WireGuard turns your Seed into a private VPN server. Laptops and phones connect through the official WireGuard apps for Windows, macOS, iOS and Android, and you add a device by scanning a QR code or importing a configuration file. On hotel or public Wi-Fi, your traffic then travels encrypted to the Seed and on to the internet from there. Services that only accept allowlisted IP addresses always see the address of your Seed. You can connect servers and other Seeds the same way and reach their internal services through the tunnel. The installation creates access for your first device right away.
After the first boot
The VPN server is ready 1 to 2 minutes after the Seed is created. /root/ready.txt then shows the server's address and port, and by that point the tunnel has already passed a connection test. If something goes wrong, the setup writes /root/failed.txt with the reason instead, and the full log is in /root/wireguard-install.log. Until one of the two files appears, setup is still running. You can reach both files via SSH or the Seed's VNC console.
The access files for your devices are in /root/wireguard-clients/, one configuration per device (client1.conf, client2.conf and so on, as many as set in WG_CLIENTS), each with a QR code as a PNG. Every file contains a private key and belongs on exactly one device.
- On a phone, open the WireGuard app and scan the QR code that
qrencode -t ansiutf8 < /root/wireguard-clients/client1.confprints in the terminal. - On a laptop, copy the file with
scpand import it into the WireGuard app. - On a Linux server, install the tools with
apt install wireguard-tools, save the file as/etc/wireguard/wg0.confand remove theDNSline so the server keeps its own resolvers. SetAllowedIPsto10.0.0.0/24plus the IPv6 prefix from theAddressline with/64, for example10.0.0.0/24, fd12:3456:789a::/64, so SSH keeps using the server's public address. Then start the tunnel withsystemctl enable --now wg-quick@wg0.
With the unchanged configuration, laptops and phones send all their traffic through the tunnel.
Devices connect to the Seed's public IPv4 address. If you use a firewall under Network > Firewalls, it has to allow UDP port 51820 or the port from WG_PORT. The tunnel runs as the wg-quick@wg0 service, with its configuration in /etc/wireguard/wg0.conf. Its rules forward only traffic that comes from the tunnel and drop new connections from outside to your devices. wg show wg0 allowed-ips lists the tunnel addresses in use, and our guide Set up a WireGuard VPN server shows how to add more devices with the next free address.
Suitable models
Entry
The entry point for low CPU load
Standard
All-rounder for variable production load
Performance
Exclusive compute for sustained load
Show all 15 suitable models
Entry
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| S | 1 Core | 2 GB | 20 GB | 10 TB | 1 Gbit/s | 0,005848 € | 3,65 € | |
| M | 2 Cores | 4 GB | 40 GB | 10 TB | 1 Gbit/s | 0,011694 € | 7,29 € | |
| L | 4 Cores | 8 GB | 80 GB | 10 TB | 1 Gbit/s | 0,023389 € | 14,59 € | |
| XL | 8 Cores | 16 GB | 160 GB | 10 TB | 1 Gbit/s | 0,038312 € | 23,91 € |
Standard
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| XS | 1 Core | 4 GB | 40 GB | 20 TB | 2.5 Gbit/s | 0,014303 € | 8,93 € | |
| S | 2 Cores | 8 GB | 80 GB | 20 TB | 2.5 Gbit/s | 0,024579 € | 15,34 € | |
| M | 4 Cores | 16 GB | 160 GB | 20 TB | 2.5 Gbit/s | 0,049158 € | 30,68 € | |
| L | 8 Cores | 24 GB | 240 GB | 20 TB | 2.5 Gbit/s | 0,093740 € | 58,49 € | |
| XL | 10 Cores | 32 GB | 360 GB | 20 TB | 2.5 Gbit/s | 0,120608 € | 75,26 € | |
| XXL | 16 Cores | 64 GB | 500 GB | 20 TB | 2.5 Gbit/s | 0,188623 € | 117,70 € |
Performance
| Model | CPU | RAM | Storage | Traffic | Bandwidth | Price/hour | Price/month | |
|---|---|---|---|---|---|---|---|---|
| S | 2 Cores | 16 GB | 80 GB | 20 TB | 10 Gbit/s | 0,070561 € | 44,03 € | |
| M | 4 Cores | 32 GB | 160 GB | 20 TB | 10 Gbit/s | 0,141122 € | 88,06 € | |
| L | 8 Cores | 64 GB | 240 GB | 20 TB | 10 Gbit/s | 0,277666 € | 173,26 € | |
| XL | 16 Cores | 128 GB | 360 GB | 20 TB | 10 Gbit/s | 0,548467 € | 342,24 € | |
| XXL | 32 Cores | 192 GB | 500 GB | 20 TB | 10 Gbit/s | 1,011118 € | 630,94 € |
Create it via the Public API
A single call creates this Seed. Replace the placeholders starting with $ with your own values, such as your API token and the IDs from your account. Go to the Public API
curl -X POST "https://api.dataforest.net/api/v1/public/seeds" \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"plan": "lines/entry/models/entry-c1-m2-s20",
"location": "fra01",
"source": {
"type": "app",
"ref": "apps/wireguard/versions/wireguard-v1.0.20210914",
"environment_variables": {
"WG_DNS": "$WG_DNS"
}
},
"project_id": "$PROJECT_ID",
"name": "wireguard"
}'