- name: Configure wireguard for wgnet ansible.builtin.template: src: templates/wgnet0.conf.j2 dest: /etc/wireguard/wgnet0.conf owner: root group: root # Config containes private key for this host, so permissions are # restricted. mode: u+rw,g-rw,o-rw notify: Reload wgnet - name: Enable wireguard service for wgnet ansible.builtin.service: name: wg-quick@wgnet0 enabled: true state: started