esc
Type to search the docs
Back to catalog

wg-easy

Draft

WireGuard VPN server with simple web management UI

UncategorizedRepository

Run locally

Terminal
$ npx launchfile up wg-easy

Requires Docker Desktop. No source code needed — pulls pre-built images and starts wg-easy with all dependencies.

Image:ghcr.io/wg-easy/wg-easy:15
LaunchfileView on GitHub
# yaml-language-server: $schema=https://launchfile.dev/schema/v1
# NOTE: wg-easy requires the NET_ADMIN Linux capability for managing WireGuard interfaces.
# Providers must grant this capability or run the container in privileged mode.
version: launch/v1
name: wg-easy
description: "WireGuard VPN server with simple web management UI"
repository: https://github.com/wg-easy/wg-easy
logo: https://raw.githubusercontent.com/wg-easy/wg-easy/master/src/public/logo.png

# Pinned to the v15 major. v15 does not read the v14 env names (WG_HOST,
# WG_PORT, PASSWORD_HASH); its unattended first-boot setup is the INIT_* group
# (docs/content/advanced/config/unattended-setup.md). INIT_* is read on the
# first start only — after that the settings live in /etc/wireguard.
image: ghcr.io/wg-easy/wg-easy:15
provides:
  - name: web
    protocol: http
    port: 51821
    exposed: true
  # The WireGuard endpoint every VPN client connects to.
  - name: wg
    protocol: udp
    port: 51820
    exposed: true
env:
  INIT_ENABLED:
    default: "true"
    description: "Enable unattended first-boot setup from the INIT_* variables"
  INIT_USERNAME:
    default: "admin"
    description: "Admin username for the web UI (first boot only)"
  INIT_PASSWORD:
    generator: secret
    sensitive: true
    description: "Admin password for the web UI (first boot only)"
  INIT_HOST:
    default: $app.host
    required: true
    description: "Public hostname or IP of the `wg` endpoint — what VPN clients connect to"
  # INIT_PORT also sets WireGuard's in-container listen port, so the `wg`
  # endpoint needs a 1:1 host publication (host port == container port).
  INIT_PORT:
    default: "51820"
    description: "Public UDP port of the `wg` endpoint — must equal the port the `wg` endpoint is published on"
  INSECURE:
    default: "true"
    description: "Drops the Secure flag from the admin session cookie so login works over plain HTTP; set false when a TLS-terminating proxy fronts the `web` endpoint"
restart: always
storage:
  config:
    path: /etc/wireguard
    persistent: true

Learn More

Spec references for features used in this Launchfile.

Related Apps