Skip to main content
Version: 0.5.6

WireGuard VPN on Aruba Cloud

Deploy a production-ready WireGuard VPN server on Aruba Cloud. All configuration is handled by cloud-init — no manual SSH required after deployment.

Provider version: arubacloud/arubacloud ~> 1.0 | Terraform: ≥ 1.9


Introduction​

WireGuard is a modern, high-performance VPN protocol built into the Linux kernel. It is simpler, faster, and more secure than OpenVPN or IPsec. This example deploys a WireGuard server that your devices can connect to for encrypted internet access or private network tunneling.

Common use cases:

  • Secure remote access to your Aruba Cloud VMs without exposing extra ports
  • Route all device traffic through a trusted Aruba Cloud IP
  • Split-tunnel access to private VPC resources

Architecture Overview​

A single CloudServer VM runs the wg-quick@wg0 systemd service. The WireGuard server keys are generated on first boot by cloud-init. Clients connect over UDP 51820. SSH is restricted to your admin IP; no HTTP/HTTPS ports are opened.


Infrastructure Created​

ResourceName patternDescription
arubacloud_projectwg-prodProject container
arubacloud_vpcwg-prod-vpcVirtual Private Cloud
arubacloud_subnetwg-prod-subnetBasic subnet
arubacloud_securitygroupwg-prod-vm-sgVM security group
arubacloud_securityrulewg-prod-vm-sshSSH ingress (admin CIDR)
arubacloud_securityrulewg-prod-wg-udpWireGuard UDP ingress
arubacloud_elasticipwg-prod-vm-eipVM public IP
arubacloud_blockstoragewg-prod-boot20 GB boot disk
arubacloud_keypairwg-prod-keypairSSH public key
arubacloud_cloudserverwg-prod-vmWireGuard VM

VM Sizing Recommendation​

Use casevCPURAMDiskFlavor
Personal VPN1–22–4 GB20 GBCSO2A4 (default)
Team VPN (10–50 users)24 GB20 GBCSO2A4
High-throughput48 GB20 GBCSO4A8

WireGuard is extremely CPU-efficient — a CSO2A4 VM comfortably handles 50+ concurrent clients.


Estimated Monthly Cost​

ResourceSpecEst. cost/mo
CloudServer VMCSO2A4 — 2 vCPU / 4 GB~€20
Boot disk20 GB Performance~€3
Elastic IP—~€5
Total~€28/mo

Requirements​

  • Terraform ≥ 1.9
  • ArubaCloud Terraform Provider ~> 1.0
  • ArubaCloud account with OAuth2 credentials
  • An SSH key pair

Variables​

Required​

VariableDescription
arubacloud_client_idArubaCloud OAuth2 client ID
arubacloud_client_secretArubaCloud OAuth2 client secret
ssh_public_keySSH public key content

Optional​

VariableDefaultDescription
app_name"wg"Short name for resource names
environment"prod"Environment label
location"ITBG-Bergamo"ArubaCloud region
zone"ITBG-1"Availability zone
vm_flavor"CSO2A4"CloudServer flavor
vm_disk_size_gb20Boot disk size in GB
ssh_cidr"0.0.0.0/0"CIDR for SSH — restrict to your IP
vpn_port51820WireGuard UDP port
vpn_server_address"10.8.0.1/24"Server VPN interface address
dns_servers["1.1.1.1","1.0.0.1"]DNS pushed to clients
billing_period"Hour""Hour" or "Month"

Deployment Instructions​

1. Clone and navigate​

git clone https://github.com/arubacloud/terraform-arubacloud-examples.git
cd terraform-arubacloud-examples/wireguard

2. Configure variables​

cp terraform.tfvars.example terraform.tfvars
# Edit terraform.tfvars

3. Deploy​

terraform init
terraform plan
terraform apply

4. Retrieve the server public key​

After deployment, get the server public key (needed to configure clients):

terraform output -raw get_server_pubkey_command | bash
# Example output: 8Zn3...abc=

5. Configure your client​

Generate a client key pair on your device:

wg genkey | tee client.key | wg pubkey > client.pub

Get the client config template from Terraform:

terraform output client_config_template

Replace <CLIENT_PRIVATE_KEY> with the content of client.key and <SERVER_PUBKEY> with the server public key.

6. Add a peer to the server​

SSH into the server and add your client's public key:

ssh ubuntu@$(terraform output -raw server_public_ip)
sudo wg set wg0 peer <CLIENT_PUBKEY> allowed-ips 10.8.0.2/32
sudo wg-quick save wg0

Destroy Instructions​

terraform destroy

Security Recommendations​

  1. Restrict SSH to your IP. Set ssh_cidr = "your.ip/32". The WireGuard UDP port should be open to all (clients connect from variable IPs).
  2. Rotate server keys if compromised. SSH in, run wg genkey | tee /etc/wireguard/server.key | wg pubkey > /etc/wireguard/server.pub, then restart the service. All clients will need to update their peer PublicKey.
  3. Use different VPN addresses per client. Assign unique IPs (10.8.0.2/32, 10.8.0.3/32, ...) so you can revoke individual clients by removing their peer entry.
  4. Keep the kernel updated. WireGuard is a kernel module — apt-get upgrade keeps it current.

Upgrade Considerations​

WireGuard itself is part of the Linux kernel — no binary upgrades are needed. To upgrade the OS:

ssh ubuntu@$(terraform output -raw server_public_ip)
sudo apt-get update && sudo apt-get upgrade -y
sudo reboot # reconnect after ~30 seconds

Screenshots​

Screenshot placeholder. Add a screenshot of sudo wg show output confirming active peers.


Troubleshooting​

Cannot connect from client​

  1. Check firewall: sudo wg show — if there are no peers, you forgot to add the peer with wg set wg0 peer ....
  2. Check the UDP port is open: from another machine, nc -u <SERVER_IP> 51820.
  3. Check IP forwarding: cat /proc/sys/net/ipv4/ip_forward should return 1.
  4. Check the service is running: sudo systemctl status wg-quick@wg0.

Keys were not generated (cloud-init failed)​

ssh ubuntu@<SERVER_IP>
sudo tail -100 /var/log/cloud-init-output.log

If /etc/wireguard/server.key is missing, re-run the setup manually:

sudo wg genkey | sudo tee /etc/wireguard/server.key | sudo wg pubkey | sudo tee /etc/wireguard/server.pub
sudo chmod 600 /etc/wireguard/server.key
sudo systemctl restart wg-quick@wg0

References​