Automate WireGuard client keys and configuration.
wg-init is a lightweight, reliable bootstrapping tool that generates cryptographic keypairs with strict umask 0077 permissions, validates environment parameters, and configures /etc/wireguard/wg0.conf ready for wg-quick.
curl https://raw.githubusercontent.com/joshuacox/wg-init/refs/heads/main/bootstrap | bashInteractive wg-init Command & Config Builder
Customize your WireGuard endpoint details below to instantly generate the exact execution command and resulting /etc/wireguard/wg0.conf file.
MyAddress="192.168.1.5/24" \
MyDNS="192.168.1.1" \
PeerPublicKey="DEADBEEF1234567890abcdefDEADBEEF1234567890=" \
PeerAllowedIPs="192.168.1.0/24" \
PeerEndpoint="10.0.0.23:51820" \
wg-init[Interface]
Address = 192.168.1.5/24
PrivateKey = <generated in ~/.wg/keys/$HOSTNAME.key>
DNS = 192.168.1.1
[Peer]
PublicKey = DEADBEEF1234567890abcdefDEADBEEF1234567890=
AllowedIPs = 192.168.1.0/24
Endpoint = 10.0.0.23:51820Built for Security, Simplicity, and Speed
WireGuard makes modern VPN tunnels fast and efficient, but manually creating client keys, maintaining directory permissions, and populating configuration files by hand is error prone. wg-init automates the entire flow.
Cryptographic Key Hardening
Generates keys into ~/.wg/keys/ with chmod 700 and an enforced umask 0077 pipeline. Your private key is never world or group readable.
Strict Environment Validation
Validates all 5 mandatory networking parameters (MyAddress, MyDNS, PeerPublicKey, PeerAllowedIPs, PeerEndpoint) before executing or writing any files.
Safe Atomic Deployment
Assembles the configuration in an isolated temporary directory and installs it via sudo install -v -m400 into /etc/wireguard/wg0.conf, preventing accidental overwrites.
Installation Methods
Option 1: One-Line Bootstrap (Recommended)
Pulls the bootstrap script directly from GitHub, clones the repository into a safe temporary directory, and runs sudo make install:
curl https://raw.githubusercontent.com/joshuacox/wg-init/refs/heads/main/bootstrap | bashOption 2: Git Clone and Make Install
Clone the repository to inspect the shell scripts locally and install into /usr/local/bin/:
git clone https://github.com/joshuacox/wg-init.git
cd wg-init
sudo make installOption 3: Direct PATH Placement
Since wg-init is a single self-contained Bash script, you can place it anywhere on your system $PATH:
sudo curl -fsSL https://raw.githubusercontent.com/joshuacox/wg-init/main/wg-init -o /usr/local/bin/wg-init
sudo chmod 555 /usr/local/bin/wg-initEnvironment Variables Reference
wg-init reads its configuration strictly from environment variables. If any variable is missing, the script halts with a helpful example.
| Variable | Description | Example Value |
|---|---|---|
| MyAddress | Local IP address and subnet mask assigned to this client inside the VPN tunnel. | 192.168.1.5/24 |
| MyDNS | DNS server IP used to resolve queries while connected to the VPN. | 192.168.1.1 |
| PeerPublicKey | WireGuard public key of the remote peer / gateway server. | DEADBEEF123= |
| PeerAllowedIPs | Subnets routed through the peer. Use 0.0.0.0/0 for default routing. | 192.168.1.0/24 |
| PeerEndpoint | Public IP address or hostname and UDP listening port of the remote server. | 10.0.0.23:51820 |
Example Invocations
MyAddress=192.168.1.5/24 \
MyDNS=192.168.1.1 \
PeerPublicKey='DEADBEEF123=' \
PeerAllowedIPs='192.168.1.0/24' \
PeerEndpoint='10.0.0.23:51820' \
wg-initOnce wg-init finishes, it prints your local public key:
Directory /home/user/.wg/keys already exists, continuing...
Installing /tmp/tmp.XXXX/wg0.conf to /etc/wireguard/
You can now use wg-quick
i.e.
sudo wg-quick up wg0
After you add your pub to your peer. Your pub is:
xK88n+7e9FpQ9k4N1q7Z8r8uW8dE8aP8t1Y8q3L5w7M=Docker Sandbox & Testing Rig
The wg-init repository includes a dedicated Debian Trixie container test suite (Dockerfile, net.sh, and run.sh) to test WireGuard routing in an isolated Linux network namespace without modifying host interfaces.
Isolated Docker Bridge (net.sh)
Sets up a dual-stack IPv4 (10.43.43.0/24) and IPv6 (fdcc:ad94:bacf:62a3::/64) Docker network:
#!/bin/bash
docker network create --subnet 10.43.43.0/24 \
--ipv6 --subnet fdcc:ad94:bacf:62a3::/64 wgPrivileged Kernel Runner (run.sh)
Mounts kernel modules, enables sysctls for packet forwarding, and runs the WireGuard test container:
./run.sh