⚡ Zero-Friction WireGuard Client Provisioning

Automate WireGuard client keys and configuration.

wg-init is a lightweight, reliable bootstrapping tool that generates cryptographic keypairs with strict umask 0077 permissions, validates environment parameters, and configures /etc/wireguard/wg0.conf ready for wg-quick.

One-liner Bootstrap Install
curl https://raw.githubusercontent.com/joshuacox/wg-init/refs/heads/main/bootstrap | bash

Interactive wg-init Command & Config Builder

Customize your WireGuard endpoint details below to instantly generate the exact execution command and resulting /etc/wireguard/wg0.conf file.

Assigned IP address inside the WireGuard subnet
DNS resolver applied when tunnel connects
Base64 WireGuard public key of the remote peer / server
IP ranges routed over this tunnel (e.g. 0.0.0.0/0 for full tunnel)
Public IP or domain and UDP port of the remote WireGuard server
Ready-to-run wg-init Command
MyAddress="192.168.1.5/24" \
MyDNS="192.168.1.1" \
PeerPublicKey="DEADBEEF1234567890abcdefDEADBEEF1234567890=" \
PeerAllowedIPs="192.168.1.0/24" \
PeerEndpoint="10.0.0.23:51820" \
wg-init
Target /etc/wireguard/wg0.conf Preview
[Interface]
Address = 192.168.1.5/24
PrivateKey = <generated in ~/.wg/keys/$HOSTNAME.key>
DNS = 192.168.1.1

[Peer]
PublicKey = DEADBEEF1234567890abcdefDEADBEEF1234567890=
AllowedIPs = 192.168.1.0/24
Endpoint = 10.0.0.23:51820

Built for Security, Simplicity, and Speed

WireGuard makes modern VPN tunnels fast and efficient, but manually creating client keys, maintaining directory permissions, and populating configuration files by hand is error prone. wg-init automates the entire flow.

🔐

Cryptographic Key Hardening

Generates keys into ~/.wg/keys/ with chmod 700 and an enforced umask 0077 pipeline. Your private key is never world or group readable.

🛡️

Strict Environment Validation

Validates all 5 mandatory networking parameters (MyAddress, MyDNS, PeerPublicKey, PeerAllowedIPs, PeerEndpoint) before executing or writing any files.

🚀

Safe Atomic Deployment

Assembles the configuration in an isolated temporary directory and installs it via sudo install -v -m400 into /etc/wireguard/wg0.conf, preventing accidental overwrites.

Installation Methods

Option 1: One-Line Bootstrap (Recommended)

Pulls the bootstrap script directly from GitHub, clones the repository into a safe temporary directory, and runs sudo make install:

Bootstrap One-liner
curl https://raw.githubusercontent.com/joshuacox/wg-init/refs/heads/main/bootstrap | bash

Option 2: Git Clone and Make Install

Clone the repository to inspect the shell scripts locally and install into /usr/local/bin/:

Manual Installation
git clone https://github.com/joshuacox/wg-init.git
cd wg-init
sudo make install

Option 3: Direct PATH Placement

Since wg-init is a single self-contained Bash script, you can place it anywhere on your system $PATH:

Direct Download
sudo curl -fsSL https://raw.githubusercontent.com/joshuacox/wg-init/main/wg-init -o /usr/local/bin/wg-init
sudo chmod 555 /usr/local/bin/wg-init

Environment Variables Reference

wg-init reads its configuration strictly from environment variables. If any variable is missing, the script halts with a helpful example.

VariableDescriptionExample Value
MyAddressLocal IP address and subnet mask assigned to this client inside the VPN tunnel.192.168.1.5/24
MyDNSDNS server IP used to resolve queries while connected to the VPN.192.168.1.1
PeerPublicKeyWireGuard public key of the remote peer / gateway server.DEADBEEF123=
PeerAllowedIPsSubnets routed through the peer. Use 0.0.0.0/0 for default routing.192.168.1.0/24
PeerEndpointPublic IP address or hostname and UDP listening port of the remote server.10.0.0.23:51820

Example Invocations

Running wg-init with inline variables
MyAddress=192.168.1.5/24 \
MyDNS=192.168.1.1 \
PeerPublicKey='DEADBEEF123=' \
PeerAllowedIPs='192.168.1.0/24' \
PeerEndpoint='10.0.0.23:51820' \
wg-init

Once wg-init finishes, it prints your local public key:

Example Output
Directory /home/user/.wg/keys already exists, continuing...
Installing /tmp/tmp.XXXX/wg0.conf to /etc/wireguard/
You can now use wg-quick
i.e.
sudo wg-quick up wg0
After you add your pub to your peer. Your pub is:

xK88n+7e9FpQ9k4N1q7Z8r8uW8dE8aP8t1Y8q3L5w7M=

Docker Sandbox & Testing Rig

The wg-init repository includes a dedicated Debian Trixie container test suite (Dockerfile, net.sh, and run.sh) to test WireGuard routing in an isolated Linux network namespace without modifying host interfaces.

Isolated Docker Bridge (net.sh)

Sets up a dual-stack IPv4 (10.43.43.0/24) and IPv6 (fdcc:ad94:bacf:62a3::/64) Docker network:

net.sh
#!/bin/bash
docker network create --subnet 10.43.43.0/24 \
  --ipv6 --subnet fdcc:ad94:bacf:62a3::/64 wg

Privileged Kernel Runner (run.sh)

Mounts kernel modules, enables sysctls for packet forwarding, and runs the WireGuard test container:

Executing test suite
./run.sh