Security
Self-host WireGuard Easy
The easiest way to run WireGuard VPN — web UI for clients, QR codes and stats. Requires instance admin (NET_ADMIN / SYS_MODULE).
Deploy WireGuard Easy with Nixploy
Install Nixploy on any Docker host — a €5 VPS is enough for most of these:
curl -fsSL https://raw.githubusercontent.com/bablilayoub/nixploy/main/install.sh | sudo bash- 1
Open Templates in the panel
Search for WireGuard Easy and open it. The compose file, the variables and the suggested domain are already filled in.
- 2
Give it a domain
Point a DNS record at your server and enter it. Traefik requests the certificate on the first request — there is no separate certbot step and nothing to renew by hand.
- 3
Deploy
Nixploy renders the compose file, validates it against the platform's safety rules, and brings the stack up on a private per-environment network. Live logs stream while it happens.
- 4
Schedule a backup
WireGuard Easy keeps its state in a named volume (wg-easy-data). Add a schedule and Nixploy streams the dump to S3 or to disk, encrypted, and can verify a restore.
What this deploys
- Images
- ghcr.io/wg-easy/wg-easy:latest
- Routed to
- wg-easy:51821
- Persistent volumes
- wg-easy-data
- Variables it asks for
- WG_HOSTPublic hostname or IP clients connect to
- Secrets Nixploy generates
- PASSWORD_HASHCreated at deploy time and stored encrypted — you never invent or paste them.
- Privileged
- Needs the Docker socket or elevated capabilities, so only the instance admin can deploy it.
What you get with it
Automatic HTTPS through Traefik and Let's Encrypt, renewed for you.
Live logs, a web terminal into the container, and CPU/memory/network history.
Encrypted backups to S3 or disk, on a schedule, with verified restores.
Roll back to the previous version when an update goes wrong.
An MCP endpoint, so an AI agent can deploy, read the logs and diagnose it for you — see the MCP guide.
Why self-host WireGuard Easy?
Running it yourself means the data lives on a disk you control, there is no per-seat price as the team grows, and nothing is retired or repriced by somebody else. The cost is the part Nixploy takes over: a reverse proxy, certificates that renew, a volume that survives a redeploy, backups you can actually restore, and a way to see the logs when it misbehaves.
WireGuard Easy upstream
Nixploy packages the project; it is not affiliated with it. Docs · Source
All 146 templates