wireguard
diff --git a/apps/wireguard/docker-compose.yml b/apps/wireguard/docker-compose.yml
new file mode 100644
index 0000000..c2ac180
--- /dev/null
+++ b/apps/wireguard/docker-compose.yml
@@ -0,0 +1,19 @@
+version: '3.3'
+services:
+  wireguard:
+    image: masipcat/wireguard-go:latest
+    cap_add:
+     - NET_ADMIN
+    sysctls:
+     - net.ipv4.ip_forward=1
+    volumes:
+     - /dev/net/tun:/dev/net/tun
+     - ./wireguard:/etc/wireguard
+    environment:
+     - WG_COLOR_MODE=always
+     - LOG_LEVEL=info
+    ports:
+     - 51820:51820/udp
+    # Uncomment the following line when 'AllowedIPs' is '0.0.0.0/0'
+    # privileged: true
+    restart: always