wiretastix

Wiretastix Documentation

A self-hosted WireGuard VPN server with a web-based admin panel, OIDC/SSO authentication, and zero-touch peer provisioning.

Why Wiretastix?

Wiretastix is a self-hosted WireGuard VPN server with a web-based admin panel, transforming WireGuard VPN management from a manual, error-prone process into an automated, self-service solution. Built for teams that need secure remote access without the operational overhead, Wiretastix delivers the performance of WireGuard with the convenience of modern identity management.

Zero-Touch User Provisioning

Your users authenticate once through your existing identity provider—Google, Azure AD, Okta, Keycloak, or any OIDC-compliant system. Wiretastix automatically generates their VPN configuration, manages keys, assigns IP addresses, and applies the right access policies based on their groups. No manual configuration files, no support tickets, no SSH sessions to add users. Your team logs in, scans a QR code, and they’re connected.

Minimal Administrative Overhead

Stop spending hours managing VPN users, rotating keys, and troubleshooting configuration mistakes. Wiretastix handles peer lifecycle management, key rotation, and network policy enforcement automatically. Your administrators define policies once through group-based access control, and Wiretastix ensures they’re consistently applied across your entire VPN infrastructure. The web-based admin panel and powerful CLI put complete control at your fingertips without complexity.

Security Without Compromise

Wiretastix inherits WireGuard’s proven cryptographic security—fast, modern, and auditable. Layer on identity-provider authentication through OIDC, granular firewall rules per user group via nftables integration, automatic key management, and comprehensive audit logging. TLS-encrypted management interface, secure database storage, and integration with your existing security infrastructure mean you get defense-in-depth without sacrificing speed or usability.

Built on WireGuard’s Speed

Wiretastix doesn’t slow down WireGuard—it enhances it. Your VPN traffic flows at line speed through WireGuard’s lightweight kernel implementation while Wiretastix handles the control plane separately. Sub-millisecond handshakes, minimal CPU overhead, seamless roaming between networks, and efficient battery usage on mobile devices. Your users get a VPN that’s faster than most corporate connections without feeling like they’re connected to one.

What You Get

Modern organizations need VPN solutions that scale with their teams, integrate with their identity infrastructure, and just work. Wiretastix delivers this through automated peer provisioning, OIDC-based authentication, group-based access policies, integrated DNS resolution with automatic PTR records, dynamic nftables firewall management, Prometheus metrics for monitoring, and a REST API for automation. Whether you’re running ten users or ten thousand, Wiretastix scales without complexity.

Perfect For

Wiretastix excels when you need to provide secure access to remote teams, protect IoT device communications, connect multiple office locations, enable contractor access with time-limited policies, or replace legacy VPN solutions with modern infrastructure. If you’re currently managing WireGuard configurations by hand or struggling with the complexity of traditional VPN solutions, Wiretastix is your answer.


Documentation Structure

This documentation follows the Diátaxis framework to help you find exactly what you need:

Concepts: Understand how Wiretastix works—OIDC integration, nftables firewall management, DNS resolution, database architecture, and security model. Read these to grasp the system’s design and capabilities.

Tutorials: Step-by-step installation guides for Debian packages, Docker Compose, Kubernetes, and building from source. Follow these to get Wiretastix running in your environment quickly.

How-to Guides: Practical instructions for specific tasks—configuring identity providers, setting up reverse proxies, managing peers and groups, backup and recovery, and monitoring. Use these when you need to accomplish a particular goal.

Reference: Complete technical specifications—configuration file format, CLI commands, REST API endpoints, Prometheus metrics, and database schema. Consult these for detailed information on specific features.

Start with the tutorials to get Wiretastix installed, then explore the how-to guides to configure it for your needs. The concepts section deepens your understanding, while the reference provides authoritative details when you need them.