Waarom deze configuratie?
- Echte data-soevereiniteit: 100% AVG/GDPR compliant. Lokale gegevens en configuratie blijven op eigen hardware zonder cloud-afhankelijkheid.
- Hardware agnostisch: Geoptimaliseerd voor Raspberry Pi 5 (ARM64) en Proxmox VE hypervisors (x86_64 LXC & VM).
- Engine vrijheid: Getest en gevalideerd voor Docker CE en rootless Podman zonder root-privileges.
- Platform verificatie: Tested on Proxmox LXC: docker (22.16.0, 2026-09-14), podman (22.16.0, 2026-09-14); Proxmox VM: docker (22.16.0, 2026-09-14), podman (22.16.0, 2026-09-14).
Snelle Start (Standalone Docker Compose)
Onderstaand compose-fragment is direct te gebruiken in elke Docker- of Podman-omgeving:
services:
wg-easy:
image: ghcr.io/wg-easy/wg-easy:latest
container_name: njorddeploy-wg-easy
restart: unless-stopped
cap_add:
- NET_ADMIN
- SYS_MODULE
- NET_RAW
sysctls:
- net.ipv4.ip_forward=1
- net.ipv4.conf.all.src_valid_mark=1
environment:
- "WG_HOST=vpn.example.com"
- "PASSWORD_HASH=$2b$12$U5DIA2y39QuBN0Cv4iZNxu9bb7NROm.gs2Kq.KbIi4uOzjJ3ST5u2"
- "PORT=51821"
- "WG_PORT=51820"
- "WG_DEFAULT_DNS=1.1.1.1"
volumes:
- "./data/wg-easy/wireguard:/etc/wireguard"
- "/lib/modules:/lib/modules:ro"
ports:
- "51820:51820/udp"
- "51821:51821/tcp"
networks:
- njorddeploy_net
networks:
njorddeploy_net:
Start de service direct via de commandline: docker compose up -d
Configuratie & Omgevingsvariabelen
Belangrijkste configuratieparameters en standaardwaarden uit de NjordDeploy component-sjabloon:
| Variable | Default Value | Description |
|---|---|---|
WG_EASY_WEB_PORT |
51821 |
Host port used to access the WireGuard Easy administration web interface. |
WG_EASY_PORT |
51820 |
Public UDP port on which WireGuard VPN traffic will be received. |
WG_HOST |
vpn.example.com |
Public domain name or external IP address that WireGuard clients will use to connect. |
WG_PASSWORD_HASH |
$2b$12$U5DIA2y39QuBN0Cv4iZNxu9bb7NROm.gs2Kq.KbIi4uOzjJ3ST5u2 |
Bcrypt password hash used to log in to the WireGuard Easy web management interface (default: change_me). |
WG_DEFAULT_DNS |
1.1.1.1 |
DNS server provided to connecting WireGuard clients. |
Ecosysteem & Bedrijfsintegratie
- Reverse Proxy Klaar: Direct te koppelen met Caddy, Traefik of Nginx Proxy Manager inclusief automatische Let's Encrypt TLS.
- Veilige Remote Toegang: Naadloos te combineren met WireGuard of Tailscale/Headscale voor veilige toegang buiten het lokale netwerk.
- Transactieve Back-ups: Geschikt voor point-in-time database dumps en container-safe volume snapshotting via NjordDeploy.
Eenvoudig beheren via NjordDeploy
Installeer, bewaak en update deze service met 1 klik op uw eigen Raspberry Pi of Proxmox server via de NjordDeploy Configurator.