Your own WireGuard network, on your own machines.

aetr is a self-hosted mesh. One image, one install path: every machine you start is a node, and the one you promote is the hub. Sign in here to link your nodes to your account — after that they find each other on their own.

What aetr is

A WireGuard data plane with a web panel on top of it, running on hardware you own.

One image, every install is a node

There is no separate hub package to choose between. The same image gives you a node with its own settings page; turn on the hub role on one of them and that node gains the pages that run the network.

Nodes find each other directly

Peers punch through NAT and carry traffic between themselves when the network lets them. When it doesn’t, they fall back through the hub — and the panel says which path you are actually on instead of claiming a direct one.

Groups keep devices apart

Put devices in groups and decide which groups may reach which. A laptop that needs one service does not get the whole network along with it.

A censorship-resistant entrance

Where plain WireGuard is blocked, a node can dial in through an entrance that wraps it in Xray with REALITY. It is optional, and native WireGuard stays the default.

How it works

Three steps, and none of them ask you to read the WireGuard manual.

  1. Run the image

    Start the image with Docker Compose on the machine that should carry the network, open its settings page, and turn on the hub role.

  2. Sign in from the node

    On each node’s settings page choose Sign in with aetr. Approve the request here, and that node is on your account.

  3. Nodes join

    The hub hands every linked node its mesh address and keys. Devices come online, and each panel shows the same network.

Sign in to link your nodes

Your account is the network. Nodes you approve here join it, and you can open any of their panels from one page.

Sign in