• v0.3.2 a59a095691

    Redetzke released this 2026-10-04 21:14:51 +00:00 | 3 commits to main since this release

    A small fix for servers that get IPv6 automatically from their router.

    Changes

    • IPv6 keeps working with forwarding on: to route VPN traffic, GHOSTWIRE turns on IPv6 forwarding, and Linux then ignores the router's announcements. A server that gets its IPv6 address and route that way (SLAAC, e.g. a Raspberry Pi at home) lost its IPv6 connection after a reboot or when the route expired. install and update now set accept_ra=2 on the network cards and the IPv6 uplink, as pivpn does, so the server keeps listening to the router. Interfaces where router announcements are switched off (accept_ra=0) are left alone.
    • New health check, "IPv6 router announcements": it turns red while the uplink still ignores router announcements, and says to run update.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.3.2-linux-amd64
    sudo ./GHOSTWIRE-v0.3.2-linux-amd64 update
    

    The update rewrites /etc/sysctl.d/99-ghostwire.conf and applies it right away; no reboot is needed. Coming from v0.3.1 or earlier, nothing else changes. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.3.2-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.3.2-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.3.2-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads
  • v0.3.1 0a8dc8f7af

    Redetzke released this 2026-10-04 19:35:22 +00:00 | 7 commits to main since this release

    A small update to v0.3.0.

    Changes

    • Passkeys only: two-step sign-in now offers an authenticator app and passkeys. Security keys are removed: a passkey does everything a security key did, works as the second step after a password, and also signs in on its own. It can live on the device (Touch ID, Face ID, Windows Hello), in a password manager, or on a YubiKey with a PIN set. Security keys added with v0.3.0 are deleted on update; add the key again as a passkey.
    • Sign-in page: "Sign in with a passkey" turns into its Japanese reading on hover, like the Sign in button.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.3.1-linux-amd64
    sudo ./GHOSTWIRE-v0.3.1-linux-amd64 update
    

    Coming from v0.3.0 or earlier, nothing else changes. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.3.1-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.3.1-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.3.1-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads
  • v0.3.0 1fe9b4e619

    Redetzke released this 2026-10-04 18:57:15 +00:00 | 10 commits to main since this release

    Changes

    • Two-step sign-in: under My account, each user can add an authenticator app (6-digit codes), security keys such as a YubiKey, and passkeys that sign in on their own, without username and password. The first method brings 10 one-time recovery codes.
      • Admins can require two-step sign-in for everyone (Settings → Sign-in) and reset it for a user who lost their phone or key (Edit user, or the iOS app).
      • Security keys and passkeys use WebAuthn and need the server's domain name with a trusted certificate (Let's Encrypt, certificate files, or a reverse proxy). On a self-signed certificate or an IP address, only the authenticator app is offered.
      • API tokens, like the iOS app's, never need a second step.
    • Sortable peers table: click any column header on the Peers page to sort by it; click again to reverse.
    • Shorter connection history: a peer's page shows the 8 newest sessions, with "Show all" for the rest.
    • Fresh files after every update: the web interface loads its scripts and styles with a version fingerprint, so browsers pick up new versions without a hard reload.
    • Sign-in page: the "WireGuard server manager" line is gone.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.3.0-linux-amd64
    sudo ./GHOSTWIRE-v0.3.0-linux-amd64 update
    

    Coming from v0.2.x or v0.1.x, nothing else changes. Two-step sign-in stays off until a user sets it up. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.3.0-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.3.0-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.3.0-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads
  • v0.2.0 04a1d1ab85

    Redetzke released this 2026-10-04 17:40:13 +00:00 | 15 commits to main since this release

    Changes

    • The iOS app can manage access: full-access API tokens can now manage users, change their owner's password, and create and revoke API tokens. Read-only tokens are refused there, even for listing. Backup and restore still need a web sign-in.
    • Sign out from the account row: the sidebar's underlined "Sign out" link is now an icon at the right edge of your account row, with a tooltip.
    • API: GET /auth/me returns tokenId when called with a token, so an app can find its own token in GET /tokens.

    The latest GHOSTWIRE Companion iOS app needs this version for its Users, My account and API tokens screens.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.2.0-linux-amd64
    sudo ./GHOSTWIRE-v0.2.0-linux-amd64 update
    

    Coming from v0.1.x, nothing else changes. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.2.0-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.2.0-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.2.0-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads
  • v0.1.1 606b3fe89f

    Redetzke released this 2026-10-04 13:44:17 +00:00 | 18 commits to main since this release

    A small update to v0.1.0.

    Changes

    • Sidebar stays in view: on long pages the sidebar now stays in place while the page scrolls, so your account link and Sign out are always visible. On a phone it still stacks above the page.
    • Version in the sidebar: release builds showed the version with two v's ("vv0.1.0"). It now shows one.
    • README: the Hannya logo at the top and screenshots of every page.

    Update

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.1.1-linux-amd64
    sudo ./GHOSTWIRE-v0.1.1-linux-amd64 update
    

    Coming from v0.1.0, nothing else changes: the config format is the same. For a new installation, use install instead of update; see the README.

    Files

    File For
    GHOSTWIRE-v0.1.1-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.1.1-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.1.1-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads
  • v0.1.0 19008f8a33

    Redetzke released this 2026-10-04 13:10:21 +00:00 | 21 commits to main since this release

    The first release of GHOSTWIRE, a WireGuard server manager for Linux with a web interface and a JSON API. One static binary installs itself, keeps its whole state in config.json and applies it with netlink, wgctrl and nftables.

    Install

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.1.0-linux-amd64
    sudo ./GHOSTWIRE-v0.1.0-linux-amd64 install
    

    It asks for the domain, endpoint and admin password, then sets up the service user, /opt/ghostwire, the systemd unit and the firewall. Use -y and flags for an unattended install; see the README.

    To update an existing installation: sudo ./GHOSTWIRE-v0.1.0-linux-amd64 update. If the installed build reports a higher version number than 0.1.0, add -force. The update converts config.json to version 2 (users) and keeps a backup as config.json.bak-<old version>; if the new version does not start, the old binary and config are put back.

    Highlights

    • Peers: add, edit, disable and delete peers live, without dropping other connections. Client configs are shown once as text and QR code; private keys are never stored. One-time setup links with an optional PIN are an alternative to the QR code.
    • Traffic and connections: per-peer and total traffic charts (24 h, 7 and 30 days), connection history with country and network from the free DB-IP Lite databases, looked up on the server only.
    • Latency check: optional per peer (off by default). The server pings the tunnel address every 30 s, either while the device is active or always, and shows the median, a sparkline and a 24-hour chart.
    • Users: several users, all admins. New users can be required to choose their own password at first sign-in. Each user has a My account page with profile, password and their own app tokens. GHOSTWIRE passwd [username] resets a password from the terminal.
    • API and iOS app: the web interface uses the same /api/v1 as scripts and the GHOSTWIRE-Companion iOS app. API tokens are stored only as hashes, can be read-only, and belong to the user who created them.
    • Server: Let's Encrypt, self-signed or your own certificate; IPv4 and optional IPv6 in the tunnel; NAT, peer-to-peer and LAN access switches; health checks; log and retention settings; backup and restore.
    • Look: the Hannya mark and a Shippori Mincho B1 wordmark, bundled with the binary.

    Files

    File For
    GHOSTWIRE-v0.1.0-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.1.0-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.1.0-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads