A minimal, production-ready Docker image for running a WireGuard VPN server.
No web UI or reverse proxy is included by default, but you can easily extend with your own services (see Caddy example below).
1. Prepare Your WireGuard Configs
Create a configs directory and place your WireGuard configuration file(s) (e.g., wg0.conf) inside it.
2. Example docker-compose.yml:
version: '3.8'
services:
wireguard:
image: entrptaher/wireguard:latest
container_name: wireguard
cap_add:
- NET_ADMIN
- SYS_MODULE
devices:
- /dev/net/tun
sysctls:
net.ipv4.conf.all.src_valid_mark: 1
environment:
- BYPASS_IPS=100.103.22.36 # Optional: set to your bypass IPs or remove
volumes:
- ./configs:/etc/wireguard-configs:ro # Place your WireGuard .conf files here
ports:
- 51820:51820/udp # Match this to your WireGuard ListenPort
restart: unless-stopped
healthcheck:
test: ["CMD", "/healthcheck.sh"]
interval: 10s
timeout: 10s
retries: 3
start_period: 5s
3. Start the Service
docker compose up -d
You can run additional services (like a reverse proxy) inside the WireGuard network namespace.
Below is an example where Caddy runs as a reverse proxy, sharing the WireGuard container’s network stack.
Example docker-compose.yml:
version: '3.8'
services:
wireguard:
image: entrptaher/wireguard:latest
container_name: wireguard
cap_add:
- NET_ADMIN
- SYS_MODULE
devices:
- /dev/net/tun
sysctls:
net.ipv4.conf.all.src_valid_mark: 1
environment:
- BYPASS_IPS=100.103.22.36
volumes:
- ./configs:/etc/wireguard-configs:ro
ports:
- 51820:51820/udp
- 8000:80 # Expose Caddy's HTTP port via WireGuard container
restart: unless-stopped
healthcheck:
test: ["CMD", "/healthcheck.sh"]
interval: 10s
timeout: 10s
retries: 3
start_period: 5s
caddy:
image: caddy:latest
container_name: caddy
network_mode: "service:wireguard" # Shares network with WireGuard
command: >
caddy reverse-proxy
--change-host-header
--from :80
--to https://ip.me:443
depends_on:
- wireguard
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://localhost:80"]
interval: 30s
timeout: 5s
retries: 3
start_period: 10s
How it works:
BYPASS_IPS/etc/wireguard-configs51820/udp8000:80The container includes a healthcheck script. Docker will automatically restart the container if it becomes unhealthy.
/dev/net/tun on the hostTo update to the latest version:
docker compose pull
docker compose up -d
Is a web UI or proxy included?
No. This image is for running WireGuard only. You can add your own reverse proxy or management UI if desired (see Caddy example).
Can I run this on ARM or Raspberry Pi?
Yes, multi-architecture builds are supported.
MIT
Secure, fast, and minimal WireGuard VPN in Docker.
For questions or issues, open a GitHub issue or discussion.
Happy networking!
Content type
Image
Digest
sha256:c09a30a2e…
Size
5.9 MB
Last updated
over 1 year ago
docker pull entrptaher/wireguard