📁 Other

WireGuard Peer Checklist from Config Inventory (No Invented Peer Keys)

Turn a WireGuard config inventory into a peer checklist only. No invented peer keys, endpoint IPs, or allowed-IP ranges beyond the inventory.

0.0
0Reviews
P
September 11, 2026

Prompt

Act as a WireGuard network engineer who only uses a pasted config inventory. You write a peer checklist the inventory already supports. You do not invent peer keys, endpoint IPs, allowed-IP ranges, or keepalives. This is not a live wg show run and not a VPN-migration quote.
You work only from Inputs. Do not invent stats, citations, quotes, URLs, names, IDs, or records that are not in Inputs.

Inputs:
- Config inventory I lock (peer stubs, interface cues, endpoint notes): [Inventory]
- WireGuard / interface version notes I lock: [Version]
- Site or workspace label I may quote (or UNKNOWN): [Workspace]
- Required peer or interface names I may quote (or UNKNOWN): [SpecNames]
- Interface names already present (or UNKNOWN): [InterfaceNames]
- AllowedIP CIDRs already present (or UNKNOWN): [AllowedIPs]
- Endpoint host:port strings already present (or UNKNOWN): [Endpoints]
- Words I must not use: [Banned]
- What I must never invent (peer keys, endpoint IPs, allowed-IP ranges, keepalives): [Never]
- Output format: [Format]
- Language: [Lang]

Generate:
1. Honesty ledger: Inventory nouns, Version, Workspace, SpecNames, InterfaceNames, AllowedIPs, Endpoints, Lang. Forbidden: invented peer keys, endpoint IPs, allowed-IP ranges, keepalives. Banner: not a live wg show; not a VPN-migration quote.
2. Peer checklist table: one row per Inventory peer stub or interface cue. Missing endpoint notes write NOT IN INPUTS. Use WireGuard [Interface], [Peer], AllowedIPs, and Endpoint language when Inventory supports it. Quote InterfaceNames and AllowedIPs only when present.
3. Spec name set: only names in SpecNames. Unnamed peers stay NOT IN INPUTS. Never print peer-key or endpoint VALUES not in Inventory.
4. Version lock: print Version. Refuse WireGuard features newer than Version if Version is named.
5. Refuse list: inventing peer keys, inventing endpoint IPs, inventing allowed-IP ranges, inventing keepalives.
6. Compliance pass: quote Banned and Never hits. Cut them. Format as Format.

Constraints:
- Checklist from Inventory only. No invented peer-key VALUES. Teach WireGuard peer mapping, not a generic OpenVPN swap.
- Honor Version. No emojis.

Instructions

Replace every [bracket] with your details before running. Works on ChatGPT, Claude, and Gemini.

Generated Output

This image was generated using the prompt above.

WireGuard Peer Checklist from Config Inventory (No Invented Peer Keys) - Result

Examples

Example Input

Inventory: peer Harbor Quay Edge as pasted interface cue wg0 as pasted endpoint note edge.quay.example:51820 as pasted; peer River Ops Jump as pasted interface cue wg1 as pasted. Peer key NOT IN INPUTS. AllowedIP invent NONE.
Version: WireGuard tools 1.0.20210914 as pasted (do not invent unreleased userspace APIs)
Workspace: Harbor Quay NetOps as pasted
SpecNames: Edge as pasted; Jump as pasted. Laptop UNKNOWN.
InterfaceNames: wg0 as pasted; wg1 as pasted. wg2 UNKNOWN.
AllowedIPs: 10.8.0.2/32 as pasted; 10.8.0.3/32 as pasted. 10.8.0.0/24 UNKNOWN.
Endpoints: edge.quay.example:51820 as pasted. jump.ops.example:51820 UNKNOWN.
Banned: guaranteed peer key, endpoint invent, CIDR invent, keepalive invent
Never: invent peer keys, invent endpoint IPs, invent allowed-IP ranges, invent keepalives
Format: ledger + table + specs + version + refuse + compliance
Lang: English

Example Output

1. Ledger. Inventory: peer Harbor Quay Edge interface cue wg0 endpoint note edge.quay.example:51820; peer River Ops Jump interface cue wg1. Peer key NOT IN INPUTS. AllowedIP invent NONE. Version WireGuard tools 1.0.20210914. Workspace Harbor Quay NetOps. SpecNames Edge; Jump; Laptop UNKNOWN. InterfaceNames wg0; wg1; wg2 UNKNOWN. AllowedIPs 10.8.0.2/32; 10.8.0.3/32; 10.8.0.0/24 UNKNOWN. Endpoints edge.quay.example:51820; jump.ops.example:51820 UNKNOWN. Lang English. Banner: not a live wg show; not a VPN-migration quote. Forbidden: invented peer keys, endpoint IPs, allowed-IP ranges, keepalives, guaranteed peer key, endpoint invent, CIDR invent, keepalive invent.

2. Peer checklist.
1. Harbor Quay Edge | interface wg0 as pasted (InterfaceNames) | AllowedIPs 10.8.0.2/32 as pasted (AllowedIPs) | Endpoint edge.quay.example:51820 as pasted (Endpoints) | peer key NOT IN INPUTS | keepalive NOT IN INPUTS | WireGuard peer checklist only.
2. River Ops Jump | interface wg1 as pasted (InterfaceNames) | AllowedIPs 10.8.0.3/32 as pasted (AllowedIPs) | Endpoint NOT IN INPUTS | peer key NOT IN INPUTS | keepalive NOT IN INPUTS.
Peer keys not printed. Keepalives not invented.

3. Spec name set. Edge; Jump as SpecNames. Laptop UNKNOWN so write Laptop NOT IN INPUTS. No peer-key VALUES printed. No third peer invented.

4. Version lock. WireGuard tools 1.0.20210914 as pasted. Unreleased userspace APIs not used. Preshared keys NOT IN INPUTS.

5. Refuse. Peer key invent: refused. Endpoint invent: refused. CIDR invent: refused. Keepalive invent: refused. Guaranteed peer key: refused.

6. Compliance. Banned hits none. Format ledger+table+specs+version+refuse+compliance. Gaps: Endpoint for River Ops Jump, Laptop decision, wg2 InterfaceNames, 10.8.0.0/24 AllowedIPs, jump.ops.example Endpoint if any.

Missing-data policy: if a field was blank, write NOT IN INPUTS rather than guessing. Lock any tool version named in Inputs; if unnamed, write unknown. No invented testimonials, star ratings, or press logos. If legal, clinical, insurance, HR, education-plan, or veterinary content appears, add a one-line not-advice and de-identify banner. Quote banned-word hits and cut them. End with a gaps list of five bullets the user still owes you. Character and byte caps in the job are hard; print counts when relevant. Refuse to backfill DOIs, exam dumps, PHI, PII, or compensation promises not in Inputs.

Reviews (0)

Please login to leave a review.
Loading reviews...