High Availability Wireguard VPN Infrastructure
A project to build a high availability WireGuard infrastructure in AWS
Started : 17-Aug-26
Notes
The initial requirements for the project, and some preliminary findings
Bookmarks
-
Set up WireGuard in a high availability configuration on AWS
Ensure that clients connecting to the VPN are able to do so in a secure manner
Child notes
How do we connect from the existing maintenance servers to VPN connected clients?
Bookmarks
-
How to build IP-over-IP GRE tunnels on Linux with iproute2, the MTU math, keepalive options, and where GRE still fits in a world of WireGuard and VXLAN.
The infrastructure necessary to provide scalability and fault tolerance
Bookmarks
-
Set up WireGuard in a high availability configuration on AWS
Attachments
-
This article will demonstrate how to set up WireGuard in a high availability configuration on AWS (Amazon Web Services).
Child notes
Provides the bare minimum permissions for an IAM user to be able to Create/Update an AWS Global Accelerator
Things To Do
Prototype AWS Infrastructure
Decide on AWS services needed for prototype & build out
Test Framework
Testing to assist with initial scale and prove the approach in DEV is required.
Document the architecture and decisions in ADR
Write up the Architecture Design Record
Publish registered clients to Wireguard instances
The peer IPs allocated to the clients during registration as well as the Wireguard public keys need to be published to each of the Wireguard hosts
Routing from maintenance servers to Wireguard hosts
Wireguard clients connecting will end up on one of x Wireguard hosts behind a load balancer. Maintenance server need to know how to route to the client connected to Wireguard Host X
Maintenance scripts need to be 'connection' agnostic
The various maintenance scripts all need to be able to either connect to clients via VPN or via the existing connection mechanism
Notify WireGuard hosts from vpn-register
To avoid having to have the WireGuard servers poll for changes to registered clients, have registration push notifications via SQS/SNS to trigger an agent on the WireGuard servers to refresh config
Secure VPN client registration
The client Wireguard client needs a way to securely register with the Wireguard server/s