services:
easy_wg_mikrotik:
image: rubyon/easy_wg_mikrotik
container_name: easy_wg_mikrotik
restart: unless-stopped
ports:
- "3000:3000"
environment:
RAILS_ENV: development
MIKROTIK_HOST: 192.168.88.1
MIKROTIK_PORT: 8728
DEFAULT_LOCALE: ko- ๐ง Environment Variables: Migrated from hardcoded values to
.envconfiguration for better deployment flexibility- ํ๊ฒฝ ๋ณ์: ํ๋์ฝ๋ฉ๋ ๊ฐ์์
.env์ค์ ์ผ๋ก ๋ง์ด๊ทธ๋ ์ด์ ํ์ฌ ๋ฐฐํฌ ์ ์ฐ์ฑ ํฅ์
- ํ๊ฒฝ ๋ณ์: ํ๋์ฝ๋ฉ๋ ๊ฐ์์
- ๐ Locale Management: Added
DEFAULT_LOCALEenvironment variable to control application language settings- ๋ก์ผ์ผ ๊ด๋ฆฌ: ์ ํ๋ฆฌ์ผ์ด์
์ธ์ด ์ค์ ์ ์ ์ดํ๋
DEFAULT_LOCALEํ๊ฒฝ ๋ณ์ ์ถ๊ฐ
- ๋ก์ผ์ผ ๊ด๋ฆฌ: ์ ํ๋ฆฌ์ผ์ด์
์ธ์ด ์ค์ ์ ์ ์ดํ๋
- ๐ก MikroTik Configuration: Replaced
SERVER_ADDRESSwithMIKROTIK_HOSTandMIKROTIK_PORTfor clearer router connection settings- MikroTik ์ค์ : ๋ช
ํํ ๋ผ์ฐํฐ ์ฐ๊ฒฐ ์ค์ ์ ์ํด
SERVER_ADDRESS๋ฅผMIKROTIK_HOST์MIKROTIK_PORT๋ก ๋์ฒด
- MikroTik ์ค์ : ๋ช
ํํ ๋ผ์ฐํฐ ์ฐ๊ฒฐ ์ค์ ์ ์ํด
- ๐ณ Docker Integration: Updated Docker Compose configuration to use environment variables
- Docker ํตํฉ: Docker Compose ์ค์ ์์ ํ๊ฒฝ ๋ณ์ ์ฌ์ฉํ๋๋ก ์ ๋ฐ์ดํธ
- ๐ Example Configuration: Added
.env.examplefile for easy setup reference- ์์ ์ค์ : ์ฌ์ด ์ค์ ์ฐธ์กฐ๋ฅผ ์ํ
.env.exampleํ์ผ ์ถ๊ฐ
- ์์ ์ค์ : ์ฌ์ด ์ค์ ์ฐธ์กฐ๋ฅผ ์ํ
- ๐ Security: Improved
.gitignoreto protect sensitive environment files while keeping examples- ๋ณด์: ์์ ํ์ผ์ ์ ์งํ๋ฉด์ ๋ฏผ๊ฐํ ํ๊ฒฝ ํ์ผ์ ๋ณดํธํ๋๋ก
.gitignore๊ฐ์
- ๋ณด์: ์์ ํ์ผ์ ์ ์งํ๋ฉด์ ๋ฏผ๊ฐํ ํ๊ฒฝ ํ์ผ์ ๋ณดํธํ๋๋ก
.env- Environment variables for local development | ๋ก์ปฌ ๊ฐ๋ฐ์ฉ ํ๊ฒฝ ๋ณ์.env.example- Template file with example configuration values | ์์ ์ค์ ๊ฐ์ด ํฌํจ๋ ํ ํ๋ฆฟ ํ์ผ
If upgrading from a previous version, please: | ์ด์ ๋ฒ์ ์์ ์ ๊ทธ๋ ์ด๋ํ๋ ๊ฒฝ์ฐ:
- Create a
.envfile based on.env.example|.env.example์ ๊ธฐ๋ฐ์ผ๋ก.envํ์ผ ์์ฑ - Set your MikroTik router IP in
MIKROTIK_HOST|MIKROTIK_HOST์ MikroTik ๋ผ์ฐํฐ IP ์ค์ - Configure your preferred locale in
DEFAULT_LOCALE|DEFAULT_LOCALE์ ์ ํธํ๋ ์ธ์ด ์ค์
A simple and intuitive web interface for managing WireGuard VPN clients on MikroTik routers.
- ๐ MikroTik RouterOS API Integration: Direct connection to your MikroTik router with secure session management
- ๐ Dynamic Interface Selection: Automatically detect and select WireGuard interfaces with real-time updates
- ๐ฅ Client Management: Create, view, and delete WireGuard clients with live status monitoring
- ๐ฑ QR Code Generation: Instant QR codes for mobile device configuration with Bootstrap Icons
- ๐พ Configuration Downloads: Download .conf files for desktop clients via Stimulus controllers
- โก Real-time Updates: Turbo Stream-powered interface for seamless user experience
- ๐จ Modern UI: Clean, responsive design with Tailwind CSS 4.1.11 and backdrop blur effects
- ๐ Multi-language Support: Korean (default), English, Chinese, and Japanese localization
- ๐ Enhanced Security: XSS protection with input validation and safe QR code generation
- Ruby: 3.0+ (Tested with Ruby 3.4.2)
- Rails: 8.0.2+ with Hotwire (Turbo + Stimulus)
- MikroTik Router: RouterOS v7.0+ with WireGuard support
- Dependencies: Node.js, Yarn for asset compilation
- Browser: Modern browser with JavaScript enabled
- Clone the repository:
git clone https://github.com/rubyon/easy_wg_mikrotik.git
cd easy_wg_mikrotik- Run with Docker Compose:
docker compose up --build- Open your browser and navigate to
http://localhost:3000
- Clone the repository:
git clone https://github.com/rubyon/easy_wg_mikrotik.git
cd easy_wg_mikrotik- Install dependencies:
bundle install
yarn install- Start the development server:
bin/dev- Open your browser and navigate to
http://localhost:3000
- Login to MikroTik: Enter your MikroTik router's IP address, username, and password
- Ensure WireGuard Interface: Make sure you have at least one WireGuard interface configured on your MikroTik router
- Click "Create New Client" button
- Select your WireGuard interface from the dropdown
- Configure the following settings:
- Endpoint: Your server's public IP and port (e.g.,
your-server.com:51820) - Allowed IPs: Networks the client can access (e.g.,
10.1.1.0/24,192.168.1.0/24) - Client IP Range: Subnet prefix for client IPs (e.g.,
10.1.1) - Keep Alive: Persistent keepalive interval in seconds (e.g.,
25)
- Endpoint: Your server's public IP and port (e.g.,
- Click "Create Client" button
- Download the configuration file or scan the QR code with your mobile device
- View Clients: Click "Client List" to see all configured clients
- Filter by Interface: Select an interface to view only its clients
- Delete Clients: Click the delete button next to any client to remove it
- Refresh: Click the refresh button to update the client list
The application uses session-based authentication to store your MikroTik credentials securely. No credentials are stored permanently on the server.
- Framework: Ruby on Rails 8.0.2
- Authentication: Session-based with optional cookie persistence (no database)
- API: RouterOS API gem for MikroTik integration
- Security: Brakeman scanning, XSS protection, input validation
- JavaScript: Hotwire (Turbo + Stimulus) for reactive UI
- CSS: Tailwind CSS 4.1.11 with modern features
- Icons: Bootstrap Icons 1.11.3
- Build Tools: esbuild for JavaScript, Tailwind CLI for CSS
- Real-time: Turbo Streams for live updates
- Cryptography: RbNaCl for secure WireGuard key generation
- QR Codes: RQRCode for mobile configuration
- Localization: Rails I18n with 4 language support
- Code Quality: RuboCop Rails Omakase, ERB Lint
- ๐ XSS Protection: Input validation and safe output rendering
- ๐ก๏ธ Session Security: Secure session management without persistent credential storage
- ๐ Security Scanning: Integrated Brakeman security analysis
- โ Input Validation: Comprehensive validation for all WireGuard configuration parameters
- ๐ Safe QR Generation: Secure QR code generation with validation
- Use strong passwords for your MikroTik router
- Run behind HTTPS in production environments
- Regularly update MikroTik RouterOS firmware
- Monitor and remove unused VPN clients
- Review application logs for suspicious activity
# Run security scan
bundle exec brakeman
# Check code style
bundle exec rubocop
erb_lint --lint-all
# Auto-fix style issues
bundle exec rubocop -A
erb_lint --lint-all --autocorrect
# Run tests
bin/rails test
bin/rails test:systemapp/controllers/clients_controller.rb- Main WireGuard client managementapp/helpers/qr_code_helper.rb- Secure QR code generationapp/javascript/controllers/- Stimulus controllers for dynamic UIapp/views/clients/- WireGuard client management viewsconfig/locales/- Multi-language support files
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Make your changes with proper tests
- Run code quality checks (
rubocop -A && erb_lint --lint-all --autocorrect) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
This project is open source and available under the MIT License.
This README.md was generated with Claude Code
MikroTik ๋ผ์ฐํฐ์์ WireGuard VPN ํด๋ผ์ด์ธํธ๋ฅผ ๊ด๋ฆฌํ ์ ์๋ ๊ฐ๋จํ๊ณ ์ง๊ด์ ์ธ ์น ์ธํฐํ์ด์ค์ ๋๋ค.
- ๐ MikroTik RouterOS API ์ฐ๋: ์์ ํ ์ธ์ ๊ด๋ฆฌ๋ก MikroTik ๋ผ์ฐํฐ์ ์ง์ ์ฐ๊ฒฐ
- ๐ ๋์ ์ธํฐํ์ด์ค ์ ํ: ์ค์๊ฐ ์ ๋ฐ์ดํธ๋ก WireGuard ์ธํฐํ์ด์ค ์๋ ๊ฐ์ง ๋ฐ ์ ํ
- ๐ฅ ํด๋ผ์ด์ธํธ ๊ด๋ฆฌ: ์ค์๊ฐ ์ํ ๋ชจ๋ํฐ๋ง์ผ๋ก WireGuard ํด๋ผ์ด์ธํธ ์์ฑ, ์กฐํ, ์ญ์
- ๐ฑ QR ์ฝ๋ ์์ฑ: Bootstrap Icons์ ํจ๊ป ๋ชจ๋ฐ์ผ ๋๋ฐ์ด์ค ์ค์ ์ ์ํ ์ฆ์ QR ์ฝ๋ ์์ฑ
- ๐พ ์ค์ ํ์ผ ๋ค์ด๋ก๋: Stimulus ์ปจํธ๋กค๋ฌ๋ฅผ ํตํ ๋ฐ์คํฌํฑ ํด๋ผ์ด์ธํธ์ฉ .conf ํ์ผ ๋ค์ด๋ก๋
- โก ์ค์๊ฐ ์ ๋ฐ์ดํธ: Turbo Stream ๊ธฐ๋ฐ ์ธํฐํ์ด์ค๋ก ์ํํ ์ฌ์ฉ์ ๊ฒฝํ
- ๐จ ๋ชจ๋ UI: Tailwind CSS 4.1.11๊ณผ ๋ฐฑ๋๋กญ ๋ธ๋ฌ ํจ๊ณผ๋ฅผ ์ฌ์ฉํ ๊น๋ํ๊ณ ๋ฐ์ํ ๋์์ธ
- ๐ ๋ค๊ตญ์ด ์ง์: ํ๊ตญ์ด(๊ธฐ๋ณธ), ์์ด, ์ค๊ตญ์ด, ์ผ๋ณธ์ด ํ์งํ
- ๐ ๊ฐํ๋ ๋ณด์: ์ ๋ ฅ ๊ฒ์ฆ๊ณผ ์์ ํ QR ์ฝ๋ ์์ฑ์ผ๋ก XSS ๋ณดํธ
- Ruby: 3.0+ (Ruby 3.4.2์์ ํ ์คํธ๋จ)
- Rails: 8.0.2+ with Hotwire (Turbo + Stimulus)
- MikroTik ๋ผ์ฐํฐ: RouterOS v7.0+ with WireGuard ์ง์
- ์์กด์ฑ: Node.js, Yarn (์์ ์ปดํ์ผ์ฉ)
- ๋ธ๋ผ์ฐ์ : JavaScript๊ฐ ํ์ฑํ๋ ์ต์ ๋ธ๋ผ์ฐ์
- ์ ์ฅ์ ํด๋ก :
git clone https://github.com/rubyon/easy_wg_mikrotik.git
cd easy_wg_mikrotik- Docker Compose๋ก ์คํ:
docker compose up --build- ๋ธ๋ผ์ฐ์ ์์
http://localhost:3000์ ์
- ์ ์ฅ์ ํด๋ก :
git clone https://github.com/rubyon/easy_wg_mikrotik.git
cd easy_wg_mikrotik- ์์กด์ฑ ์ค์น:
bundle install
yarn install- ๊ฐ๋ฐ ์๋ฒ ์์:
bin/dev- ๋ธ๋ผ์ฐ์ ์์
http://localhost:3000์ ์
- MikroTik ๋ก๊ทธ์ธ: MikroTik ๋ผ์ฐํฐ์ IP ์ฃผ์, ์ฌ์ฉ์๋ช , ๋น๋ฐ๋ฒํธ ์ ๋ ฅ
- WireGuard ์ธํฐํ์ด์ค ํ์ธ: MikroTik ๋ผ์ฐํฐ์ ์ต์ ํ๋์ WireGuard ์ธํฐํ์ด์ค๊ฐ ๊ตฌ์ฑ๋์ด ์๋์ง ํ์ธ
- "์ ํด๋ผ์ด์ธํธ ์์ฑ" ๋ฒํผ ํด๋ฆญ
- ๋๋กญ๋ค์ด์์ WireGuard ์ธํฐํ์ด์ค ์ ํ
- ๋ค์ ์ค์ ๊ตฌ์ฑ:
- ์๋ํฌ์ธํธ: ์๋ฒ์ ๊ณต์ธ IP์ ํฌํธ (์:
your-server.com:51820) - ํ์ฉ๋ IP: ํด๋ผ์ด์ธํธ๊ฐ ์ก์ธ์คํ ์ ์๋ ๋คํธ์ํฌ (์:
10.1.1.0/24,192.168.1.0/24) - ํด๋ผ์ด์ธํธ IP ๋์ญ: ํด๋ผ์ด์ธํธ IP์ฉ ์๋ธ๋ท ์ ๋์ฌ (์:
10.1.1) - ํต์ผ๋ผ์ด๋ธ: ์ง์์ ์ธ ํต์ผ๋ผ์ด๋ธ ๊ฐ๊ฒฉ(์ด) (์:
25)
- ์๋ํฌ์ธํธ: ์๋ฒ์ ๊ณต์ธ IP์ ํฌํธ (์:
- "์ ํด๋ผ์ด์ธํธ ์์ฑ" ๋ฒํผ ํด๋ฆญ
- ์ค์ ํ์ผ์ ๋ค์ด๋ก๋ํ๊ฑฐ๋ ๋ชจ๋ฐ์ผ ๋๋ฐ์ด์ค๋ก QR ์ฝ๋ ์ค์บ
- ํด๋ผ์ด์ธํธ ๋ณด๊ธฐ: "ํด๋ผ์ด์ธํธ ๋ชฉ๋ก"์ ํด๋ฆญํ์ฌ ๋ชจ๋ ๊ตฌ์ฑ๋ ํด๋ผ์ด์ธํธ ํ์ธ
- ์ธํฐํ์ด์ค๋ณ ํํฐ๋ง: ์ธํฐํ์ด์ค๋ฅผ ์ ํํ์ฌ ํด๋น ํด๋ผ์ด์ธํธ๋ง ํ์
- ํด๋ผ์ด์ธํธ ์ญ์ : ํด๋ผ์ด์ธํธ ์์ ์ญ์ ๋ฒํผ์ ํด๋ฆญํ์ฌ ์ ๊ฑฐ
- ์๋ก๊ณ ์นจ: ์๋ก๊ณ ์นจ ๋ฒํผ์ ํด๋ฆญํ์ฌ ํด๋ผ์ด์ธํธ ๋ชฉ๋ก ์ ๋ฐ์ดํธ
์ ํ๋ฆฌ์ผ์ด์ ์ ์ธ์ ๊ธฐ๋ฐ ์ธ์ฆ์ ์ฌ์ฉํ์ฌ MikroTik ์๊ฒฉ ์ฆ๋ช ์ ์์ ํ๊ฒ ์ ์ฅํฉ๋๋ค. ์๋ฒ์๋ ์๊ฒฉ ์ฆ๋ช ์ด ์๊ตฌ์ ์ผ๋ก ์ ์ฅ๋์ง ์์ต๋๋ค.
- ํ๋ ์์ํฌ: Ruby on Rails 8.0.2
- ์ธ์ฆ: ์ ํ์ ์ฟ ํค ์ง์์ฑ์ ๊ฐ์ง ์ธ์ ๊ธฐ๋ฐ ์ธ์ฆ (๋ฐ์ดํฐ๋ฒ ์ด์ค ์์)
- API: MikroTik ํตํฉ์ ์ํ RouterOS API gem
- ๋ณด์: Brakeman ์ค์บ๋, XSS ๋ณดํธ, ์ ๋ ฅ ๊ฒ์ฆ
- JavaScript: ๋ฐ์ํ UI๋ฅผ ์ํ Hotwire (Turbo + Stimulus)
- CSS: ์ต์ ๊ธฐ๋ฅ์ ๊ฐ์ง Tailwind CSS 4.1.11
- ์์ด์ฝ: Bootstrap Icons 1.11.3
- ๋น๋ ๋๊ตฌ: JavaScript์ฉ esbuild, CSS์ฉ Tailwind CLI
- ์ค์๊ฐ: ์ค์๊ฐ ์ ๋ฐ์ดํธ๋ฅผ ์ํ Turbo Streams
- ์ํธํ: ์์ ํ WireGuard ํค ์์ฑ์ ์ํ RbNaCl
- QR ์ฝ๋: ๋ชจ๋ฐ์ผ ์ค์ ์ ์ํ RQRCode
- ํ์งํ: 4๊ฐ ์ธ์ด ์ง์์ ๊ฐ์ง Rails I18n
- ์ฝ๋ ํ์ง: RuboCop Rails Omakase, ERB Lint
- ๐ XSS ๋ณดํธ: ์ ๋ ฅ ๊ฒ์ฆ๊ณผ ์์ ํ ์ถ๋ ฅ ๋ ๋๋ง
- ๐ก๏ธ ์ธ์ ๋ณด์: ์๊ตฌ ์๊ฒฉ ์ฆ๋ช ์ ์ฅ ์์ด ์์ ํ ์ธ์ ๊ด๋ฆฌ
- ๐ ๋ณด์ ์ค์บ๋: ํตํฉ๋ Brakeman ๋ณด์ ๋ถ์
- โ ์ ๋ ฅ ๊ฒ์ฆ: ๋ชจ๋ WireGuard ์ค์ ๋งค๊ฐ๋ณ์์ ๋ํ ํฌ๊ด์ ๊ฒ์ฆ
- ๐ ์์ ํ QR ์์ฑ: ๊ฒ์ฆ์ ํตํ ์์ ํ QR ์ฝ๋ ์์ฑ
- MikroTik ๋ผ์ฐํฐ์ ๊ฐ๋ ฅํ ๋น๋ฐ๋ฒํธ ์ฌ์ฉ
- ํ๋ก๋์ ํ๊ฒฝ์์ HTTPS ๋ค์์ ์คํ
- MikroTik RouterOS ํ์จ์ด ์ ๊ธฐ ์ ๋ฐ์ดํธ
- ์ฌ์ฉํ์ง ์๋ VPN ํด๋ผ์ด์ธํธ ๋ชจ๋ํฐ๋ง ๋ฐ ์ ๊ฑฐ
- ์์ฌ์ค๋ฌ์ด ํ๋์ ๋ํ ์ ํ๋ฆฌ์ผ์ด์ ๋ก๊ทธ ๊ฒํ
# ๋ณด์ ์ค์บ ์คํ
bundle exec brakeman
# ์ฝ๋ ์คํ์ผ ๊ฒ์ฌ
bundle exec rubocop
erb_lint --lint-all
# ์คํ์ผ ์ด์ ์๋ ์์
bundle exec rubocop -A
erb_lint --lint-all --autocorrect
# ํ
์คํธ ์คํ
bin/rails test
bin/rails test:systemapp/controllers/clients_controller.rb- ๋ฉ์ธ WireGuard ํด๋ผ์ด์ธํธ ๊ด๋ฆฌapp/helpers/qr_code_helper.rb- ์์ ํ QR ์ฝ๋ ์์ฑapp/javascript/controllers/- ๋์ UI๋ฅผ ์ํ Stimulus ์ปจํธ๋กค๋ฌapp/views/clients/- WireGuard ํด๋ผ์ด์ธํธ ๊ด๋ฆฌ ๋ทฐconfig/locales/- ๋ค๊ตญ์ด ์ง์ ํ์ผ
- ์ ์ฅ์๋ฅผ ํฌํฌํฉ๋๋ค
- ๊ธฐ๋ฅ ๋ธ๋์น๋ฅผ ์์ฑํฉ๋๋ค (
git checkout -b feature/amazing-feature) - ์ ์ ํ ํ ์คํธ์ ํจ๊ป ๋ณ๊ฒฝ์ฌํญ์ ๋ง๋ญ๋๋ค
- ์ฝ๋ ํ์ง ๊ฒ์ฌ๋ฅผ ์คํํฉ๋๋ค (
rubocop -A && erb_lint --lint-all --autocorrect) - ๋ณ๊ฒฝ์ฌํญ์ ์ปค๋ฐํฉ๋๋ค (
git commit -m 'Add amazing feature') - ๋ธ๋์น์ ํธ์ํฉ๋๋ค (
git push origin feature/amazing-feature) - Pull Request๋ฅผ ์ฝ๋๋ค
์ด ํ๋ก์ ํธ๋ ์คํ ์์ค์ด๋ฉฐ MIT ๋ผ์ด์ผ์ค ํ์ ์ ๊ณต๋ฉ๋๋ค.
์ด README.md๋ Claude Code๋ก ์์ฑ๋์์ต๋๋ค