About wg-init
The philosophy, security considerations, and architecture behind the tool.
The Motivation
WireGuard is renowned for its speed, simplicity, and state-of-the-art cryptography. However, provisioning new client workstations or IoT nodes often involves multiple manual steps:
- Generating private and public keys using
wg genkeyandwg pubkey. - Ensuring proper UNIX file permissions (
chmod 600orumask 0077) so private keys are never exposed. - Constructing the
wg0.conffile with the correct sections, endpoints, and allowed IPs. - Writing the configuration into
/etc/wireguard/with root privileges without leaving world-readable temporary files.
wg-init automates this routine into a single idempotent command with built-in guardrails against configuration overwrites and permission leaks.
Security By Design
Subshell umask Isolation
During key generation, (umask 0077 && tee $HOSTNAME.key) guarantees that newly created private key files are strictly accessible only by the owner from the exact microsecond of creation.
Atomic Non-Destructive Install
If /etc/wireguard/wg0.conf already exists, wg-init refuses to overwrite it, protecting active VPN profiles from accidental deletion.
Open Source & Licensing
wg-init is open source software created by Joshua Cox and distributed under the GNU General Public License v3.0 (GPL-3.0).
Source code, Docker testing harnesses, and documentation contributions are welcomed at: