DigitalOcean WireGuard Tunnel with Terraform and Ansible
See WireGuard: Key Generation for details on how to create keys for the WireGuard server and peers.
Create a .tfvars
file defining the value of the Terraform variables.
See for a complete list of variables.
Example .tfvars
do_token = "dop_v1_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
ssh_key_fingerprint = "aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa:aa"
ssh_private_key_file = "/home/user/.ssh/id_rsa"
ssh_public_key_file = "/home/user/.ssh/"
domain = ""
# WireGuard
wg_port = "33099"
wg_ipv4_range = ""
wg_private_key = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx="
wg_allowed_peers = {
"xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=" = ""
terraform init
terraform apply -var-file my-vars.tfvars
terraform destroy -var-file my-vars.tfvars
Peer configurations vary depending on the platform. See DigitalOcean: How to Set Up WireGuard - Configuring a WireGuard Peer for Linux instructions.
This Terraform does not support adding additional nodes after initial setup.
To add additional nodes either do so manually or update the .tfvars
file and destroy then recreate the infrastructure.