- A different device from your home server?
- On the same home server as the services but directly on the host?
- On the same home server as the services but inside some VM or container?
Do you configure it manually or do you use some helper/interface like WGEasy?
I have been personally using wgeasy but recently started locking down and hardening my containers and this node app running as root is kinda…


Im mostly using a self hosted headscale on a remote vps and then tailscale on my clients.
Having the coordination server outside of my network helps quite a bit and things still communicate over the local lan when possible.
For just wireguard itself, I do have a few site to site connections set up at the router level (opnsense).