WireGuard client for running a persistent site-to-site VPN endpoint as a TrueNAS SCALE Custom App.
1.1K
A small WireGuard client container intended for running a persistent site-to-site VPN endpoint as a TrueNAS SCALE Custom App.
The container renders a wg-quick configuration from environment variables, stores changed configs as timestamped history, starts one WireGuard interface, optionally refreshes a dynamic DNS endpoint, and cleans the interface up when the app stops.
wg-quick/configPreUp, PostUp, PreDown, and PostDown hooksTo let the tunnel affect the TrueNAS host network, run the app with:
Unless Stopped or Always/config is recommendedPrivileged mode gives the container broad host access. This is required for the simple TrueNAS Custom App setup because WireGuard interfaces, routes, iptables, and sysctl changes must happen in the host network namespace. Only run images you trust.
| Variable | Example | Description |
|---|---|---|
WG_ADDRESS | 10.255.0.2/32 | WireGuard address for this client. |
WG_PRIVATE_KEY | ... | Private key for this client. |
PEER_PUBLIC_KEY | ... | Public key of the remote WireGuard peer. |
PEER_ENDPOINT | wg.example.com:51820 | Remote endpoint hostname/IP and UDP port. |
PEER_ALLOWED_IPS | 172.20.10.0/24,10.255.0.1/32 | Routes sent through the tunnel. |
| Variable | Default | Description |
|---|---|---|
WG_IF | wg0 | WireGuard interface name. |
WG_LISTEN_PORT | empty | Optional local listen port. |
WG_DNS | empty | Optional DNS line for wg-quick. |
WG_MTU | empty | Optional MTU override. |
WG_TABLE | empty | Optional routing table override. |
WG_FWMARK | empty | Optional WireGuard fwmark. |
CONFIG_HISTORY_DIR | /config | Directory for timestamped generated config history. |
WG_REPLACE_EXISTING | false | Set to true to tear down an existing interface with the same WG_IF during startup. |
PEER_PRESHARED_KEY | empty | Optional preshared key. |
PEER_PERSISTENT_KEEPALIVE | 25 | Keepalive interval in seconds. |
RESOLVE_INTERVAL | 0 | Set to seconds, for example 300, to periodically re-resolve PEER_ENDPOINT. |
PRE_UP | empty | Semicolon or newline separated wg-quick PreUp commands. |
POST_UP | empty | Semicolon or newline separated wg-quick PostUp commands. |
PRE_DOWN | empty | Semicolon or newline separated wg-quick PreDown commands. |
POST_DOWN | empty | Semicolon or newline separated wg-quick PostDown commands. |
Use a WG_IF name that this app owns. If another host service already uses wg0, stop that service first, choose another interface name, or set WG_REPLACE_EXISTING=true.
Mount a persistent volume at:
/config
On each startup, the app renders a config from the environment.
Changed configs are saved as:
/config/wg0-YYYYMMDDTHHMMSSZ.conf
The latest config is linked as:
/config/wg0.conf
If the generated config has not changed, no duplicate history file is created.
WG_ADDRESS=10.255.0.2/32
WG_PRIVATE_KEY=<site-b-private-key>
PEER_PUBLIC_KEY=<site-a-public-key>
PEER_ENDPOINT=wg.example.com:51820
PEER_ALLOWED_IPS=172.20.10.0/24,10.255.0.1/32
PEER_PERSISTENT_KEEPALIVE=25
RESOLVE_INTERVAL=300
This creates a WireGuard client tunnel from the TrueNAS host to the remote peer.
If the remote site should reach hosts behind the TrueNAS system, enable forwarding and add firewall rules. Replace br0 with the actual TrueNAS LAN interface.
PRE_UP=sysctl -w net.ipv4.ip_forward=1
POST_UP=iptables -A FORWARD -i wg0 -o br0 -j ACCEPT; iptables -A FORWARD -i br0 -o wg0 -j ACCEPT
POST_DOWN=iptables -D FORWARD -i wg0 -o br0 -j ACCEPT; iptables -D FORWARD -i br0 -o wg0 -j ACCEPT
If the local router does not have a static route back to the remote tunnel/LAN networks, add masquerading:
POST_UP=iptables -A FORWARD -i wg0 -o br0 -j ACCEPT; iptables -A FORWARD -i br0 -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -s 172.20.10.0/24 -o br0 -j MASQUERADE; iptables -t nat -A POSTROUTING -s 10.255.0.0/24 -o br0 -j MASQUERADE
POST_DOWN=iptables -D FORWARD -i wg0 -o br0 -j ACCEPT; iptables -D FORWARD -i br0 -o wg0 -j ACCEPT; iptables -t nat -D POSTROUTING -s 172.20.10.0/24 -o br0 -j MASQUERADE; iptables -t nat -D POSTROUTING -s 10.255.0.0/24 -o br0 -j MASQUERADE
latestsha-... tags for non-release buildsGitHub: https://github.com/ACSimon33/truenas-wireguard-client-app
MIT
Content type
Image
Digest
sha256:3e50546d2…
Size
34.4 MB
Last updated
5 months ago
docker pull acsimon33/truenas-wireguard-client-app