Dmytro Onyshchenko
← All case studies

Remote Connectivity with WireGuard

Secure remote access to on-site controllers and industrial gateways through per-tenant WireGuard tunnels, provisioned with GitOps on Kubernetes.

WireGuardVPNJavaQuarkusPythonNetworkingKubernetesSecurity

Customer

An industrial machinery business that engineers energy-efficient heating and cooling products and solutions for buildings, industry, infrastructure, and the food cold chain, with about 11,300 employees worldwide and €3.1bn in net sales.

Problem

Operators and managers need secure remote access to the system managers (on-site controllers) installed in stores and other customer locations. These devices are not reachable from the public internet, and access must not rely on broad VPN access or weaken tenant and network boundaries.

Architecture

Provisioning: the platform UI manages connection configs through a connectivity service. Configs are persisted and committed to a Git repository, and a GitOps controller deploys a per-tenant WireGuard router into the tenant namespace. A sidecar exposes the router to the service so device connections can be added and listed.

Tunnels: engineers connect with a local WireGuard client or a remote desktop machine to the tenant WireGuard router. Industrial gateways at each customer location keep a WireGuard tunnel to the same router, which gives access to the PLCs behind them. Platform services reach the router as a peer.

My contribution

  • Built the WireGuard router service in Python, which acts as the interface to WireGuard (the sidecar that adds and lists device connections).
  • Built the connectivity service in Java with Quarkus, which manages connection configs and drives provisioning.
  • Made the design and architecture decisions for the solution: tenant-aware tunnels, GitOps-based provisioning, and least-privilege access with no standing broad network exposure.
  • Integrated connectivity status and failures into platform observability and runbooks.

Outcomes

  • Multiple customers now use the feature in production.
  • Reduced the time needed to manage gateway configuration and connections.
  • Centralized, controlled access to remote devices through the platform, with no devices exposed to the public internet.