// the find
MindFlavor/prometheus_wireguard_exporter
A Prometheus exporter for WireGuard, written in Rust.
A small Rust daemon that shells out to `wg show <iface> dump`, parses the output, and serves it as Prometheus metrics. For anyone running WireGuard and already on Prometheus/Grafana, it's the straightforward way to get handshake times and byte counters without writing a parser yourself.
It's a thin wrapper, not a reimplementation of WireGuard's wire protocol, so it inherits correctness from `wg` itself rather than reinventing it. The friendly_name/friendly_json comment-tag trick is a genuinely useful idea — it lets you attach human labels to peers without touching the actual WireGuard config syntax that `wg-quick` has to parse. Multi-arch Docker builds (amd64/386/arm64/armv7/armv6) cover real router and Pi hardware, not just x86 servers.
It has to run as root (or via a passwordless sudo rule) because `wg show` requires elevated privileges — that's a real deployment wrinkle for anyone trying to keep an exporter unprivileged, and the systemd hardening notes in the README are basically an admission that most of the usual sandboxing options break here. Last push was October 2023, so it's over two years stale with no response to issues like #59 (pre-built binaries still 'coming soon' since whenever that was filed). The CLI/env-var interface has broken backward compatibility at least three times (3.3.0, 3.4.0, 3.6.0), so upgrading across versions isn't a drop-in replace. It shells out to a subprocess and parses text output rather than linking against a WireGuard library, which is simple but fragile if `wg`'s output format ever shifts.