Sign inSign up

molinaig/wireguard-proxy

By molinaig

•Updated 3 months ago

Image
0

216

molinaig/wireguard-proxy repository overview

⁠wireguard-proxy

Docker container with WireGuard VPN client and Squid proxy.

The idea is simple:

Client -> Squid Proxy -> WireGuard VPN -> Internet

⁠Features

  • WireGuard VPN client
  • Squid HTTP proxy
  • Username/password authentication
  • Automatic WireGuard configuration from environment variables
  • Docker-friendly routing
  • Fail-safe startup (proxy only works when WireGuard is active)

⁠Docker Compose example

services:
  wireguard-proxy:
    image: molinaig/wireguard-proxy:latest
    container_name: wireguard-proxy
    restart: unless-stopped

    cap_add:
      - NET_ADMIN

    devices:
      - /dev/net/tun:/dev/net/tun

    ports:
      - "3131:3128"

    environment:
      WG_PRIVATE_KEY: "xxxxxxxxxxxxxxxxxxx"
      WG_ADDRESS: "10.2.0.2/32, 2a07:b944::2:2/128"
      WG_DNS: "10.2.0.1, 2a07:b944::2:1"
      WG_PUBLIC_KEY: "xxxxxxxxxxxxxxxxxxxxxxxxxxx"
      WG_ENDPOINT: "1.2.3.4:51820"

      SQUID_USERNAME: "user"
      SQUID_PASSWORD: "pass"

⁠Environment Variables

VariableDescription
WG_PRIVATE_KEYWireGuard private key
WG_ADDRESSWireGuard IP address(es)
WG_DNSDNS server(s)
WG_PUBLIC_KEYWireGuard server public key
WG_ENDPOINTWireGuard server endpoint (IP:PORT)
SQUID_USERNAMEProxy username
SQUID_PASSWORDProxy password

⁠Example WireGuard Configuration

The container automatically generates a WireGuard configuration similar to:

[Interface]
PrivateKey = yA3P06QRHQFRVVhG6X+Hjstm5OamLyxIeLYhLKtf8FM=
Address = 10.2.0.2/32, 2a07:b944::2:2/128

[Peer]
PublicKey = DznTG0WjFUlvggmQ9FsoUvbrU6D9zz1YgdRImKR/+18=
AllowedIPs = 0.0.0.0/0, ::/0
Endpoint = 169.150.218.90:51820
PersistentKeepalive = 25

⁠Start Container

docker compose up -d

⁠View Logs

docker logs -f wireguard-proxy

⁠Test Proxy

curl -x http://user:[email protected]:3131 http://ip-api.com/json

Example output:

{
  "status": "success",
  "country": "Netherlands",
  "countryCode": "NL",
  "query": "x.x.x.x"
}

⁠Network Diagram

                    +-------------------+
                    |    WireGuard      |
                    |       VPN         |
                    +---------+---------+
                              ^
                              |
                              |
+-----------+       +---------+---------+
|  Client   | ----> |      Squid        |
+-----------+       +---------+---------+
                              |
                              |
                    +---------+---------+
                    | wireguard-proxy   |
                    |    Container      |
                    +-------------------+

⁠Port Mapping

Internal Squid listens on port 3128.

Example:

Host:3131 -> Container:3128

This allows multiple WireGuard proxy containers to run on the same host using different ports.

Tag summary

Content type

Image

Digest

sha256:54c907b54…

Size

807.6 MB

Last updated

3 months ago

docker pull molinaig/wireguard-proxy