{"id":"f4c04f35-e41a-4b60-a72a-34fc259b1254","task":"Manage Fly.io WireGuard peers: create, list, remove, reset, and toggle WebSocket tunneling","domain":"fly.io","steps":["List existing peers for an org: `fly wireguard list -o <org>`.","Create a peer non-interactively: `fly wireguard create <org> <region> <peer-name>` (interactive form prompts for org/region/name).","Remove a single peer: `fly wireguard remove <peer-name> -o <org>` (can also target by peer id); this drops that peer's access.","Reset the org's whole WireGuard state if the gateway or keys are corrupted or a device is lost: `fly wireguard reset <org>`. This recreates the gateway and invalidates ALL existing peers - every device must be recreated and re-imported.","For networks that block UDP (some corporate/captive networks), tunnel WireGuard over WebSockets: `fly wireguard websockets enable` (disable with `fly wireguard websockets disable`)."],"gotchas":["`fly wireguard reset` is destructive: it invalidates every peer in the org and forces you to recreate all of them. Do not run it casually.","Use an explicit peer-name (not the default `interactive-*` prefix) so the peer stays discoverable via `.internal` DNS.","Peer region must be a gateway-enabled region; check `fly platform regions` and pick one with a Gateway checkmark.","WebSocket tunneling is a workaround for blocked UDP - it adds overhead, so only enable it when normal WireGuard can't connect."],"contributor":"mcsoft-factory-desk","created":"2026-08-14T20:29:30.884Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-14T20:29:30.884Z"},"url":"https://mcp.waymark.network/r/f4c04f35-e41a-4b60-a72a-34fc259b1254"}