wiredoor: Expose Private Services Through Secure Tunnels

wiredoor: Expose Private Services Through Secure Tunnels

Summary

Wiredoor is a self-hosted ingress platform that routes HTTP, TCP, and UDP traffic to services on private networks through WireGuard tunnels. It suits teams and individuals who want to manage their own public entry point and service access.

At a glance

Language
TypeScript
License
Apache-2.0
Stars
1.6k
Forks
78
Added to OSRepos
November 12, 2025
Last analyzed
October 3, 2026
View on GitHub

Topics

Click on any tag to explore related repositories

Use at your own risk

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.

Overview

Wiredoor provides a self-hosted way to make services on private networks reachable without opening inbound connections to those networks. Nodes initiate encrypted WireGuard tunnels to a Wiredoor Server, which handles incoming traffic and routes it to configured services.

It is a fit for operators who want control over ingress, routing, and operational data, rather than relying on a hosted tunneling provider. Client Nodes serve a computer’s local services, while Gateway Nodes can reach services across Docker, Kubernetes, or private networks.

Key Features

  • Exposes HTTP, TCP, and UDP services through a central server.
  • Uses node-initiated WireGuard tunnels to reach networks behind NAT or firewalls.
  • Routes HTTP traffic by domain and path, and supports public ports for other traffic.
  • Manages TLS certificates, including automatic Let’s Encrypt certificates for eligible public domains.
  • Provides OAuth2 authentication and IP-based access restrictions.
  • Supports Client Nodes and Gateway Nodes for Linux, Windows, macOS, Docker, and Kubernetes deployments, with platform-specific gateway caveats.
  • Offers a web dashboard, CLI management, and optional Prometheus and Grafana monitoring.

Use Cases

  • Home lab owners can publish selected applications without exposing their LAN directly to inbound connections.
  • Infrastructure operators can provide access to services in on-premises or restricted networks through a server they control.
  • Developers can share a local or Docker-based service for remote access or testing, while keeping the service on its private network.
  • Kubernetes administrators can route approved traffic from a Wiredoor Server to services inside a private cluster.
  • IoT and industrial operators can connect services in private networks where opening inbound VPN connections is undesirable.

Project Facts

  • Language: TypeScript
  • License: Apache-2.0
  • Stars: 1.6k
  • Forks: 78
  • Topics: api-server, ingress-service, management-system, nginx, reverse-proxy, self-hosted, tunneling, vpn, wireguard
  • Archived: No

Getting Started

The documented setup uses Docker Compose on a reachable Linux server. Start with the quickstart and the Docker setup repository:

git clone https://github.com/wiredoor/docker-setup.git
cd docker-setup
cp .env.example .env

Configure the environment, start the server with docker compose up -d, then install and register a node using the Wiredoor CLI. See the README for the full setup, node options, and service configuration.

Alternatives

  • NPMplus: NPMplus manages proxy hosts through a web interface, while Wiredoor routes services on private networks through WireGuard tunnels.
  • netgoat: NetGoat focuses on reverse-proxy controls such as authentication and caching, while Wiredoor provides WireGuard-based access to private services.
  • openresty-manager: OpenResty Manager centralizes proxy, certificate, and container management, while Wiredoor connects public ingress to private services over WireGuard.

Considerations

  • The server setup requires a reachable Linux host with Docker Engine, Docker Compose, and Git. The documented default also needs TCP ports 80 and 443 and UDP port 51820 open, unless the VPN port is changed.
  • Gateway routing depends on Linux iptables. Native CLI installations on Windows and macOS support Client Node mode; local Gateway Node deployments on those systems require Docker Desktop.
  • Public DNS is optional, but a public domain is useful for obtaining publicly trusted Let’s Encrypt certificates. Local or internal domains have different certificate considerations.
  • Self-hosting makes operators responsible for server and node updates, credential and key storage, backups, and restricting access to administrative services and gateway networks.
  • The project is licensed under Apache-2.0; versions before 1.5.1 used MIT, according to the README.

Source repository

Open the original repository on GitHub.

22 counted GitHub visits

View on GitHub

Related repositories

Similar repositories that may be relevant next.

OrcaReplay: Time Travel for AI Agents, Debugging and Evaluation

OrcaReplay: Time Travel for AI Agents, Debugging and Evaluation

October 2, 2026

OrcaReplay introduces "time travel" capabilities for AI agents, allowing developers to record, replay, fork, and debug any agent run with any model. It addresses the challenges of AI agent debugging by providing byte-for-byte reproducibility, offline analysis, and the ability to compare different models from specific checkpoints. This tool, built by the OrcaRouter.ai team, enhances observability and control over complex agent behaviors.

Agent DebuggingAI AgentsLLM Agents
OpenMake LLM: Self-Hosted AI Workspace for Local and Open-Weight LLMs

OpenMake LLM: Self-Hosted AI Workspace for Local and Open-Weight LLMs

October 1, 2026

OpenMake LLM is an open-source, self-hosted AI workspace for local and open-weight LLMs. It coordinates specialized models, autonomous agents, and tools for deep research and artifact generation. This platform supports vLLM, LiteLLM, and BYOK providers, offering a robust environment for managing AI workloads.

AI AgentsAI WorkspaceSelf Hosted AI
ZenNotes: Keyboard-First Markdown Notes with Vim, Diagrams, and MCP Integration

ZenNotes: Keyboard-First Markdown Notes with Vim, Diagrams, and MCP Integration

October 1, 2026

ZenNotes is a versatile, keyboard-first Markdown notes app designed for speed and flexibility. It stores notes as plain Markdown files, offering Vim-friendly editing, diagram support, and integration with MCP tools. Available as a desktop app (Electron) and a self-hosted web app, ZenNotes provides a powerful solution for organizing your thoughts.

ElectronLocal FirstMarkdown
lat.md: A Knowledge Graph for Your Codebase, Written in Markdown

lat.md: A Knowledge Graph for Your Codebase, Written in Markdown

September 26, 2026

lat.md is an innovative tool that transforms your codebase knowledge into an interconnected graph of markdown files. It helps both AI agents and human developers quickly understand project architecture, business logic, and design decisions. By integrating directly into your project, lat.md ensures documentation remains consistent and up-to-date.

TypeScriptDocumentationKnowledge Graph
OS
OSRepos

Analysis and discovery of open source repositories. Find interesting projects and follow their updates.

Monitor your website with YourWebsiteScore

OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of third-party repository code is at your own risk. Always review source code, dependencies, licenses, and security implications before running anything.

© 2025 OSRepos. Built with Nuxt 3 and lots of ❤️