Skip to content

Addis Ababa, Ethiopia. Support on 6993.MCP ready. Attach your agents 100% self-service. Sign up using google or phone number. No sales call to get started

System status

Reach your serversover a private tunnel

One WireGuard network per account. Turn it on, add the devices you work from, and reach every machine by its private address with nothing exposed to the public internet.

Free with the account.

What the tunnel joins.

Two ranges with one endpoint between them. A machine answers on its private address whether or not it also has a public one.

Your devices10.200.8.0/24
laptop-210.200.8.3
admin10.200.8.4
pixel-810.200.8.5

WireGuard endpoint

vpn.aletcloud.com:xxxxx

MTU 1420
PersistentKeepalive 25

Your machines10.100.8.0/24
shop-prod10.100.8.4
shop-db10.100.8.7
worker-110.100.8.9

AllowedIPs = 10.100.8.0/24, 10.200.8.0/24

Nothing has to be published
A machine with no public IP answers over the tunnel.
The private key can stay on the device
Paste the device public key and AletCloud never holds the private half. Ask it to generate instead and the key is shown once, at import.
A device is revoked from the list
Remove one and its address gets unassigned while the others carry on.
It is plain WireGuard
wg-quick on a laptop, the WireGuard app on a phone. No AletCloud client is installed on the device.

Three steps to a device.

Once and for the account, then once for each laptop or phone that needs in.

01

Turn it on

One switch on the account. An endpoint and a private range are assigned to it, and the same switch turns the whole network off again.

VPN active10.200.8.0/24

vpn.aletcloud.com:xxxxx

02

Add the device

Name it, then decide who makes the keys. Pasting a public key is the private way round: the half that matters never leaves the machine it was made on.

Generate for meAletCloud makes the pair and hands back a config ready to import.
I will paste my public keyKeys are made on the device and only the public half is sent.

03

Import it and you are on

Download the file and bring it up with wg-quick, or scan the code with the WireGuard app on a phone. From then on every private address answers.

If AletCloud generated the keys, the private one is in this file and is shown once. Nothing can print it again.

$ sudo wg-quick up laptop-2

[Interface]PrivateKey = cHJpdmF0ZS1rZXktc2hvd24tb25jZQ…Address = 10.200.8.5/32MTU = 1420[Peer]PublicKey = c2VydmVyLXB1YmxpYy1rZXk…Endpoint = vpn.aletcloud.com:51822AllowedIPs = 10.100.8.0/24, 10.200.8.0/24PersistentKeepalive = 25

Questions people ask

Short answers to the ones that come up most. For anything else, call 6993 and a person answers.

Ask us something else
What does it cost?

Nothing. One WireGuard network per account, and every device added to it, comes with the account.

Do I need an AletCloud client?

No. It is plain WireGuard: wg-quick on a laptop, the WireGuard app on a phone. The console hands back a config file to import, or you paste the device's public key and the private half never leaves the device.

Can a server have no public IP at all?

Yes. A machine without a public IPv4 address answers on its private address over the tunnel and nowhere else. Remove a device from the list and its address is unassigned while the others carry on.

Start building locally.

13 ETB buys you an afternoon. Signup is a phone number and one SMS.

If it does not work the way this page says it does, call 6993 and say so.