updateInterfaceLdapFilters saved the matched users with SaveInterface, which creates the interface when it is missing. On first start that panics. The sync runs immediately (main.go:85) and the importer later (main.go:116), so the sync creates a stub row for every interface_filter key, and the importer, which snapshotted the interface list before its device round-trips, then fails with "interface already exists". The window is GetInterfaces plus GetPeers, so a directory on localhost loses the race and a slower one hides it. The stub rows are wrong anyway. They have no backend, so a typo in an interface_filter key quietly created an interface attached to no controller. Look the interface up and skip with a warning when it is absent. The filter is applied on the next sync once the importer has created it. A lookup error that is not ErrNotFound also skips. Signed-off-by: clark-ja <37738506+clark-ja@users.noreply.github.com>
WireGuard Portal v2
Introduction
WireGuard Portal is a simple, web-based configuration portal for WireGuard server management. The portal uses the WireGuard wgctrl library to manage existing VPN interfaces. This allows for the seamless activation or deactivation of new users without disturbing existing VPN connections.
The configuration portal supports using a database (SQLite, MySQL, MsSQL, or Postgres), OAuth or LDAP (Active Directory or OpenLDAP) as a user source for authentication and profile data.
Features
- Self-hosted - the whole application is a single binary
- Responsive multi-language web UI with dark-mode written in Vue.js
- Automatically selects IP from the network pool assigned to the client
- QR-Code for convenient mobile client configuration
- Sends email to the client with QR-code and client config
- Enable / Disable clients seamlessly
- Generation of wg-quick configuration file (
wgX.conf) if required - User authentication (database, OAuth, or LDAP), Passkey support
- IPv6 ready
- Docker ready
- Can be used with existing WireGuard setups
- Support for multiple WireGuard interfaces
- Supports multiple WireGuard backends (wgctrl, MikroTik, or pfSense)
- Peer Expiry Feature
- Handles route and DNS settings like wg-quick does
- Exposes Prometheus metrics for monitoring and alerting
- REST API for management and client deployment
- Webhook for custom actions on peer, interface, or user updates
Documentation
For the complete documentation visit wgportal.org.
What is out of scope
- Automatic generation or application of any
iptablesornftablesrules. - Support for operating systems other than linux.
- Automatic import of private keys of an existing WireGuard setup.
Application stack
- wgctrl-go and netlink for interface handling
- Bootstrap, for the HTML templates
- Vue.js, for the frontend
License
- MIT License. MIT or https://opensource.org/licenses/MIT
Contributors and Sponsors
Thanks so much for all your contributions! They’re truly appreciated and help keep WireGuard Portal moving ahead.
Want to support the project? You can buy me a coffee or join as a contributor - every bit of support helps! Become a sponsor!
Important
Since the project was accepted by the Docker-Sponsored Open Source Program, the Docker image location has moved to wgportal/wg-portal. Please update the Docker image from h44z/wg-portal to wgportal/wg-portal.
