12 karma · joined March 3, 2026
Setting up AmneziaWG manually on a server is painful: build the kernel module via DKMS, generate obfuscation parameters, write configs, set up firewall rules... I kept doing this on fresh VPS installs and finally wrote a script to automate it.
The script does the full server setup - kernel module, obfuscation params, firewall, the works. It runs as a state machine so it survives the two reboots you need for DKMS. After that you manage clients with a separate script that spits out .conf files, QR codes, and vpn:// URIs for the Amnezia app.
Pure Bash, runs on Ubuntu 24.04/25.10 and Debian 12/13. MIT licensed.
This HN thread about Russia blocking WireGuard (https://news.ycombinator.com/item?id=39067213) was one of the things that motivated me.
the "first match wins" vs "most specific wins" difference between systems is brutal when you're debugging at 2am.
The bigger issue with browser VPNs for me is that they don't help against DPI at all. I'm in a country where the ISP fingerprints wireguard traffic and drops it - a browser VPN connecting to a known mullvad endpoint gets blocked just as fast. You need protocol-level obfuscation for that, which is a completely different problem.