High Availability Wireguard VPN Infrastructure

A project to build a high availability WireGuard infrastructure in AWS

Started : 17-Aug-26

Notes

Requirements and beginnings
Created : 18 Aug 26 | Modified : 25 Aug 26 14:38

The initial requirements for the project, and some preliminary findings

Bookmarks

Secure VPN client registration
Created : 24 Aug 26 | Modified : 24 Aug 26 11:41

Ensure that clients connecting to the VPN are able to do so in a secure manner

Child notes

Fetch of AWS IoT Core Thing Principals
Created 08/24/2026 12:18 · Modified 08/25/2026 14:39
Routing From Maintenance Servers to Clients
Created : 28 Aug 26 | Modified : 28 Aug 26 08:29

How do we connect from the existing maintenance servers to VPN connected clients?

Bookmarks

Infrastructure
Created : 28 Aug 26

The infrastructure necessary to provide scalability and fault tolerance

Bookmarks

Attachments

Child notes

Minimal Policy for Global Accelerator creation
Created 08/28/2026 08:53 · Modified 08/31/2026 17:53

Provides the bare minimum permissions for an IAM user to be able to Create/Update an AWS Global Accelerator

Things To Do

Prototype AWS Infrastructure

Decide on AWS services needed for prototype & build out

Test Framework

Testing to assist with initial scale and prove the approach in DEV is required.

Document the architecture and decisions in ADR

Write up the Architecture Design Record

Publish registered clients to Wireguard instances

The peer IPs allocated to the clients during registration as well as the Wireguard public keys need to be published to each of the Wireguard hosts

Routing from maintenance servers to Wireguard hosts

Wireguard clients connecting will end up on one of x Wireguard hosts behind a load balancer. Maintenance server need to know how to route to the client connected to Wireguard Host X

Maintenance scripts need to be 'connection' agnostic

The various maintenance scripts all need to be able to either connect to clients via VPN or via the existing connection mechanism

Notify WireGuard hosts from vpn-register

To avoid having to have the WireGuard servers poll for changes to registered clients, have registration push notifications via SQS/SNS to trigger an agent on the WireGuard servers to refresh config

Secure VPN client registration

The client Wireguard client needs a way to securely register with the Wireguard server/s

Done

Back to Projects