Self-hosted service
bivlked/amneziawg-installer avatar
bivlked/amneziawg-installer

bivlked/amneziawg-installer: a one-command AmneziaWG server for Ubuntu and Debian VPS

One-command AmneziaWG 2.0 / 3.x installer for a self-hosted VPN server on Ubuntu and Debian: DPI bypass, traffic obfuscation, split tunneling, auto-hardening, client management. Includes a VPN cascade guide.

1,332 stars107 forksShellMIT

At a glance

What is it?
This repository installs AmneziaWG 2.0 / 3.x as a kernel module on a clean Ubuntu or Debian server, configures the firewall and the first client, and prints a QR code. It is for people who want a self-hosted VPN that survives DPI, not a web panel.
Who is it for?
Adopt it if you control a clean Ubuntu 24.04, Ubuntu 26.04 or Debian 13 VPS, you are comfortable with root shell access, and you want an AmneziaWG endpoint without Docker or a panel. Do not adopt it on shared hosting, on a router, on Ubuntu 25.10 or Debian 12 for a new server, or if you need a web UI for non-technical users; the project ships CLI scripts only.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 3 days ago.
What is it written in?
Mainly Shell, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem: WireGuard handshakes that never complete

Plain WireGuard has a recognisable handshake. On networks that run deep packet inspection, that handshake is enough to identify and drop the connection, so a correctly configured WireGuard server can be unreachable from mobile data or a corporate network while working fine from home. AmneziaWG is the protocol variant that adds traffic obfuscation to the same underlying design. This installer is the deployment layer around it: it takes a fresh Ubuntu or Debian VPS and produces a working server plus a client profile you can import.

The audience is narrow and specific. The README addresses people running a cheap VPS who do not want to learn Linux internals, and it states the script targets a clean Ubuntu or Debian VPS, not a router and not shared hosting. The project also publishes a cascade guide, so a second audience is anyone who wants to chain two servers. Everything is driven from the shell: there is no web panel, and the README presents that as a deliberate choice rather than a missing feature.

What the installer actually changes on the server

The script runs as root and the README publishes a transparency list of what it touches. On the package side it updates the system, installs dependencies such as amneziawg-tools and qrencode, and removes packages it considers unnecessary on a VPN host, including unattended-upgrades. That removal has a consequence the README states plainly: automatic security updates stop being applied. It also removes cloud-init when cloud-init is not managing the network.

For the kernel, it adds the Amnezia PPA with the GPG key checked against a full fingerprint and builds the AmneziaWG module through DKMS. On kernels older than 6.7, which includes stock Debian 12, the README says the installer falls back to a tested 2.0 module built from source, and for some ARM targets it uses prebuilt modules. Networking changes are written as separate files under /etc/sysctl.d/: forwarding, socket buffers and BBR. IPv6 on the host is disabled by default unless you pass --allow-ipv6. Swap is resized according to RAM.

Hardening is part of the same run. UFW is configured to deny inbound, rate-limit SSH and open only the VPN UDP port, and Fail2Ban watches SSH. Key material lives in /root/awg/ and /etc/amnezia/amneziawg/ with 600 or 700 permissions, the service is awg-quick@awg0, and a cron job removes expired clients. This is a lot of system mutation from one command, which is why the rollback behaviour matters as much as the install.

Installing it and adding the first client

The quick start downloads the release script, makes it executable and runs it under sudo. The README says the whole sequence is three commands, involves two reboots, and takes about twenty minutes to a finished VPN. The script itself is fetched over HTTPS from the releases page, and the README notes that helper scripts are verified against pinned SHA256 hashes and that releases carry a detached minisign signature.

bash
wget -O install_amneziawg.sh https://github.com/bivlked/amneziawg-installer/releases/latest/download/install_amneziawg.sh
chmod +x install_amneziawg.sh
sudo bash ./install_amneziawg.sh

When it finishes, according to the README, you get a QR code and a vpn:// link for import into Amnezia Client. The installer creates the first client during installation, so there is nothing else to configure before you can connect.

For unattended runs the script accepts flags. This variant answers every prompt automatically and routes all traffic through the tunnel:

bash
sudo bash ./install_amneziawg.sh --yes --route-all

If the network you connect from inspects traffic, the README recommends a preset that combines obfuscation settings with UDP port 443:

bash
sudo bash ./install_amneziawg.sh --mobile

Client management afterwards goes through a separate script. Granting someone temporary access is a single command with an expiry:

bash
manage_amneziawg.sh add guest --expires=7d

The README also documents --uninstall, which removes the module, configs, sysctl files, cron entries and the UFW rule for the VPN port and the awg0 routing rule.

The rollback is honest but incomplete

Installers that take root are judged by how they leave. The README is unusually direct here: --uninstall removes what the installer added, but it does not restore swap settings and does not reinstall packages that were removed. UFW is disabled and Fail2Ban is uninstalled only if the installer turned them on or installed them; if UFW was already active, the SSH rate-limit rule it added stays behind. That is a reasonable boundary, and stating it is better than pretending the system returns to its prior state, but it means a server that has run this script is not byte-identical to a fresh one after uninstall.

The other sharp edge is unattended-upgrades. Removing it is defensible on a single-purpose VPN host, where an unexpected kernel update can break a DKMS module, but it shifts patch responsibility to the operator. Anyone who installs this and then forgets the server exists is running an unpatched system. The project's own framing, that you set it up and forget it, sits awkwardly next to that fact.

IPv6 is a similar trade-off. Disabling it on the host by default closes a leak path, and release v5.31.0 is described as stopping IPv6 from escaping around the tunnel in the default install. If your server is reachable over IPv6 or you need IPv6 inside the tunnel, you must pass --allow-ipv6 and accept that you are outside the default configuration.

AmneziaWG versus plain WireGuard, and why there is no panel

The meaningful comparison is not with another installer but with WireGuard itself. WireGuard is in the mainline kernel, has first-class tooling on every platform, and is simpler to reason about. Its weakness is exactly the one this project targets: on a network that fingerprints the protocol, a WireGuard endpoint can be blocked regardless of how well it is configured. AmneziaWG changes the wire format to resist that fingerprinting. The cost is a smaller ecosystem, a kernel module that must be built and rebuilt through DKMS on kernel upgrades, and client support that is narrower than WireGuard's.

There is also a comparison to Amnezia VPN, the consumer application. That is a packaged client with a GUI and a server component; this repository is the server side, delivered as shell scripts. If your users need a graphical installer on Windows, Android or iOS, this project does not provide one. It provides a vpn:// link and a QR code that an existing client imports. The README's own framing of the CLI versus panel question is that running without a panel means no overhead and no web surface to expose. The trade-off is that adding a client means running a command, not clicking a button.

Version and maintenance signals

The last push to the default branch was on 2026-09-10, and the most recent release, v5.32.0, is dated 2026-09-08. Releases are frequent and the changelogs describe behavioural changes rather than cosmetic ones: v5.32.0 adds client expiry to a machine-readable interface, records the protocol generation of an installation, and allows client routes to be set at creation time; v5.31.0 closed the IPv6 leak in the default install; v5.30.0 addressed install commands going stale and added a guard for oversized masking parameters. The repository is not archived and is licensed MIT.

One detail worth reading carefully is the protocol generation. The facts block states that the configuration profile is AmneziaWG 2.0 even when the installed module is 3.x, because the generated configs remain 2.0. So a 3.x module does not automatically mean 3.x client profiles. If you specifically need 3.x configuration semantics, verify what the installer produces on your target before assuming it.

On upgrade cost: because the module is built through DKMS, a kernel upgrade triggers a rebuild, and the README's warning about kernels older than 6.7 shows that the module source path depends on your distribution. Re-running the latest release script is the documented way to pick up installer changes, and the pinned-hash verification means the helper scripts are checked on each run. Budget time for the two reboots and for re-issuing client profiles if a protocol change ever lands.

Who this is for, and what to check first

This is a good fit for an engineer or a technically confident individual who owns a VPS, wants an AmneziaWG endpoint in a jurisdiction of their choosing, and prefers shell scripts to a control panel. It is a poor fit for shared hosting, for routers, for anyone who needs a browser UI to hand out access, and for new servers on Ubuntu 25.10 or Debian 12, which the facts block lists as outside normal vendor support.

Before running it, read ADVANCED.md for the complete list of removed packages so the unattended-upgrades removal is a decision rather than a surprise. Check the architecture line if you are on ARM, since the module source differs. Decide whether you need IPv6, because the default is off. And confirm your client supports the vpn:// import format, since the project does not ship clients of its own.

Editorial conclusion

Adopt it if you control a clean Ubuntu 24.04, Ubuntu 26.04 or Debian 13 VPS, you are comfortable with root shell access, and you want an AmneziaWG endpoint without Docker or a panel. Do not adopt it on shared hosting, on a router, on Ubuntu 25.10 or Debian 12 for a new server, or if you need a web UI for non-technical users; the project ships CLI scripts only. Before installing, read ADVANCED.md for the full package removal list, check whether IPv6 matters to you because the default install disables it on the host, and note that --uninstall does not restore swap settings or removed packages.

Frequently asked questions

How do I install AmneziaWG with this installer?

Download the release script, make it executable and run it with sudo: wget -O install_amneziawg.sh followed by chmod +x and sudo bash. The README says the process is three commands, two reboots and about twenty minutes, and that it finishes by printing a QR code and a vpn:// link.

Is AmneziaWG free?

The installer repository is licensed MIT, so the scripts themselves are free to use and modify. The README frames the target as any cheap VPS, which means your own hosting cost is separate from the software.

What are the differences between Amnezia VPN and AmneziaWG?

AmneziaWG is the protocol variant that adds traffic obfuscation so the tunnel is harder to fingerprint. This repository is the server-side installer for it, producing a vpn:// link or QR code that an existing Amnezia Client imports; it does not ship a client application.

Official sources

  1. bivlked/amneziawg-installer on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/bivlked-amneziawg-installer.svg)](https://hysenlabs.com/projects/bivlked-amneziawg-installer)