Docker bridge
The Python worker originates automation traffic from the IntelliconOps container network.
Private automation path
IntelliconOps guides a WireGuard router and network path inside the selected VPC or VNet, stores the worker-side tunnel configuration persistently and verifies that private workload routes remain reachable.
Discuss private connectivityPrivate traffic path
How the bridge works
The Python worker originates automation traffic from the IntelliconOps container network.
The Docker host routes and, where required, translates container traffic onto wg0.
WireGuard carries authenticated traffic to the selected cloud router over its UDP endpoint.
The router forwards tunnel traffic to workload private IPs and handles the return path.
Provider-specific network paths
Each guided plan uses the selected provider’s network, firewall, addressing and router primitives while producing a consistent worker-side WireGuard outcome.
Azure walkthrough example
These screenshots show the Azure path. AWS and Google Cloud follow the same controlled stages with provider-specific VPC, router, firewall and addressing steps.
Select any screenshot to inspect it at full size.
Choose WireGuard, identify the Azure VNet and workload subnet, then define the tunnel range, UDP port and router.
Confirm automation SSH readiness, router and NAT settings, expected costs and the generated provisioning plan.
Run the ordered Azure steps, configure both peers and enable Docker-to-WireGuard forwarding where WSL requires it.
Test router reachability, the workload route and a recent WireGuard handshake, then retain an explicit teardown path.
Where the tunnel fits
The WireGuard route does not replace AWS, Azure or Google Cloud authentication. It gives IntelliconOps a controlled network path to private workload addresses after provider operations have created or discovered the infrastructure.
Supported host patterns
Install WireGuard in the WSL distribution that owns wg0 and persist the Docker bridge forwarding rules across restarts.
Use the customer droplet as the initiating peer and route its IntelliconOps container traffic through the tunnel.
Apply the same host-level pattern where the server supports WireGuard, forwarding, firewall rules and persistent services.
Network safeguards
Private infrastructure automation
Use a guided WireGuard route from the Docker host into an AWS VPC, Azure VNet or Google Cloud VPC, then let governed SSH and Ansible workflows operate over private addresses.
Explore OpenTofu, Python and AnsibleSee IntelliconOps in action
Tell us how your teams manage infrastructure today. We will show you how IntelliconOps can simplify the work.
Book a demonstration