Jump to content

Wireguard - Docker

From Deffcon
Revision as of 00:35, 16 June 2025 by Rusyanto (talk | contribs) (Created page with "== Install Wireguard == This is a quick start guide to get you up and running with WireGuard Easy. The easiest way to run WireGuard Easy is with Docker Compose. Create <code>docker-compose.yml</code> and execute <code>sudo docker compose up -d</code><syntaxhighlight lang="bash"> volumes: etc_wireguard: services: wg-easy: #environment: # Optional: # - PORT=51821 # - HOST=0.0.0.0 # - INSECURE=false image: ghcr.io/wg-easy/wg-easy:15 c...")
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

Install Wireguard

This is a quick start guide to get you up and running with WireGuard Easy.

The easiest way to run WireGuard Easy is with Docker Compose.

Create docker-compose.yml and execute sudo docker compose up -d

volumes:
  etc_wireguard:

services:
  wg-easy:
    #environment:
    #  Optional:
    #  - PORT=51821
    #  - HOST=0.0.0.0
    #  - INSECURE=false

    image: ghcr.io/wg-easy/wg-easy:15
    container_name: wg-easy
    networks:
      wg:
        ipv4_address: 10.42.42.42
        ipv6_address: fdcc:ad94:bacf:61a3::2a
    volumes:
      - etc_wireguard:/etc/wireguard
      - /lib/modules:/lib/modules:ro
    ports:
      - "51820:51820/udp"
      - "51821:51821/tcp"
    restart: unless-stopped
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
      # - NET_RAW # ⚠️ Uncomment if using Podman
    sysctls:
      - net.ipv4.ip_forward=1
      - net.ipv4.conf.all.src_valid_mark=1
      - net.ipv6.conf.all.disable_ipv6=0
      - net.ipv6.conf.all.forwarding=1
      - net.ipv6.conf.default.forwarding=1

networks:
  wg:
    driver: bridge
    enable_ipv6: true
    ipam:
      driver: default
      config:
        - subnet: 10.42.42.0/24
        - subnet: fdcc:ad94:bacf:61a3::/64

Now setup a reverse proxy to be able to access the Web UI securely from the internet.

If you want to access the Web UI over HTTP, change the env var INSECURE to true. This is not recommended. Only use this for testing.

Secure Connection