Add wireguard server

This commit is contained in:
2026-09-23 23:44:54 -06:00
parent 2334d9d933
commit fe0087314d
25 changed files with 142 additions and 0 deletions
+11
View File
@@ -0,0 +1,11 @@
# These top ones are required to be filled out
# Mullvad keys work here
WIREGUARD_PRIVATE_KEY=
WIREGUARD_ADDRESSES=
# Optional vars
# Exposed port (default is 51820)
PORT=1984
# Number of client.conf files you want automatically generated (into /config/peer*/peer*.conf)
PEERS=
+4
View File
@@ -0,0 +1,4 @@
Changes to the docker-compose and .env files may not affect the previously made wireguard config files. So it is recommended to:
- Stop/Remove the container
- Delete the previous configuration (default location is ./wireguard)
- Start the container
+28
View File
@@ -0,0 +1,28 @@
---
services:
wireguard:
image: lscr.io/linuxserver/wireguard:latest
container_name: wireguard
cap_add:
- NET_ADMIN
- SYS_MODULE #optional
environment:
- PUID=1000
- PGID=1000
- TZ=Etc/UTC
- SERVERURL=wg.happylizard.me #optional
- PEERS=${PEERS:-3}
- SERVERPORT=${PORT:-51820} #optional
- PEERDNS=auto #optional
- INTERNAL_SUBNET=10.20.0.0 #optional
- ALLOWEDIPS=0.0.0.0/0 #optional
- PERSISTENTKEEPALIVE_PEERS= #optional
- LOG_CONFS=true #optional
volumes:
- ./wireguard:/config
- /lib/modules:/lib/modules #optional
ports:
- ${PORT:-51820}:${PORT:-51820}/udp
sysctls:
- net.ipv4.conf.all.src_valid_mark=1
restart: unless-stopped
+7
View File
@@ -0,0 +1,7 @@
ORIG_SERVERURL="wg.happylizard.me"
ORIG_SERVERPORT="1984"
ORIG_PEERDNS="10.20.0.1"
ORIG_PEERS="3"
ORIG_INTERFACE="10.20.0"
ORIG_ALLOWEDIPS="0.0.0.0/0"
ORIG_PERSISTENTKEEPALIVE_PEERS=""
+6
View File
@@ -0,0 +1,6 @@
. {
loop
errors
health
forward . /etc/resolv.conf
}
+11
View File
@@ -0,0 +1,11 @@
[Interface]
Address = 10.20.0.2
PrivateKey = 2Me6IkZWRid7dL7B0uQqyGAgNzVrNbzfWOd8tN2jYmw=
ListenPort = 51820
DNS = 10.20.0.1
[Peer]
PublicKey = eEYoSfzAsXWz++EV7y8h2DS7RubpyiGJojx6V6HgAiI=
PresharedKey = 5WP5+4ZIy6a8ROn/2ZKaYT0m/23sbOHMFvT/euWH/Cw=
Endpoint = wg.happylizard.me:1984
AllowedIPs = 0.0.0.0/0
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

@@ -0,0 +1 @@
5WP5+4ZIy6a8ROn/2ZKaYT0m/23sbOHMFvT/euWH/Cw=
@@ -0,0 +1 @@
2Me6IkZWRid7dL7B0uQqyGAgNzVrNbzfWOd8tN2jYmw=
@@ -0,0 +1 @@
c+993PShllBNgnR/phaLym8tTW4QMjbeAmh+67ybxDU=
+11
View File
@@ -0,0 +1,11 @@
[Interface]
Address = 10.20.0.3
PrivateKey = 8FM+qjgHlcmWjVKYaPKH8qM7HtfXbcYf0A8lXGJ160E=
ListenPort = 51820
DNS = 10.20.0.1
[Peer]
PublicKey = eEYoSfzAsXWz++EV7y8h2DS7RubpyiGJojx6V6HgAiI=
PresharedKey = bJnoOmSwf9tbLt59nMNRdL98CtC+gMLczbqz/6hBJzo=
Endpoint = wg.happylizard.me:1984
AllowedIPs = 0.0.0.0/0
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

@@ -0,0 +1 @@
bJnoOmSwf9tbLt59nMNRdL98CtC+gMLczbqz/6hBJzo=
@@ -0,0 +1 @@
8FM+qjgHlcmWjVKYaPKH8qM7HtfXbcYf0A8lXGJ160E=
@@ -0,0 +1 @@
mNTq/XTXXZFtyXc7t1uQ9vdcwneU2XkWrWzjPgRe/1E=
+11
View File
@@ -0,0 +1,11 @@
[Interface]
Address = 10.20.0.4
PrivateKey = SNzbsWlC/6+TI74yStzmuzKog6fAPBStdlfffp/nk3c=
ListenPort = 51820
DNS = 10.20.0.1
[Peer]
PublicKey = eEYoSfzAsXWz++EV7y8h2DS7RubpyiGJojx6V6HgAiI=
PresharedKey = YLYvms8UHwE2IkF7WgIrDNDisUK4JveacI5EQpAHHUw=
Endpoint = wg.happylizard.me:1984
AllowedIPs = 0.0.0.0/0
Binary file not shown.

After

Width:  |  Height:  |  Size: 1.1 KiB

@@ -0,0 +1 @@
YLYvms8UHwE2IkF7WgIrDNDisUK4JveacI5EQpAHHUw=
@@ -0,0 +1 @@
SNzbsWlC/6+TI74yStzmuzKog6fAPBStdlfffp/nk3c=
@@ -0,0 +1 @@
w34g7tWb9txMZmluL1VdRH4o0UTJWfOjFrZDKOkdFHQ=
@@ -0,0 +1 @@
+FCo3yAN1vvpckw4ndWEgA3WtdG7SjaiiJqCResRVlU=
@@ -0,0 +1 @@
eEYoSfzAsXWz++EV7y8h2DS7RubpyiGJojx6V6HgAiI=
+11
View File
@@ -0,0 +1,11 @@
[Interface]
Address = ${CLIENT_IP}
PrivateKey = $(cat /config/${PEER_ID}/privatekey-${PEER_ID})
ListenPort = 51820
DNS = ${PEERDNS}
[Peer]
PublicKey = $(cat /config/server/publickey-server)
PresharedKey = $(cat /config/${PEER_ID}/presharedkey-${PEER_ID})
Endpoint = ${SERVERURL}:${SERVERPORT}
AllowedIPs = ${ALLOWEDIPS}
@@ -0,0 +1,6 @@
[Interface]
Address = ${INTERFACE}.1
ListenPort = 51820
PrivateKey = $(cat /config/server/privatekey-server)
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth+ -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth+ -j MASQUERADE
+25
View File
@@ -0,0 +1,25 @@
[Interface]
Address = 10.20.0.1
ListenPort = 51820
PrivateKey = +FCo3yAN1vvpckw4ndWEgA3WtdG7SjaiiJqCResRVlU=
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth+ -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth+ -j MASQUERADE
[Peer]
# peer1
PublicKey = c+993PShllBNgnR/phaLym8tTW4QMjbeAmh+67ybxDU=
PresharedKey = 5WP5+4ZIy6a8ROn/2ZKaYT0m/23sbOHMFvT/euWH/Cw=
AllowedIPs = 10.20.0.2/32
[Peer]
# peer2
PublicKey = mNTq/XTXXZFtyXc7t1uQ9vdcwneU2XkWrWzjPgRe/1E=
PresharedKey = bJnoOmSwf9tbLt59nMNRdL98CtC+gMLczbqz/6hBJzo=
AllowedIPs = 10.20.0.3/32
[Peer]
# peer3
PublicKey = w34g7tWb9txMZmluL1VdRH4o0UTJWfOjFrZDKOkdFHQ=
PresharedKey = YLYvms8UHwE2IkF7WgIrDNDisUK4JveacI5EQpAHHUw=
AllowedIPs = 10.20.0.4/32