finds.dev← search

// the find

devops-land/wireguard-operator

★ 711 · Go · MIT · updated Dec 2025

Project is now maintained by Namecheap on https://github.com/nccloud/wireguard-operator. This repo is archived.

A Kubernetes operator that manages WireGuard VPN servers and peers as CRDs, handling key generation, IP allocation, and config distribution without needing persistent storage. It's for people running their own VPN inside a k8s cluster who don't want to hand-roll Wireguard manifests and secret rotation. This repo is archived — development moved to nccloud/wireguard-operator under Namecheap.

Falls back to the userspace wireguard-go implementation when the kernel module isn't available, which matters a lot on managed k8s where you don't control the node image. Storing peer/server keys as k8s Secrets instead of requiring a PVC is the right call for an operator — stateless pods, no storage class dependency. Ships a metrics endpoint via prometheus_wireguard_exporter instead of leaving observability as an exercise for the user. The compatibility matrix in the README (GKE needs MTU override, DigitalOcean needs NodePort since their LB doesn't do UDP) reflects real testing against actual providers, not just a demo on minikube.

It's archived with zero commits since the fork — anyone adopting this specific repo is adopting a dead end; go to nccloud/wireguard-operator instead. No EKS or AKS support listed as tested, which rules out two of the three major managed k8s providers. Peer config retrieval via `kubectl get wireguardpeer ... | bash` is a rough interface — piping kubectl output straight into bash is the kind of pattern that makes security reviewers nervous, and it won't work from CI or anywhere without a shell. No mention of key rotation or revocation workflow once a peer is compromised, which is a real operational gap for a VPN tool.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →