-
GHOSTWIRE v0.3.2 Stable
released this
2026-10-04 21:14:51 +00:00 | 3 commits to main since this releaseA small fix for servers that get IPv6 automatically from their router.
Changes
- IPv6 keeps working with forwarding on: to route VPN traffic, GHOSTWIRE turns on IPv6 forwarding, and Linux then ignores the router's announcements. A server that gets its IPv6 address and route that way (SLAAC, e.g. a Raspberry Pi at home) lost its IPv6 connection after a reboot or when the route expired.
installandupdatenow setaccept_ra=2on the network cards and the IPv6 uplink, as pivpn does, so the server keeps listening to the router. Interfaces where router announcements are switched off (accept_ra=0) are left alone. - New health check, "IPv6 router announcements": it turns red while the uplink still ignores router announcements, and says to run
update.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.3.2-linux-amd64 sudo ./GHOSTWIRE-v0.3.2-linux-amd64 updateThe update rewrites
/etc/sysctl.d/99-ghostwire.confand applies it right away; no reboot is needed. Coming from v0.3.1 or earlier, nothing else changes. For a new installation, useinstallinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.3.2-linux-amd6464-bit x86 servers GHOSTWIRE-v0.3.2-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.3.2-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads
- IPv6 keeps working with forwarding on: to route VPN traffic, GHOSTWIRE turns on IPv6 forwarding, and Linux then ignores the router's announcements. A server that gets its IPv6 address and route that way (SLAAC, e.g. a Raspberry Pi at home) lost its IPv6 connection after a reboot or when the route expired.
-
GHOSTWIRE v0.3.1 Stable
released this
2026-10-04 19:35:22 +00:00 | 7 commits to main since this releaseA small update to v0.3.0.
Changes
- Passkeys only: two-step sign-in now offers an authenticator app and passkeys. Security keys are removed: a passkey does everything a security key did, works as the second step after a password, and also signs in on its own. It can live on the device (Touch ID, Face ID, Windows Hello), in a password manager, or on a YubiKey with a PIN set. Security keys added with v0.3.0 are deleted on update; add the key again as a passkey.
- Sign-in page: "Sign in with a passkey" turns into its Japanese reading on hover, like the Sign in button.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.3.1-linux-amd64 sudo ./GHOSTWIRE-v0.3.1-linux-amd64 updateComing from v0.3.0 or earlier, nothing else changes. For a new installation, use
installinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.3.1-linux-amd6464-bit x86 servers GHOSTWIRE-v0.3.1-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.3.1-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads
-
GHOSTWIRE v0.3.0 Stable
released this
2026-10-04 18:57:15 +00:00 | 10 commits to main since this releaseChanges
- Two-step sign-in: under My account, each user can add an authenticator app (6-digit codes), security keys such as a YubiKey, and passkeys that sign in on their own, without username and password. The first method brings 10 one-time recovery codes.
- Admins can require two-step sign-in for everyone (Settings → Sign-in) and reset it for a user who lost their phone or key (Edit user, or the iOS app).
- Security keys and passkeys use WebAuthn and need the server's domain name with a trusted certificate (Let's Encrypt, certificate files, or a reverse proxy). On a self-signed certificate or an IP address, only the authenticator app is offered.
- API tokens, like the iOS app's, never need a second step.
- Sortable peers table: click any column header on the Peers page to sort by it; click again to reverse.
- Shorter connection history: a peer's page shows the 8 newest sessions, with "Show all" for the rest.
- Fresh files after every update: the web interface loads its scripts and styles with a version fingerprint, so browsers pick up new versions without a hard reload.
- Sign-in page: the "WireGuard server manager" line is gone.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.3.0-linux-amd64 sudo ./GHOSTWIRE-v0.3.0-linux-amd64 updateComing from v0.2.x or v0.1.x, nothing else changes. Two-step sign-in stays off until a user sets it up. For a new installation, use
installinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.3.0-linux-amd6464-bit x86 servers GHOSTWIRE-v0.3.0-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.3.0-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads
- Two-step sign-in: under My account, each user can add an authenticator app (6-digit codes), security keys such as a YubiKey, and passkeys that sign in on their own, without username and password. The first method brings 10 one-time recovery codes.
-
GHOSTWIRE v0.2.0 Stable
released this
2026-10-04 17:40:13 +00:00 | 15 commits to main since this releaseChanges
- The iOS app can manage access: full-access API tokens can now manage users, change their owner's password, and create and revoke API tokens. Read-only tokens are refused there, even for listing. Backup and restore still need a web sign-in.
- Sign out from the account row: the sidebar's underlined "Sign out" link is now an icon at the right edge of your account row, with a tooltip.
- API:
GET /auth/mereturnstokenIdwhen called with a token, so an app can find its own token inGET /tokens.
The latest GHOSTWIRE Companion iOS app needs this version for its Users, My account and API tokens screens.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.2.0-linux-amd64 sudo ./GHOSTWIRE-v0.2.0-linux-amd64 updateComing from v0.1.x, nothing else changes. For a new installation, use
installinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.2.0-linux-amd6464-bit x86 servers GHOSTWIRE-v0.2.0-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.2.0-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads
-
GHOSTWIRE v0.1.1 Stable
released this
2026-10-04 13:44:17 +00:00 | 18 commits to main since this releaseA small update to v0.1.0.
Changes
- Sidebar stays in view: on long pages the sidebar now stays in place while the page scrolls, so your account link and Sign out are always visible. On a phone it still stacks above the page.
- Version in the sidebar: release builds showed the version with two v's ("vv0.1.0"). It now shows one.
- README: the Hannya logo at the top and screenshots of every page.
Update
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.1.1-linux-amd64 sudo ./GHOSTWIRE-v0.1.1-linux-amd64 updateComing from v0.1.0, nothing else changes: the config format is the same. For a new installation, use
installinstead ofupdate; see the README.Files
File For GHOSTWIRE-v0.1.1-linux-amd6464-bit x86 servers GHOSTWIRE-v0.1.1-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.1.1-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads
-
GHOSTWIRE v0.1.0 Stable
released this
2026-10-04 13:10:21 +00:00 | 21 commits to main since this releaseThe first release of GHOSTWIRE, a WireGuard server manager for Linux with a web interface and a JSON API. One static binary installs itself, keeps its whole state in
config.jsonand applies it with netlink, wgctrl and nftables.Install
Copy the binary for your server to it and run, as root:
chmod +x GHOSTWIRE-v0.1.0-linux-amd64 sudo ./GHOSTWIRE-v0.1.0-linux-amd64 installIt asks for the domain, endpoint and admin password, then sets up the service user,
/opt/ghostwire, the systemd unit and the firewall. Use-yand flags for an unattended install; see the README.To update an existing installation:
sudo ./GHOSTWIRE-v0.1.0-linux-amd64 update. If the installed build reports a higher version number than 0.1.0, add-force. The update convertsconfig.jsonto version 2 (users) and keeps a backup asconfig.json.bak-<old version>; if the new version does not start, the old binary and config are put back.Highlights
- Peers: add, edit, disable and delete peers live, without dropping other connections. Client configs are shown once as text and QR code; private keys are never stored. One-time setup links with an optional PIN are an alternative to the QR code.
- Traffic and connections: per-peer and total traffic charts (24 h, 7 and 30 days), connection history with country and network from the free DB-IP Lite databases, looked up on the server only.
- Latency check: optional per peer (off by default). The server pings the tunnel address every 30 s, either while the device is active or always, and shows the median, a sparkline and a 24-hour chart.
- Users: several users, all admins. New users can be required to choose their own password at first sign-in. Each user has a My account page with profile, password and their own app tokens.
GHOSTWIRE passwd [username]resets a password from the terminal. - API and iOS app: the web interface uses the same
/api/v1as scripts and the GHOSTWIRE-Companion iOS app. API tokens are stored only as hashes, can be read-only, and belong to the user who created them. - Server: Let's Encrypt, self-signed or your own certificate; IPv4 and optional IPv6 in the tunnel; NAT, peer-to-peer and LAN access switches; health checks; log and retention settings; backup and restore.
- Look: the Hannya mark and a Shippori Mincho B1 wordmark, bundled with the binary.
Files
File For GHOSTWIRE-v0.1.0-linux-amd6464-bit x86 servers GHOSTWIRE-v0.1.0-linux-arm6464-bit ARM, e.g. Raspberry Pi OS 64-bit GHOSTWIRE-v0.1.0-linux-armv7Raspberry Pi OS 32-bit SHA256SUMSchecksums: shasum -a 256 -c SHA256SUMSDownloads