• v0.1.0 19008f8a33

    Redetzke released this 2026-10-04 13:10:21 +00:00 | 21 commits to main since this release

    The first release of GHOSTWIRE, a WireGuard server manager for Linux with a web interface and a JSON API. One static binary installs itself, keeps its whole state in config.json and applies it with netlink, wgctrl and nftables.

    Install

    Copy the binary for your server to it and run, as root:

    chmod +x GHOSTWIRE-v0.1.0-linux-amd64
    sudo ./GHOSTWIRE-v0.1.0-linux-amd64 install
    

    It asks for the domain, endpoint and admin password, then sets up the service user, /opt/ghostwire, the systemd unit and the firewall. Use -y and flags for an unattended install; see the README.

    To update an existing installation: sudo ./GHOSTWIRE-v0.1.0-linux-amd64 update. If the installed build reports a higher version number than 0.1.0, add -force. The update converts config.json to version 2 (users) and keeps a backup as config.json.bak-<old version>; if the new version does not start, the old binary and config are put back.

    Highlights

    • Peers: add, edit, disable and delete peers live, without dropping other connections. Client configs are shown once as text and QR code; private keys are never stored. One-time setup links with an optional PIN are an alternative to the QR code.
    • Traffic and connections: per-peer and total traffic charts (24 h, 7 and 30 days), connection history with country and network from the free DB-IP Lite databases, looked up on the server only.
    • Latency check: optional per peer (off by default). The server pings the tunnel address every 30 s, either while the device is active or always, and shows the median, a sparkline and a 24-hour chart.
    • Users: several users, all admins. New users can be required to choose their own password at first sign-in. Each user has a My account page with profile, password and their own app tokens. GHOSTWIRE passwd [username] resets a password from the terminal.
    • API and iOS app: the web interface uses the same /api/v1 as scripts and the GHOSTWIRE-Companion iOS app. API tokens are stored only as hashes, can be read-only, and belong to the user who created them.
    • Server: Let's Encrypt, self-signed or your own certificate; IPv4 and optional IPv6 in the tunnel; NAT, peer-to-peer and LAN access switches; health checks; log and retention settings; backup and restore.
    • Look: the Hannya mark and a Shippori Mincho B1 wordmark, bundled with the binary.

    Files

    File For
    GHOSTWIRE-v0.1.0-linux-amd64 64-bit x86 servers
    GHOSTWIRE-v0.1.0-linux-arm64 64-bit ARM, e.g. Raspberry Pi OS 64-bit
    GHOSTWIRE-v0.1.0-linux-armv7 Raspberry Pi OS 32-bit
    SHA256SUMS checksums: shasum -a 256 -c SHA256SUMS
    Downloads