Reads /etc/wireguard, lets you add/edit/remove peers, applies with wg syncconf (no interface bounce). Does not install WireGuard or rewrite your PostUp/NAT. That's all
Seems like high-risk and low-reward for your network security. You could host it behind the WG interface, but… still exposing the castle’s master key to a python web app.
I have found that WG client management is as simple as a couple scripts and a TSV file to match pubkeys to users.
Anyhow, cool project and I like the overall concept of respecting existing config.
Well, I don't rely on tools to deliver security out of the box without me knowing what is all about. Therefore, this tool is not meant to be secure by itself. I use other means to achieve that.
A dead giveaway that I think it's AI-made (not necessarily a con) is the complexity of the UI and redundant information. Things like the green dot paired with "interface is up". It looks polished though.
It's not hand coded. I've built it because I've needed for my own purposes.
I've tried wg-easy, but I didn't like the docker approach because it implied to dramatically alter my setup. I just wanted something to manage my already existing setup, something simple and effective. And the coding agent was good enough to built quickly what I needed.
I have found that WG client management is as simple as a couple scripts and a TSV file to match pubkeys to users.
Anyhow, cool project and I like the overall concept of respecting existing config.
reply