spcfox/amnezia-wg-easy

The easiest way to run AmneziaWG VPN + Web-based Admin UI.

JavaScript

238

692 commits

updated Nov 24, 2025

See the code

README

AmnewziaWG Easy

You have found the easiest way to install & manage AmneziaWG on any Linux host!

Features

  • All-in-one: AmneziaWG + Web UI.
  • Easy installation, simple to use.
  • List, create, edit, delete, enable & disable clients.
  • Download a client's configuration file.
  • Statistics for which clients are connected.
  • Tx/Rx charts for each connected client.
  • Gravatar support.
  • Automatic Light / Dark Mode
  • Multilanguage Support
  • UI_TRAFFIC_STATS (default off)

Requirements

  • A host with Docker installed.

Versions

We provide more then 1 docker image to get, this will help you decide which one is best for you.

tagBranchExampleDescription
latestproductionghcr.io/wg-easy/wg-easy:latest or ghcr.io/wg-easy/wg-easystable as possbile get bug fixes quickly when needed, deployed against production.
13productionghcr.io/wg-easy/wg-easy:13same as latest, stick to a version tag.
nightlymasterghcr.io/wg-easy/wg-easy:nightlymostly unstable gets frequent package and code updates, deployed against master.
developmentpull requestsghcr.io/wg-easy/wg-easy:developmentused for development, testing code from PRs before landing into master.

Installation

1. Install Docker

If you haven't installed Docker yet, install it by running:

curl -sSL https://get.docker.com | sh
sudo usermod -aG docker $(whoami)
exit

And log in again.

2. Run AmneziaWG Easy

  docker run -d \
  --name=amnezia-wg-easy \
  -e LANGUAGE=en \
  -e WG_HOST=<🚨YOUR_SERVER_IP> \
  -e PASSWORD=<🚨YOUR_ADMIN_PASSWORD> \
  -e PORT=51821 \
  -e WG_PORT=51820 \
  -v ~/.amnezia-wg-easy:/etc/wireguard \
  -p 51820:51820/udp \
  -p 51821:51821/tcp \
  --cap-add=NET_ADMIN \
  --cap-add=SYS_MODULE \
  --sysctl="net.ipv4.conf.all.src_valid_mark=1" \
  --sysctl="net.ipv4.ip_forward=1" \
  --device=/dev/net/tun:/dev/net/tun \
  --restart unless-stopped \
  ghcr.io/spcfox/amnezia-wg-easy

💡 Replace YOUR_SERVER_IP with your WAN IP, or a Dynamic DNS hostname.

💡 Replace YOUR_ADMIN_PASSWORD with a password to log in on the Web UI.

The Web UI will now be available on http://0.0.0.0:51821.

💡 Your configuration files will be saved in ~/.amnezia-wg-easy

AmneziaWG Easy can be launched with Docker Compose as well - just download docker-compose.yml, make necessary adjustments and execute docker compose up --detach.

Options

These options can be configured by setting environment variables using -e KEY="VALUE" in the docker run command.

EnvDefaultExampleDescription
LANGUAGEendeWeb UI language (Supports: en, ru, tr, no, pl, fr, de, ca, es).
CHECK_UPDATEtruefalseCheck for a new version and display a notification about its availability
PORT518216789TCP port for Web UI.
WEBUI_HOST0.0.0.0localhostIP address web UI binds to.
PASSWORD-foobar123When set, requires a password when logging in to the Web UI.
WG_HOST-vpn.myserver.comThe public hostname of your VPN server.
WG_DEVICEeth0ens6f0Ethernet device the AmneziaWG traffic should be forwarded through.
WG_PORT5182012345The public UDP port of your VPN server. AmneziaWG will listen on that (othwise default) inside the Docker container.
WG_MTUnull1420The MTU the clients will use. Server uses default WG MTU.
WG_PERSISTENT_KEEPALIVE025Value in seconds to keep the "connection" open. If this value is 0, then connections won't be kept alive.
WG_DEFAULT_ADDRESS10.8.0.x10.6.0.xClients IP address range.
WG_DEFAULT_DNS1.1.1.18.8.8.8, 8.8.4.4DNS server clients will use. If set to blank value, clients will not use any DNS.
WG_ALLOWED_IPS0.0.0.0/0, ::/0192.168.15.0/24, 10.0.1.0/24Allowed IPs clients will use.
WG_PRE_UP...-See config.js for the default value.
WG_POST_UP...iptables ...See config.js for the default value.
WG_PRE_DOWN...-See config.js for the default value.
WG_POST_DOWN...iptables ...See config.js for the default value.
UI_TRAFFIC_STATSfalsetrueEnable detailed RX / TX client stats in Web UI
UI_CHART_TYPE01UI_CHART_TYPE=0 # Charts disabled, UI_CHART_TYPE=1 # Line chart, UI_CHART_TYPE=2 # Area chart, UI_CHART_TYPE=3 # Bar chart
JCrandom5Junk packet count — number of packets with random data that are sent before the start of the session.
JMIN5025Junk packet minimum size — minimum packet size for Junk packet. That is, all randomly generated packets will have a size no smaller than Jmin.
JMAX1000250Junk packet maximum size — maximum size for Junk packets.
S1random75Init packet junk size — the size of random data that will be added to the init packet, the size of which is initially fixed.
S2random75Response packet junk size — the size of random data that will be added to the response packet, the size of which is initially fixed.
H1random1234567891Init packet magic header — the header of the first byte of the handshake. Must be < uint_max.
H2random1234567892Response packet magic header — header of the first byte of the handshake response. Must be < uint_max.
H3random1234567893Underload packet magic header — UnderLoad packet header. Must be < uint_max.
H4random1234567894Transport packet magic header — header of the packet of the data packet. Must be < uint_max.

If you change WG_PORT, make sure to also change the exposed port.

Updating

To update to the latest version, simply run:

docker stop amnezia-wg-easy
docker rm amnezia-wg-easy
docker pull ghcr.io/spcfox/amnezia-wg-easy

And then run the docker run -d \ ... command above again.

With Docker Compose AmneziaWG Easy can be updated with a single command: docker compose up --detach --pull always (if an image tag is specified in the Compose file and it is not latest, make sure that it is changed to the desired one; by default it is omitted and defaults to latest).
The WireGuared Easy container will be automatically recreated if a newer image was pulled.

Thanks

Based on wg-easy by Emile Nijssen.

Contributors

(top 30 of 39)

pheiduck

384 commits

peterlewis

131 commits

spcfox

29 commits

suxscribe

24 commits

spcfox/amnezia-wg-easy

The easiest way to run AmneziaWG VPN + Web-based Admin UI.

JavaScript

238

692 commits

updated Nov 24, 2025

See the code

README

AmnewziaWG Easy

You have found the easiest way to install & manage AmneziaWG on any Linux host!

Features

  • All-in-one: AmneziaWG + Web UI.
  • Easy installation, simple to use.
  • List, create, edit, delete, enable & disable clients.
  • Download a client's configuration file.
  • Statistics for which clients are connected.
  • Tx/Rx charts for each connected client.
  • Gravatar support.
  • Automatic Light / Dark Mode
  • Multilanguage Support
  • UI_TRAFFIC_STATS (default off)

Requirements

  • A host with Docker installed.

Versions

We provide more then 1 docker image to get, this will help you decide which one is best for you.

tagBranchExampleDescription
latestproductionghcr.io/wg-easy/wg-easy:latest or ghcr.io/wg-easy/wg-easystable as possbile get bug fixes quickly when needed, deployed against production.
13productionghcr.io/wg-easy/wg-easy:13same as latest, stick to a version tag.
nightlymasterghcr.io/wg-easy/wg-easy:nightlymostly unstable gets frequent package and code updates, deployed against master.
developmentpull requestsghcr.io/wg-easy/wg-easy:developmentused for development, testing code from PRs before landing into master.

Installation

1. Install Docker

If you haven't installed Docker yet, install it by running:

curl -sSL https://get.docker.com | sh
sudo usermod -aG docker $(whoami)
exit

And log in again.

2. Run AmneziaWG Easy

  docker run -d \
  --name=amnezia-wg-easy \
  -e LANGUAGE=en \
  -e WG_HOST=<🚨YOUR_SERVER_IP> \
  -e PASSWORD=<🚨YOUR_ADMIN_PASSWORD> \
  -e PORT=51821 \
  -e WG_PORT=51820 \
  -v ~/.amnezia-wg-easy:/etc/wireguard \
  -p 51820:51820/udp \
  -p 51821:51821/tcp \
  --cap-add=NET_ADMIN \
  --cap-add=SYS_MODULE \
  --sysctl="net.ipv4.conf.all.src_valid_mark=1" \
  --sysctl="net.ipv4.ip_forward=1" \
  --device=/dev/net/tun:/dev/net/tun \
  --restart unless-stopped \
  ghcr.io/spcfox/amnezia-wg-easy

💡 Replace YOUR_SERVER_IP with your WAN IP, or a Dynamic DNS hostname.

💡 Replace YOUR_ADMIN_PASSWORD with a password to log in on the Web UI.

The Web UI will now be available on http://0.0.0.0:51821.

💡 Your configuration files will be saved in ~/.amnezia-wg-easy

AmneziaWG Easy can be launched with Docker Compose as well - just download docker-compose.yml, make necessary adjustments and execute docker compose up --detach.

Options

These options can be configured by setting environment variables using -e KEY="VALUE" in the docker run command.

EnvDefaultExampleDescription
LANGUAGEendeWeb UI language (Supports: en, ru, tr, no, pl, fr, de, ca, es).
CHECK_UPDATEtruefalseCheck for a new version and display a notification about its availability
PORT518216789TCP port for Web UI.
WEBUI_HOST0.0.0.0localhostIP address web UI binds to.
PASSWORD-foobar123When set, requires a password when logging in to the Web UI.
WG_HOST-vpn.myserver.comThe public hostname of your VPN server.
WG_DEVICEeth0ens6f0Ethernet device the AmneziaWG traffic should be forwarded through.
WG_PORT5182012345The public UDP port of your VPN server. AmneziaWG will listen on that (othwise default) inside the Docker container.
WG_MTUnull1420The MTU the clients will use. Server uses default WG MTU.
WG_PERSISTENT_KEEPALIVE025Value in seconds to keep the "connection" open. If this value is 0, then connections won't be kept alive.
WG_DEFAULT_ADDRESS10.8.0.x10.6.0.xClients IP address range.
WG_DEFAULT_DNS1.1.1.18.8.8.8, 8.8.4.4DNS server clients will use. If set to blank value, clients will not use any DNS.
WG_ALLOWED_IPS0.0.0.0/0, ::/0192.168.15.0/24, 10.0.1.0/24Allowed IPs clients will use.
WG_PRE_UP...-See config.js for the default value.
WG_POST_UP...iptables ...See config.js for the default value.
WG_PRE_DOWN...-See config.js for the default value.
WG_POST_DOWN...iptables ...See config.js for the default value.
UI_TRAFFIC_STATSfalsetrueEnable detailed RX / TX client stats in Web UI
UI_CHART_TYPE01UI_CHART_TYPE=0 # Charts disabled, UI_CHART_TYPE=1 # Line chart, UI_CHART_TYPE=2 # Area chart, UI_CHART_TYPE=3 # Bar chart
JCrandom5Junk packet count — number of packets with random data that are sent before the start of the session.
JMIN5025Junk packet minimum size — minimum packet size for Junk packet. That is, all randomly generated packets will have a size no smaller than Jmin.
JMAX1000250Junk packet maximum size — maximum size for Junk packets.
S1random75Init packet junk size — the size of random data that will be added to the init packet, the size of which is initially fixed.
S2random75Response packet junk size — the size of random data that will be added to the response packet, the size of which is initially fixed.
H1random1234567891Init packet magic header — the header of the first byte of the handshake. Must be < uint_max.
H2random1234567892Response packet magic header — header of the first byte of the handshake response. Must be < uint_max.
H3random1234567893Underload packet magic header — UnderLoad packet header. Must be < uint_max.
H4random1234567894Transport packet magic header — header of the packet of the data packet. Must be < uint_max.

If you change WG_PORT, make sure to also change the exposed port.

Updating

To update to the latest version, simply run:

docker stop amnezia-wg-easy
docker rm amnezia-wg-easy
docker pull ghcr.io/spcfox/amnezia-wg-easy

And then run the docker run -d \ ... command above again.

With Docker Compose AmneziaWG Easy can be updated with a single command: docker compose up --detach --pull always (if an image tag is specified in the Compose file and it is not latest, make sure that it is changed to the desired one; by default it is omitted and defaults to latest).
The WireGuared Easy container will be automatically recreated if a newer image was pulled.

Thanks

Based on wg-easy by Emile Nijssen.

Contributors

(top 30 of 39)

pheiduck

384 commits

peterlewis

131 commits

spcfox

29 commits

suxscribe

24 commits

Languages

JavaScript

46.3%

HTML

27.8%

CSS

24.7%

Dockerfile

1.1%