{"id":13509873,"url":"https://github.com/utilitywarehouse/wiresteward","last_synced_at":"2026-04-02T19:03:06.660Z","repository":{"id":36346495,"uuid":"208277557","full_name":"utilitywarehouse/wiresteward","owner":"utilitywarehouse","description":"Wireguard peer manager","archived":false,"fork":false,"pushed_at":"2026-03-30T14:12:15.000Z","size":1720,"stargazers_count":82,"open_issues_count":4,"forks_count":6,"subscribers_count":10,"default_branch":"master","last_synced_at":"2026-03-30T16:22:45.158Z","etag":null,"topics":["oauth2","uw-owner-system","wireguard"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/utilitywarehouse.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2019-09-13T14:08:40.000Z","updated_at":"2026-03-30T14:11:59.000Z","dependencies_parsed_at":"2023-02-19T06:15:42.983Z","dependency_job_id":"91042e9e-af2a-497c-88c1-46fecc1db54d","html_url":"https://github.com/utilitywarehouse/wiresteward","commit_stats":null,"previous_names":[],"tags_count":43,"template":false,"template_full_name":null,"purl":"pkg:github/utilitywarehouse/wiresteward","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/utilitywarehouse%2Fwiresteward","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/utilitywarehouse%2Fwiresteward/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/utilitywarehouse%2Fwiresteward/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/utilitywarehouse%2Fwiresteward/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/utilitywarehouse","download_url":"https://codeload.github.com/utilitywarehouse/wiresteward/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/utilitywarehouse%2Fwiresteward/sbom","scorecard":{"id":913067,"data":{"date":"2025-08-11","repo":{"name":"github.com/utilitywarehouse/wiresteward","commit":"a3ae97bb72b48263e73a3d4ad20daca4868438cf"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5,"checks":[{"name":"Maintained","score":9,"reason":"11 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 9","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":3,"reason":"Found 2/6 approved changesets -- score normalized to 3","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Info: jobLevel 'actions' permission set to 'read': .github/workflows/codeql-analysis.yml:28","Info: jobLevel 'contents' permission set to 'read': .github/workflows/codeql-analysis.yml:29","Warn: topLevel 'contents' permission set to 'write': .github/workflows/build.yaml:14","Warn: no topLevel permission defined: .github/workflows/codeql-analysis.yml:1","Warn: topLevel 'contents' permission set to 'write': .github/workflows/dependabot-auto-merge.yaml:7","Warn: topLevel 'contents' permission set to 'write': .github/workflows/goreleaser.yaml:9","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: MIT License: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/build.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/codeql-analysis.yml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/codeql-analysis.yml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-approve.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/dependabot-auto-approve.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/dependabot-auto-merge.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/goreleaser.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/goreleaser.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/utilitywarehouse/wiresteward/goreleaser.yaml/master?enable=pin","Warn: containerImage not pinned by hash: Dockerfile:1","Warn: containerImage not pinned by hash: Dockerfile:11: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:b6a6be0ff92ab6db8acd94f5d1b7a6c2f0f5d10ce3c24af348d333ac6da80685","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of  10 third-party GitHubAction dependencies pinned","Info:   0 out of   2 containerImage dependencies pinned","Info:   1 out of   1 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.2.9 not signed: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/218787389","Warn: release artifact v0.2.8 not signed: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/199025113","Warn: release artifact v0.2.7 not signed: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/195053652","Warn: release artifact v0.2.7-RC3 not signed: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/194068177","Warn: release artifact v0.2.7-RC1 not signed: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/193827947","Warn: release artifact v0.2.9 does not have provenance: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/218787389","Warn: release artifact v0.2.8 does not have provenance: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/199025113","Warn: release artifact v0.2.7 does not have provenance: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/195053652","Warn: release artifact v0.2.7-RC3 does not have provenance: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/194068177","Warn: release artifact v0.2.7-RC1 does not have provenance: https://api.github.com/repos/utilitywarehouse/wiresteward/releases/193827947"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/build.yaml:21"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":10,"reason":"SAST tool is run on all commits","details":["Info: SAST configuration detected: CodeQL","Info: all commits (26) are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-24T19:57:34.912Z","repository_id":36346495,"created_at":"2025-08-24T19:57:34.912Z","updated_at":"2025-08-24T19:57:34.912Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":31313871,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-02T12:59:32.332Z","status":"ssl_error","status_checked_at":"2026-04-02T12:54:48.875Z","response_time":89,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["oauth2","uw-owner-system","wireguard"],"created_at":"2024-08-01T02:01:15.569Z","updated_at":"2026-04-02T19:03:06.651Z","avatar_url":"https://github.com/utilitywarehouse.png","language":"Go","funding_links":[],"categories":["Go","others","Projects"],"sub_categories":["User Interface"],"readme":"# Wiresteward\n\n\u003cimg src=\"./logo.png\" width=\"200\"/\u003e\n\n---\n\nWiresteward is a WireGuard peer manager with oauth2 authentication. It is\ncomprised of two components: server and agent.\n\nThe design is for Wiresteward server to run on a remote machine in a private\nnetwork, to which users will connect with WireGuard in order to access the\nprivate network.\n\nThe agent runs on the user's machine and is responsible for authenticating with\nthe server and retrieving WireGuard configuration.\n\nBoth components will configure their local WireGuard devices and route tables\nas needed to enable access to a private network.\n\n## Installation\n\n### Binary\n\nDownload the latest binary from:\nhttps://github.com/utilitywarehouse/wiresteward/releases\n\n### Homebrew\n\nIf you're on macOS or Linux and have [Homebrew](https://brew.sh/) installed,\ngetting Wiresteward is as simple as running:\n\n```\nbrew install utilitywarehouse/tap/wiresteward\n```\n\n## Agent\n\nThe Wiresteward agent is responsible for:\n\n- creating network tun devices\n- fetching oauth tokens to pass server authentication\n- registering WireGuard keys with the Wiresteward server and retrieving configuration\n- configuring WireGuard peers\n- configuring routes for the subnets allowed by the server\n\nIt is recommended that the agent is run as a Systemd (Linux) / launchd (macOS)\nservice.\n\nBut you can also run the executable directly:\n\n```console\n# wiresteward -agent -config=path-to-config.json\n```\n\nPlease note that because `wiresteward` will create and manage network devices\nand network routes, it requires `NET_ADMIN` capabilities. You can run it as\nroot with `sudo`.\n\nSee [`examples/server.json`](./examples/server.json) and\n[`examples/agent.json`](./examples/agent.json) for example configuration.\n\n\n### Configuration\n\nThe agent can take a config file as an argument or look for it under the\ndefault location:\n\n```\n/etc/wiresteward/config.json\n```\n\nThe config contains details about the oauth server and the local devices that\nwe need the agent to manage.\n\nAn example, where the config format can be found in\n[`examples/agent.json`](./examples/agent.json).\n\n#### MTU\n\nThe default MTU for the interfaces created via the agent is `1420` and it comes\nfrom the [default value of wireguard-go\npackage](https://git.zx2c4.com/wireguard-go/tree/device/tun.go#n14).\nOptionally, MTU can be set explicitly per wg device created by the agent via\nthe configuration file (using the \"MTU\" key under device config)\n\n### Running as Systemd service (Linux)\n\nThe agent is designed to run as a Systemd service. An example working service\nis described in\n[`examples/wiresteward.service`](./examples/wiresteward.service).\n\nA typical location for user defined systemd service is\n`/etc/systemd/system/wiresteward.service` so you'll need to copy the unit file\nto that location and then run:\n\n```console\n# systemctl daemon-reload\n# systemctl enable --now wiresteward.service\n```\n\nTo look at its logs:\n\n```console\n$ journalctl -u wiresteward.service\n```\n\n### Running as a launchd service (macOS)\n\nAn example working service for launchd is described in\n[`examples/uk.co.uw.wiresteward.plist`](./examples/uk.co.uw.wiresteward.plist).\n\nYou need to copy the file under `/Library/LaunchDaemons/` and then set the\nownership to root:\n\n```console\n# chown root:admin /Library/LaunchDaemons/uk.co.uw.wiresteward.plist\n```\n\nThen need to load the service:\n\n```console\n# sudo launchctl load /Library/LaunchDaemons/uk.co.uw.wiresteward.plist\n```\n\nThis will allow the service to run as root, which is required to operate on the\nnetwork devices and routing table.\n\nLogs are stored in `/var/log/wirestward.log` as defined in the service file. To\nview the logs you can:\n\n```console\n$ tail -f /var/log/wiresteward.log\n```\n\nYou might want to setup log rotation as well if you find that the log file\ngrows too large.\n\n### Authentication\n\nThe agent runs a local server on port 7773 and expects the user to visit\n`http://localhost:7773/` in order to authenticate. Once authenticated, the\nagent will be able to continue operating until the token retrieved is expired,\nat which point the user needs to authenticate again.\n\nVisiting `http://localhost:7773/` will cause the agent to immediately configure\nthe local WireGuard devices. If it already has a valid token, it will not prompt\nthe user to re-authenticate but it will re-configure the system.\n\n## Server\n\nThe Wiresteward server is responsible for:\n\n- creating new network WireGuard device\n- registering new peers and allocating ip addresses for them\n- configuring WireGuard peers\n- revoking access for expired address leases\n\nIt is recommended that the agent is run as a systemd service.\n\n### Configuration\n\nThe server can take a config file as an argument or look for it under the\ndefault location `/etc/wiresteward/config.json`. The config contains details\nabout the oauth server and the network subnets that need to be exposed, as well\nas the network subnet from which peer addresses are leased to agents.\n\nAn example, where the config format can be found in\n[`examples/server.json`](./examples/server.json).\n\n#### Private address validation\n\nThe server will refuse to start if `address` or any entry in `allowedIPs` is\nnot fully contained within a private address range (RFC 1918: `10.0.0.0/8`,\n`172.16.0.0/12`, `192.168.0.0/16`; or RFC 4193 IPv6 ULA: `fc00::/7`). This\nprevents accidentally configuring a public IP as the WireGuard interface\naddress, or advertising overly broad routes that could hijack public internet\ntraffic on connected agents.\n\nIf you intentionally need to use public CIDRs, start the server with the\n`-allow-public-routes` flag to bypass this check:\n\n```console\n# wiresteward -server -allow-public-routes -config=path-to-config.json\n```\n\n### Operating\n\nThere are Terraform modules defined under [`terraform/`](./terraform) which\ndescribe the recommended deployment method in AWS and GCP. See the more specific\n[README](./terraform/README.md) file for details.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Futilitywarehouse%2Fwiresteward","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Futilitywarehouse%2Fwiresteward","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Futilitywarehouse%2Fwiresteward/lists"}