# Private Network + VPN

Source: https://docs.quake.ai/resources/iac-templates/private-network-vpn
Markdown: https://docs.quake.ai/resources/iac-templates/private-network-vpn.md

---

# Private network + VPN

This pattern composes Network and Compute.

## What this template does

Provisions a private network topology with site-to-site VPN connectivity:

- Private network and subnet for internal workloads
- VPN gateway instance with WireGuard or IPsec (cloud-init installs WireGuard; see [cloud-init and first-boot configuration](/docs/compute/concepts/cloud-init))
- Security groups restricting VPN traffic to authorized endpoints
- Router configuration for VPN tunnel routing
- Split DNS or route-based forwarding to on-premises networks

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist in your project) | required |
| `vpn_protocol` | VPN protocol (wireguard or ipsec) | `wireguard` |
| `private_cidr` | Private network CIDR | `10.0.0.0/24` |
| `remote_cidr` | Remote network CIDR | No default |
| `remote_endpoint` | Remote VPN endpoint IP | No default |
| `remote_wireguard_public_key` | Public key of the WireGuard peer | No default |
| `gateway_flavor` | VPN gateway instance size | `s1a.small` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `external_network` | External network for router gateway and floating IP | `PublicStatic` |
| `vpn_port` | UDP port WireGuard listens on | `51820` |

## When to use this pattern

Connect a private network to remote clients through a WireGuard VPN gateway instance. Choose [Development Environment](/resources/iac-templates/dev-environment) for a bastion-based lab without VPN, or [Simple VM with Floating IP](/resources/iac-templates/simple-vm) when a single public VM is enough.

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "private-network-vpn", required: true },
  ]}
/>

## Template source

<TemplateSource slug="private-network-vpn" />

<TemplateResourceMap template="private-network-vpn" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy the private network + VPN template with OpenTofu](/resources/deployments/deploy-private-network-vpn-template): end-to-end tutorial that applies this template, verifies the WireGuard tunnel, and tears the stack down
- [Networking concepts](/docs/network/concepts/networking)
- [Kubernetes Cluster template](/resources/iac-templates/k8s-cluster)
