- name: Configure WireGuard for wgnet ansible.builtin.template: src: templates/wgnet0.conf.j2 dest: /etc/wireguard/wgnet0.conf owner: root group: root # Config containes private key for this host, so permissions are # restricted. mode: u+rw,g-rw,o-rw notify: Reload wgnet - name: Enable WireGuard service for wgnet ansible.builtin.service: name: wg-quick@wgnet0 enabled: yes state: started