Self-host wg-easy
The easiest way to run your own WireGuard VPN server, with a clean web UI for adding and managing clients — a self-hosted alternative to Tailscale and commercial VPNs for private access to your network from anywhere.
Key facts
Pick wg-easy when you want one WireGuard server with a web UI and nothing else to learn: add a client, scan the QR code, done. The v15 line (a full rewrite; v15.4.0 as of September 2026) lists one-time links, client expiry, 2FA, OIDC login, Prometheus metrics, IPv6 and per-client firewall rules among its features, all in one AGPL-3.0 container, and the documented requirements are just a host you manage, a domain or public IP, `curl`, and x86_64 or arm64. It is a hub-and-spoke VPN, not a mesh — every client routes through this one box — which is exactly why it is the simplest pick here.
Follow the wg-easy deploy guide →What you need
- Any VPS with at least 256 MB of RAM
- A domain you control — most self-hosted setups need HTTPS in front of them
- Under an hour if you've used Docker before
Paid link — we earn a commission if you shop through it.
Install
Run these commands on your server:
# wg-easy — official docker run (docs → Examples → Docker Run); web UI on 51821/tcp, tunnel on 51820/udp
# 1. One-time IPv6-enabled bridge network the container gets fixed addresses on
docker network create -d bridge --ipv6 --subnet 10.42.42.0/24 --subnet fdcc:ad94:bacf:61a3::/64 wg
# 2. The container. The /lib/modules mount is required — without it wg0 never comes up.
docker run -d --net wg -e INSECURE=true --name wg-easy \
--ip6 fdcc:ad94:bacf:61a3::2a --ip 10.42.42.42 \
-v ~/.wg-easy:/etc/wireguard \
-v /lib/modules:/lib/modules:ro \
-p 51820:51820/udp -p 51821:51821/tcp \
--cap-add NET_ADMIN --cap-add SYS_MODULE \
--sysctl net.ipv4.ip_forward=1 --sysctl net.ipv4.conf.all.src_valid_mark=1 \
--sysctl net.ipv6.conf.all.disable_ipv6=0 --sysctl net.ipv6.conf.all.forwarding=1 --sysctl net.ipv6.conf.default.forwarding=1 \
--restart unless-stopped ghcr.io/wg-easy/wg-easy:15
# → http://SERVER_IP:51821 — the first-run wizard creates the admin account. INSECURE=true allows plain HTTP;
# for HTTPS put Caddy or Traefik in front (docs → Examples) and drop it.What you take on
wg-easy's defaults are safe, which means a few of them will stop you until you read the docs: