Connect your devices into a single secure private WireGuard®-based mesh network with SSO/MFA and simple access controls.
Go to file
Maycon Santos 071b03e790
Updated self-hosted scripts and documentation (#249)
* Updated self-hosted scripts and documentation

Added more variables to setup.env and
Updated the documentation.

We are now configuring turn server
with template as well.

* Updated self-hosted scripts and documentation

Added more variables to setup.env and
Updated the documentation.

We are now configuring turn server
with template as well.

* Updated self-hosted scripts and documentation

Added more variables to setup.env and
Updated the documentation.

We are now configuring turn server
with template as well.

* Updated self-hosted scripts and documentation

Added more variables to setup.env and
Updated the documentation.

We are now configuring turn server
with template as well.
2022-03-05 11:20:04 +01:00
.github/workflows Update windows sign pipeline version (#248) 2022-03-03 10:21:58 +01:00
client Remove Wireguard peer in no-proxy mode on Close (#247) 2022-03-02 14:50:22 +01:00
docs Updated self-hosted scripts and documentation (#249) 2022-03-05 11:20:04 +01:00
encryption feature: basic auth0 support (#78) 2021-08-07 12:26:07 +02:00
iface Group users of same private domain (#243) 2022-03-01 15:22:18 +01:00
infrastructure_files Updated self-hosted scripts and documentation (#249) 2022-03-05 11:20:04 +01:00
management Group users of same private domain (#243) 2022-03-01 15:22:18 +01:00
release_files fix: avoid failing and extra error messages (#136) 2021-10-20 11:51:32 +02:00
signal Login exits on a single attempt to connect to management (#220) 2022-02-06 18:56:00 +01:00
util Write to temp file before saving data (#238) 2022-02-20 19:03:16 +01:00
.gitignore chore: add client distfiles to gitignore 2022-02-15 13:01:56 +01:00
.goreleaser.yaml Add client version to the client app and send it to the management service (#218) 2022-02-03 18:35:54 +01:00
AUTHORS chore: update license and AUTHORS 2022-01-19 16:22:40 +01:00
CODE_OF_CONDUCT.md Conduct (#205) 2022-01-26 09:33:16 +01:00
go.mod Bump wiretrustee-ice version 2022-02-18 15:06:44 +01:00
go.sum Write to temp file before saving data (#238) 2022-02-20 19:03:16 +01:00
LICENSE chore: update license and AUTHORS 2022-01-19 16:22:40 +01:00
README.md Update self-hosting docs 2022-03-02 09:52:09 +01:00

Start using Wiretrustee at app.wiretrustee.com
See Documentation
Join our Slack channel


Wiretrustee is an open-source VPN platform built on top of WireGuard® making it easy to create secure private networks for your organization or home.

It requires zero configuration effort leaving behind the hassle of opening ports, complex firewall rules, VPN gateways, and so forth.

Wiretrustee automates Wireguard-based networks, offering a management layer with:

  • Centralized Peer IP management with a UI dashboard.
  • Encrypted peer-to-peer connections without a centralized VPN gateway.
  • Automatic Peer discovery and configuration.
  • UDP hole punching to establish peer-to-peer connections behind NAT, firewall, and without a public static IP.
  • Connection relay fallback in case a peer-to-peer connection is not possible.
  • Multitenancy (coming soon).
  • Client application SSO with MFA (coming soon).
  • Access Controls (coming soon).
  • Activity Monitoring (coming soon).
  • Private DNS (coming soon)

Secure peer-to-peer VPN in minutes

Note: The main branch may be in an unstable or even broken state during development. For stable versions, see releases.

Hosted version: https://app.wiretrustee.com/.

UI Dashboard Repo

A bit on Wiretrustee internals

  • Wiretrustee features a Management Service that offers peer IP management and network updates distribution (e.g. when a new peer joins the network).
  • Wiretrustee uses WebRTC ICE implemented in pion/ice library to discover connection candidates when establishing a peer-to-peer connection between devices.
  • Peers negotiate connection through Signal Service.
  • Signal Service uses public Wireguard keys to route messages between peers. Contents of the messages sent between peers through the signaling server are encrypted with Wireguard keys, making it impossible to inspect them.
  • Occasionally, the NAT traversal is unsuccessful due to strict NATs (e.g. mobile carrier-grade NAT). When this occurs the system falls back to the relay server (TURN), and a secure Wireguard tunnel is established via the TURN server. Coturn is the one that has been successfully used for STUN and TURN in Wiretrustee setups.

Product Roadmap

Client Installation

Linux

APT/Debian

  1. Add the repository:
    sudo apt-get update
    sudo apt-get install ca-certificates curl gnupg -y
    curl -L https://pkgs.wiretrustee.com/debian/public.key | sudo apt-key add -
    echo 'deb https://pkgs.wiretrustee.com/debian stable main' | sudo tee /etc/apt/sources.list.d/wiretrustee.list
    
  2. Install the package
    sudo apt-get update
    sudo apt-get install wiretrustee
    

RPM/Red hat

  1. Add the repository:
    cat <<EOF | sudo tee /etc/yum.repos.d/wiretrustee.repo
    [Wiretrustee]
    name=Wiretrustee
    baseurl=https://pkgs.wiretrustee.com/yum/
    enabled=1
    gpgcheck=0
    gpgkey=https://pkgs.wiretrustee.com/yum/repodata/repomd.xml.key
    repo_gpgcheck=1
    EOF
    
  2. Install the package
    sudo yum install wiretrustee
    

MACOS

Brew install

  1. Download and install Brew at https://brew.sh/
  2. Install the client
brew install wiretrustee/client/wiretrustee

Installation from binary

  1. Checkout Wiretrustee releases
  2. Download the latest release (Switch VERSION to the latest):
curl -o ./wiretrustee_<VERSION>_darwin_amd64.tar.gz https://github.com/wiretrustee/wiretrustee/releases/download/v<VERSION>/wiretrustee_<VERSION>_darwin_amd64.tar.gz
  1. Decompress
tar xcf ./wiretrustee_<VERSION>_darwin_amd64.tar.gz
sudo mv wiretrusee /usr/local/bin/wiretrustee
chmod +x /usr/local/bin/wiretrustee

After that you may need to add /usr/local/bin in your MAC's PATH environment variable:

export PATH=$PATH:/usr/local/bin

Windows

  1. Checkout Wiretrustee releases
  2. Download the latest Windows release installer wiretrustee_installer_<VERSION>_windows_amd64.exe (Switch VERSION to the latest):
  3. Proceed with installation steps
  4. This will install the client in the C:\Program Files\Wiretrustee and add the client service
  5. After installing, you can follow the Client Configuration steps.

To uninstall the client and service, you can use Add/Remove programs

Client Configuration

  1. Login to the Management Service. You need to have a setup key in hand (see ).

For Unix systems:

sudo wiretrustee up --setup-key <SETUP KEY>

For Windows systems, start powershell as administrator and:

wiretrustee up --setup-key <SETUP KEY>

For Docker, you can run with the following command:

docker run --network host --privileged --rm -d -e WT_SETUP_KEY=<SETUP KEY> -v wiretrustee-client:/etc/wiretrustee wiretrustee/wiretrustee:<TAG>

TAG > 0.3.0 version

Alternatively, if you are hosting your own Management Service provide --management-url property pointing to your Management Service:

sudo wiretrustee up --setup-key <SETUP KEY> --management-url https://localhost:33073

You could also omit the --setup-key property. In this case, the tool will prompt for the key.

  1. Check your IP: For MACOS you will just start the service:
sudo ipconfig getifaddr utun100

For Linux systems:

ip addr show wt0

For Windows systems:

netsh interface ip show config name="wt0"
  1. Repeat on other machines.

Running Dashboard, Management, Signal and Coturn

See Self-Hosting Guide

WireGuard is a registered trademark of Jason A. Donenfeld.