How to set up your own WireGuard server
Your own VPN — route your devices' traffic through this server. Cresdock runs it on a server you own, from a catalogue, with no Docker and no reverse proxy to configure.
This is Cresdock's suggested starting point in its category — the one to pick if you have no reason to prefer another.
What Cresdock does for you with WireGuard
Installed, started and kept running for you — no Dockerfile, no compose file, no reverse-proxy configuration to write.
Reached through your panel login. There is no second password to invent for WireGuard and no port to open on your firewall.
WireGuard lets your own devices reach this machine privately, in a leaner, faster way, and meets nothing else here.
It and OpenVPN cover the same ground, so most people keep the one their devices get on with best.
Why run WireGuard yourself
A VPN you run yourself has one user — you. There is no shared exit address, no logging policy to take on trust, and no subscription.
What kind of server WireGuard needs
Almost nothing while idle. The limit is your server's own connection speed, since everything you send through the tunnel goes out through it.
Cresdock itself is undemanding — it runs on a small rented server, an old desktop or a mini PC, on Ubuntu or Debian. Everything it installs shares that machine, so the honest question is not "will this app run" but "how much am I going to put on here in total".
Where to run WireGuard
WireGuard runs wherever Cresdock runs, and the choice is about the machine, not the app:
- At home, on hardware you already own. A mini PC, an old desktop or a NAS that can run Debian. Cresdock works behind a home router with no port forwarding and no domain, so WireGuard is reachable on your own network first and from outside only if you choose.
- On a rented server. A small VPS is enough for most apps and is the usual answer when WireGuard should be reachable from anywhere. The setup guide covers the specs and the one-command install.
- Through a provider that runs Cresdock. Hosting companies deploy Cresdock workspaces for their customers, so WireGuard can come with a server you rent rather than one you set up — ask your provider, or see how providers offer it.
Installing WireGuard
- Put Cresdock on a server
One line on any Ubuntu or Debian machine — a rented VPS, a spare PC, a home server. It sets itself up.
- Pick WireGuard from the catalogue
Click Install. The panel pulls the image, writes the configuration, gets a certificate and starts it.
- Open it from your dashboard
Its address and any login details are on its card. Start, stop, update, roll back or remove it from the same place, any time.
What's left for you to do
Cresdock does not pretend to do the parts that are genuinely yours to decide. After it's running:
Download a connection file (or scan the QR) into the WireGuard app on your device
What this replaces
Doing it by hand means writing something like this, then keeping it working:
services:
wireguard:
image: lscr.io/linuxserver/wireguard:1.0.20260223-r0-ls118
restart: unless-stopped
ports:
- "51820:51820"
environment:
- PUID=1000
- PGID=1000
- TZ=Etc/UTC
volumes:
- ./wireguard/config:/config
And that is the easy half. Still to do:
Install a reverse proxy and write a server block for it
Get a TLS certificate and set up automatic renewal
Create the folders above with the right ownership, or it will not start
Repeat all of it for the next app, and again on every server rebuild
On Cresdock, WireGuard is one click and none of the above exists.
Common questions
Do I need to know Docker to run WireGuard?
No. Cresdock installs WireGuard in one click from its catalogue: it pulls the image, writes the configuration, gets an HTTPS certificate and starts it. WireGuard runs on the tenant's own private network, reachable through the panel login and nothing else.
What happens to my WireGuard data when it updates?
Cresdock updates the WireGuard image and leaves its stored data in place. WireGuard keeps its own files in its own folder, which survives an update, a rebuild and a reinstall — and Cresdock never writes into it.
Can I run WireGuard at home instead of on a VPS?
Yes. Cresdock runs on a mini PC, an old desktop or anything that boots Debian, behind a normal home router with no port forwarding, and WireGuard is reachable on your own network first. A rented server is only needed when WireGuard must be reachable from anywhere without a VPN.
Can I remove WireGuard later?
Yes. Cresdock removes WireGuard in one click, and asks whether to keep its configuration for a future reinstall. Nothing else you have installed is affected.
Looking for what WireGuard itself can do? That lives in its own documentation — this page is only about running it.
Pairs well with: OpenVPN · qBittorrent · Actual Budget · how WireGuard connects to your other apps
Before you start: where to rent a server · what it needs to run · Cresdock vs Cloudron