> that always comes with the danger of not going through VPN if the connection somehow drops or you've restarted the machine its running on and the vpn started after the torrent client.
My current setup uses namespaces to avoid this issue. Basically, one can create a wg interface in the default namespace and then move it to a new namespace and run applications there. The wg interface keeps routing the encrypted traffic through the interfaces in the default namespace, but as there is only the wg interface in the new namespace, there is no risk of leaking any traffic.
It also doesn't need a network bridge and doesn't disturb the network configuration of the host.
I use lxc, but there are probably more lightweight options to just start an application in a different network namespace.
See: https://www.wireguard.com/netns/