (ClusterIP, media ns)