Why this Configuration?
- True Data Sovereignty: 100% GDPR-compliant on-premises deployment. You own your configuration and data without vendor lock-in.
- Hardware Agnostic: Optimized and verified across low-power ARM64 SBCs (Raspberry Pi 5) and x86_64 hypervisors (Proxmox VE LXC & VM).
- Engine Freedom: Tested and supported under standard Docker Engine and unprivileged rootless Podman.
- Platform Verification: Tested on Proxmox LXC: docker (22.16.0, 2026-09-14), podman (22.16.0, 2026-09-14); Proxmox VM: docker (22.16.0, 2026-09-14), podman (22.16.0, 2026-09-14).
Quick Start (Standalone Docker Compose)
The snippet below is immediately ready to run in any standard Docker or Podman environment:
services:
wg-easy:
image: ghcr.io/wg-easy/wg-easy:latest
container_name: njorddeploy-wg-easy
restart: unless-stopped
cap_add:
- NET_ADMIN
- SYS_MODULE
- NET_RAW
sysctls:
- net.ipv4.ip_forward=1
- net.ipv4.conf.all.src_valid_mark=1
environment:
- "WG_HOST=vpn.example.com"
- "PASSWORD_HASH=$2b$12$U5DIA2y39QuBN0Cv4iZNxu9bb7NROm.gs2Kq.KbIi4uOzjJ3ST5u2"
- "PORT=51821"
- "WG_PORT=51820"
- "WG_DEFAULT_DNS=1.1.1.1"
volumes:
- "./data/wg-easy/wireguard:/etc/wireguard"
- "/lib/modules:/lib/modules:ro"
ports:
- "51820:51820/udp"
- "51821:51821/tcp"
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start the service directly via the command line: docker compose up -d
Configuration & Environment Variables
Key configuration parameters and defaults derived from the NjordDeploy component template:
| Variable | Default Value | Description |
|---|---|---|
WG_EASY_WEB_PORT |
51821 |
Host port used to access the WireGuard Easy administration web interface. |
WG_EASY_PORT |
51820 |
Public UDP port on which WireGuard VPN traffic will be received. |
WG_HOST |
vpn.example.com |
Public domain name or external IP address that WireGuard clients will use to connect. |
WG_PASSWORD_HASH |
$2b$12$U5DIA2y39QuBN0Cv4iZNxu9bb7NROm.gs2Kq.KbIi4uOzjJ3ST5u2 |
Bcrypt password hash used to log in to the WireGuard Easy web management interface (default: change_me). |
WG_DEFAULT_DNS |
1.1.1.1 |
DNS server provided to connecting WireGuard clients. |
Ecosystem & Enterprise Integration
- Reverse Proxy Ingress Ready: Pre-configured for Caddy, Traefik, or Nginx Proxy Manager with automatic Let's Encrypt TLS certificates.
- Zero-Trust Mesh VPN: Seamless integration with WireGuard or Tailscale/Headscale mesh networks for secure remote administration.
- Transactional State Backups: Ready for point-in-time database dumps and container-safe persistent volume freezing.
Effortless Management with NjordDeploy
Deploy, monitor, and update this service with a single click on your own hardware via the NjordDeploy Configurator.