7 ms·
Subspace – A simple WireGuard VPN server GUI
- lykr0n 6y agoI giggled at this project name. Seriously. This is cool. CLI rules all, but man, sometimes it's nice to use a GUI.
- hawski 6y agoIn my early Linux days I remember Subspace Continuum a 2d MMO space ship battle game. I did suck at it, but it was massively interesting.
- icholy 6y agoWhat's the deal with the fork?
- jamilbk 6y agoThe original project [1] hasn’t seen any commits in a year. [1] https://github.com/subspacecloud/subspace https://github.com/subspacecloud/subspace
- DCKing 6y agoGreat news this was forked. It was pretty clear the previous project was not really a project but a code dump (still: thank you to the original devs for sharing this with the world!), and so I refrained from using it. Really great this has become a more open project with continued development!
- rubatuga 6y agoIs there anybody interested in building or using a service that routes static public IPs to self-hosted servers, over WireGuard? I made a prototype a week ago, here's the homepage: https://hoppy.network https://hoppy.network I realized that I didn't want to ever deal with port-forwarding, NAT, or dynamic DNS and decided to create this. Message me if you want a signup link.
- PaulBGD_ 6y agoNot to oversimplify, but it's like a VPN that you have access to all the external ports on the IP?
- rubatuga 6y agoPlus it's static, supports roaming, and you get an IPv6 as well.
- 1cvmask 6y agoDo you have any milestones till you take this commercial?
- rubatuga 6y agoI need to create installation scripts that bring up the WireGuard interface without changing the server's routing table. Then I need to do documentation, figure out pricing/billing.
- ta999999171 6y agoI'm excellent at the last two. Let me know if you'd like help
- kortilla 6y agoIs this any different from something like the public IPs on NordVPN?
- rubatuga 6y agoYes, NordVPN doesn't do hosting, and it costs >$150 USD a year total for their public ips.
- jo909 6y agoI'm sure there is and will be demand for good static IPv4 tunnel brokers. I'm personally fine with dealing with dynamic DNS and port forwards for my home setup for now, but once I no longer have a public IPv4 assigned I would be a potential customer. How do you deal with the global scarcity of IPv4-addresses that you would need to scale your service? I think this can only work long term if you own the address space yourself and are not dependent on some specific provider or cloud. Also very important is a local endpoint to get a reasonable end to end latency.
- ochronus 6y agoKudos! Nice work, I hope this helps with the adoption of WireGuard
- PeterStuer 6y agoAnyone else thought of 'Subspace', the pioneering internet multiplayer space shooter from the 90's that was in many ways ahead of it's time? Great times were had. https://en.wikipedia.org/wiki/SubSpace_(video_game) https://en.wikipedia.org/wiki/SubSpace_(video_game)
- Daishiman 6y agoWhat became of it?
- jalada 6y agoIt's still a thing, it was re-released on Steam: https://store.steampowered.com/app/352700/Subspace_Continuum/ https://store.steampowered.com/app/352700/Subspace_Continuum...
- docflabby 6y agoI played this game for years in the competitive leagues and as a moderator running special events before life responsibilities took over (still pop in occasionally) is super fun. I was never very good at it though :)
- elric 6y agoIt's still being played. There are some plans to write an android client (notably by Trench War's poid, on patreon as quantumspace). Its golden days are long gone, but it's not uncommon to find games with 40 active players in Trench Wars these days.
- PH00 6y agoFor anyone who liked Subspace checkout Airmash: https://airmash.online/ https://airmash.online/ Originally released on HN. The game was abandoned by the developer. Entire thing was rewritten by the community and refuses to die. Lots of fun and great people involved. Keyboards can take a bit of a beating though.
- tiborsaas 6y ago
- naggie 6y agoShameless plug time: those interested in subspace might want to check out a project of mine: dsnet https://github.com/naggie/dsnet/ https://github.com/naggie/dsnet/ dsnet is a simple wiregard management command that manages key generation and IP allocation, generating config files. I'm using it for a few networks at the moment. I recently tried to add decent documentation and a blog post in the hope that it's useful to someone. I should so a Show HN really. Here's the blog post: https://callanbryant.co.uk/blog/how-to-set-up-a-wireguard-vpn-in-minutes-with-dsnet/ https://callanbryant.co.uk/blog/how-to-set-up-a-wireguard-vp...
- piquadrat 6y agoThis looks very interesting, thanks. Side note, any particular reason for having `user-select: none` set on your blog? That seems somewhat counterproductive for a blog with code examples...
- naggie 6y ago> This looks very interesting, thanks. I'm glad you like it. > Side note, any particular reason for having `user-select: none` set on your blog? That seems somewhat counterproductive for a blog with code examples... Ah -- that's not intentional. Thanks for letting me know, I've pushed a fix! I developed the hugo theme for something else where it made sense (a portal) then converted it for use with my blog and missed that.
- terrywang 6y agoAh, this is a fork, NOT the original. I came across the original subspace long time ago when switching from strongSwan (IPsec based VPN) to WireGuard for my own good. There has been no development work for the original project in a while. If you are looking for user friendly web UI for quickly building a VPN for remote access (encrypting traffic / data path between the device and Internet), with easy client management (scan the QR code for client profile thingy) try - wg-access-server [1] - wg-gen-web [2] - wg-ui [3] They all work well in a containerized fashion, all created around the same time when WireGuard was merged into Linux kernel mainline ;-) Simple script worked better for my remote access use case for now, for use cases at scale I'd seriously take Tailscale into account (100 clients for personal - free account). [1]: https://github.com/Place1/wg-access-server https://github.com/Place1/wg-access-server [2]: https://github.com/vx3r/wg-gen-web https://github.com/vx3r/wg-gen-web [3]: https://github.com/EmbarkStudios/wg-ui https://github.com/EmbarkStudios/wg-ui
- oregontechninja 6y agoPretty sure this is a fork because the original has arbitrary user limits due to it wanting to be a commericial product. Que hundreds of forks with the user limits removed.
- elitistphoenix 6y agoWhich one would you recommend?
- terrywang 6y ago
- unixhero 6y agoCould anyone refer to a definite guide to what Wireguard is, what painpoint it solves and effective applications of it? What kind of magic can I use it for to pipe data around securely in my AWS fortress?
- danielbln 6y agoIt's pretty clearly stated on the landing page of their website: https://www.wireguard.com/ https://www.wireguard.com/ - simplicity - sound crypto - minimal attack surface - high performance - well defined
- boringg 6y agoLet's be clear here. Subspace is and always will foremost be a fantastic massive online game from the late 90s. See wikipedia for more info. Slight disappointment that it wasn't related.
- hu3 6y agoI had no notion about the Subspace game and as time passes my parcel of the population will only grow relative to people who do know the Subspace game. It's not fair nor feasible to reserve names permanently.
- boringg 6y agoIt's cool - I'm having fun with nostalgia.
- hombre_fatal 6y agofwiw, the Continuum client is available even on Steam and some zones, like Trench Wars and Extreme Games still have full lobbies. I got back into Extreme Games (30-flag CTF) for 6 months last year. Good times all over again.
- econcon 6y agoAnyone who uses wireguard UI on Mac? I tried downloading it from app store, with error " unable to download to Macintosh HD " I am only one version behind the latest Mac, so what could be the problem?
- microcolonel 6y agoCool, the slick SSO feature means this may be a good choice if I want to set something up that I won't have to support until the day I die. I like how many choices there are for off-the-shelf configuration generators.
- simias 6y agoI don't mind the wg-quick command line interface but I must say that the #1 thing that bothers me with wg is that the private keys are stored directly in the config. That means that every time I add a new users the keys are plainly readable on my screen. Is there a simple way to work around this issue? Can I include the keys from a 3rd party file for instance? I guess I could always just pre-process the config file to generate the final one from multiple sources.
- BCM43 6y agoPostUp should do what you want. https://wiki.archlinux.org/index.php/WireGuard#Store_private_keys_in_encrypted_form https://wiki.archlinux.org/index.php/WireGuard#Store_private... I have it grabbing a key from AWS Secret Manager, haven't had a problem with that.
- atonse 6y agoIn case others got confused by this thread (I thought for a minute "how do you know which private key goes with which peer", is PostUp per peer, etc)... There is only one private key per interface on the server (or anywhere for that matter) and all the other peers are public keys. I might be the only one who confused myself :)
- simias 6y agoRight, my use of the plural was confusing. It's just that in general when you add a client you end up editing both the client and the server config, so both keys end up being disclosed on the screen.
- simias 6y agoThat's perfect! Thank you.
- cyphar 6y agoWhat I do is that I have scripts to manage the configuration file, rather than manually editing it. So you never open the configuration file in a terminal in order to see the private key.
- djsumdog 6y agoInteresting. I wonder if it re-creates the connection each time you login. The biggest issue I have with Wireguard is that it's not set up for Roadwarriors. If you have an endpoint with a dynamic IP address (like your home router), but you give wireguard a DNS name, it doesn't store the DNS name. It only stores the resolved IP address. The official solution is a script they have in their contrib repo that you stick in cron and it scans for changes and resets the endpoint if your DNS changes. Wireguard also can't bind to a specific adapter on a multi adapter server. Since it doesn't respond with anything with unauthenticated packets, the official solution is that is shouldn't matter. Just iptables on everything and only accept packets on the adapter you want public. The problem is, the egress packets will just go over the default adapter, so now you have incoming and outgoing packets taking different routes. Overall thought, I like wireguard way more than OpenVPN. They still need to fix those and other issues though.
- L_Rahman 6y agoI setup Wireguard using Algo on a home server I kept behind a home router with no problems. It was definitely a dynamic IP because Comcast doesn't provide static IPs for residential connections. Am I misunderstanding the limitation you're claiming?
- mbreese 6y agoI think the question is — does it still work when you get a new IP from Comcast? Even if you don’t have a static IP, your Comcast IP probably doesn’t change all that often. If WG stores the resolve IP instead of a dynamic dns domain name, you’d eventually have issues. I’m in the same boat, but my ISP almost never changes IPs.
- KAMSPioneer 6y agoI have configured a box with Wireguard listening on it, put a dynamic DNS updater on it, and gave it to my parents (they have a different ISP than I do). My .conf file had a DNS name as the peer, and it has worked just fine since it was installed. I don't know what issue GP is referring to; maybe an old version of wg-quick or something?
- chrisallick 6y agoBest video game ever.
- deleted 6y ago[deleted]
- abdulqabiz 6y agoNot sure following is related to the post, but it might help a few like me who are still using High Sierra (macos), and can't use the official WireGuard GUI client (becuase it targets newer versions of macos). You might want to check WireGuardStatusBar - https://github.com/aequitas/macos-menubar-wireguard https://github.com/aequitas/macos-menubar-wireguard I like it over wg-quick (which requires sudo, and prompts for password all the time). The WireGuardStatusBar uses a privileged helper, so you only need to authorize it once and use it all the time. Cheers.