3 ms·
In the case that someone has any trouble configuring WireGuard, I would like to share my automatic deployment of WireGuard and Unbound with full IPv4 and IPv6 s
by hectorm 7y ago
In the case that someone has any trouble configuring WireGuard, I would like to share my automatic deployment of WireGuard and Unbound with full IPv4 and IPv6 support with Packer and Terraform in Hetzner Cloud (although it can be easily adapted to other providers) [1].
In the case that no automatic deployment is necessary, it may also be useful to look directly at the WireGuard configuration [2]. Since WireGuard supports scripts in "PostUp" and "PostDown", I have automated the configuration of iptables, including some useful rules to redirect 53/UDP port traffic from the public interface to WireGuard, which helps in some cases to bypass some firewalls.
[1]: https://github.com/hectorm/wireguard-setup https://github.com/hectorm/wireguard-setup
[2]: https://github.com/hectorm/wireguard-setup/blob/master/packer/rootfs/etc/wireguard/wg0.conf https://github.com/hectorm/wireguard-setup/blob/master/packe...
- LilBytes 7y agoThis is awesome, I'll be giving it a go this week. Thanks!
- saber6 7y agoVery nice! I just finished a very similar home project consisting of WireGuard in CentOS VM, built via Packer, deployed via Terraform to an on-prem vCenter cluster (vSphere/ESXi Host). All of the software/tools are inside a Docker container (for versioning). Next, I plan on doing AWS, Azure, Google, and Packet. I'll send you a note when I put my stuff on GitHub as you may be interested in some of the tooling (specifically, Makefiles to help speed up workflows).