A professional, web-based Django applican, WireGuard VPN Management
921
A professional, web-based Django application designed to automate and manage WireGuard VPN server and peer configurations. It provides an intuitive admin panel, automatic QR code generation, client configuration delivery via email, and robust asynchronous task processing using Celery.

This is the official, production-ready image for WireGuard Auto. It is a multi-stage, hardened Docker container based on Python 3.11-slim, pre-loaded with wireguard-tools, iproute2, and iptables. It runs the core Django application, Celery workers, and Celery beat schedulers.
This image requires a PostgreSQL database and a Redis instance to function. The easiest and recommended way to deploy is using Docker Compose.
docker-compose.ymlCreate a file named docker-compose.yml on your server with the following configuration:
version: '3.8'
services:
web:
image: developerantony/wg-auto:latest
ports:
- "8004:8004"
env_file: .env
environment:
- DATABASE_HOST=db
- REDIS_HOST=redis
- CELERY_BROKER_URL=redis://redis:6379/0
- CELERY_RESULT_BACKEND=redis://redis:6379/0
cap_add:
- NET_ADMIN
sysctls:
- net.ipv4.ip_forward=1
volumes:
- static_data:/app/staticfiles
- wg_config:/etc/wireguard
- app_logs:/app/logs
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
celery:
image: developerantony/wg-auto:latest
command: celery -A config worker --loglevel=info --concurrency=2
env_file: .env
network_mode: "host"
environment:
- DATABASE_HOST=127.0.0.1
- DATABASE_PORT=5432
- REDIS_HOST=127.0.0.1
- CELERY_BROKER_URL=redis://127.0.0.1:6379/0
- CELERY_RESULT_BACKEND=redis://127.0.0.1:6379/0
cap_add:
- NET_ADMIN
volumes:
- wg_config:/etc/wireguard
- app_logs:/app/logs
restart: unless-stopped
celery-beat:
image: developerantony/wg-auto:latest
command: celery -A config beat --loglevel=info --scheduler django_celery_beat.schedulers:DatabaseScheduler
env_file: .env
environment:
- DATABASE_HOST=db
- REDIS_HOST=redis
- CELERY_BROKER_URL=redis://redis:6379/0
- CELERY_RESULT_BACKEND=redis://redis:6379/0
volumes:
- app_logs:/app/logs
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
restart: unless-stopped
redis:
image: redis:7-alpine
ports:
- "127.0.0.1:6379:6379"
volumes:
- redis_data:/data
restart: unless-stopped
healthcheck:
test: ["CMD", "redis-cli", "ping"]
interval: 10s
timeout: 5s
retries: 5
db:
image: postgres:15-alpine
ports:
- "127.0.0.1:5432:5432"
environment:
POSTGRES_DB: ${DATABASE_NAME:-wireguard_db}
POSTGRES_USER: ${DATABASE_USER:-wireguard_user}
POSTGRES_PASSWORD: ${DATABASE_PASSWORD:?DATABASE_PASSWORD must be set}
volumes:
- postgres_data:/var/lib/postgresql/data
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${DATABASE_USER:-wireguard_user} -d ${DATABASE_NAME:-wireguard_db}"]
interval: 10s
timeout: 5s
retries: 5
volumes:
postgres_data:
redis_data:
static_data:
wg_config:
app_logs:
Create a .env file in the same directory:
# Core Django
DJANGO_SECRET_KEY=your-super-secret-key-change-me
DJANGO_DEBUG=False
# Cryptography (Must be exactly 32 URL-safe base64-encoded bytes)
# Generate with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
ENCRYPTION_KEY=your-fernet-key-here
# Database
DATABASE_NAME=wireguard_db
DATABASE_USER=wireguard_user
DATABASE_PASSWORD=your-secure-db-password
# Application Settings
WIREGUARD_ENDPOINT=vpn.yourdomain.com
Start the application in the background:
docker compose up -d
Once the containers are running, create your first superuser:
docker compose exec web python manage.py createsuperuser
Navigate to http://<your-server-ip>:8004 to log in and start managing your VPN!
To bypass Docker's known limitations with routing UDP packets for WireGuard, the celery container (which manages the WireGuard kernel interface) is configured with network_mode: "host". This physically attaches the wg1 interface to your host machine, ensuring perfect performance and handshake reliability.
MIT License. See the GitHub Repository for full source code and documentation.
Content type
Image
Digest
sha256:dbbd031a6…
Size
88.8 MB
Last updated
4 months ago
docker pull developerantony/wg-auto