I truly appreciate Wireguard's simplicity but what's the best way to handle key management and peer address assignment in larger deployments?
PrivateKey = !peername
Publickey = !peername
And the actual credentials could be in a separate file with a specific name, with one peer per line:
peername:pubkeystring:privkeystring
That would make deployments much easier, as the credentials could be handled separately.
However, the peer address assignment is another good question. One file per peer would be better, I think, but you'd need something like another directory, and, at that point, you might as well write a script to take all your config and concatenate it into one file. That having been said, I don't know why that can't be a part of wg-quick.