A unified Dockerized solution to manage WireGuard VPN access control lists (ACLs) via a web UI with built-in monitoring and failsafe host lockdown capabilities. The container runs both the web UI and monitor in a single instance for simplified deployment.
Features:
Note: WireGuard defaults are based on Linuxserver/wireguard. If using a different WireGuard container, adjust names and directories using environment variables.
docker pull remotecellist/wireguard-acl:latest
Create a strong flask key:
openssl rand -base64 32 # generate a strong secret key
Run the unified container (web UI + monitor):
docker run -d \
--name wireguard-acl \
--privileged \
--network host \
--cap-add NET_ADMIN \
--cap-add SYS_ADMIN \
-e APP_PASSWORD='change-me' \
-e FLASK_SECRET_KEY='paste-generated-key' \
-e ENABLE_HOST_LOCKDOWN=true \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
-v /lib/modules:/lib/modules:ro \
-v ./users-data:/app/users-data:rw \
--restart unless-stopped \
remotecellist/wireguard-acl:latest
Access the web UI at: http://localhost:5001
If your WireGuard container name, config dir, or port differ from defaults, add:
-e DOCKER_WIREGUARD_CONTAINER_NAME=my-wg \
-e WIREGUARD_CONFIG_DIR=/etc/wireguard \
-e WIREGUARD_PORT=51820 \
Create a strong flask key:
openssl rand -base64 32 # generate a strong secret key
Use the compose below in your desired directory:
services:
wireguard-acl:
image: remotecellist/wireguard-acl:latest
container_name: wireguard-acl
restart: unless-stopped
privileged: true
network_mode: host
cap_add:
- NET_ADMIN
- SYS_ADMIN
environment:
- FLASK_SECRET_KEY=your-secret-key-here
- APP_PASSWORD=your-app-password-here
- WEB_PORT=5001
- DOCKER_WIREGUARD_CONTAINER_NAME=wireguard
- ENABLE_HOST_LOCKDOWN=true
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
- /lib/modules:/lib/modules:ro
- ./users-data:/app/users-data:rw
healthcheck:
test: ["CMD", "wget", "--no-verbose", "--tries=1", "--spider", "http://localhost:5001/api/check_session"]
interval: 30s
timeout: 10s
retries: 3
start_period: 30s
Access the web UI at: http://localhost:5001
Notes:
wireguard with configs in /config)DOCKER_WIREGUARD_CONTAINER_NAME (default: wireguard)WIREGUARD_CONFIG_DIR (default: /config)WIREGUARD_PORT (default: 51820, used for lockdown)Required:
openssl rand -base64 32Optional:
5001)wireguard)/config)51820)true)/app/users-data)users.json)24)INFO)/app/users-data (rw): Persists users configuration (users.json)/var/run/docker.sock (ro): Enables the UI to execute docker commands against your WireGuard container/lib/modules (ro): Required for iptables functionalitynetwork_mode: host, so the web UI is accessible directly on localhost:5001-p flags or ports: section requiredGET /api/check_session which returns { "isAuthenticated": <bool> }.${WIREGUARD_CONFIG_DIR} (default: /config)/var/run/docker.sockAPP_PASSWORD and FLASK_SECRET_KEYprivileged: true and network_mode: host for iptables accessprivileged: true and network_mode: hostlocalhost:5001 instead of container nameContent type
Image
Digest
sha256:52ba9a705…
Size
39.4 MB
Last updated
about 1 year ago
docker pull remotecellist/wireguard-acl