Skip to main content
See this official Wireguard quick start tutorial to understand the basic concepts. For each machine, generate a public/private key pair:
Wireguard network requires a set of overlay addresses that will be used by Wireguard interfaces on each machine (WireguardConfig). For example, you can use the 10.0.0.0/24 network for overlay addresses (if this network does not conflict with your existing networks).
This configuration creates a Wireguard interface named wg.int with the overlay address 10.0.0.1/32, if applied on all machines, the machines will be able to communicate with each other over the Wireguard network using the overlay addresses. If you want to route specific networks over the Wireguard interface, you need to set up routing accordingly. See KubeSpan for a way to make Talos Linux set up Wireguard overlay mesh network automatically across the cluster.