Private automation path

Reach private AWS, Azure and Google Cloud workloads without exposing every VM.

IntelliconOps guides a WireGuard router and network path inside the selected VPC or VNet, stores the worker-side tunnel configuration persistently and verifies that private workload routes remain reachable.

Discuss private connectivity

Private traffic path

Docker worker
Starts SSH and Ansible traffic. Auto-starts WireGuard tunnels on boot.
WireGuard tunnel
Encrypts traffic between authenticated worker and cloud router.
Cloud router VM
A lightweight AWS, Azure or Google Cloud VM forwards traffic into the private subnet.
Private VM
Receives SSH and automation traffic on its private IP. No public IP needed.

How the bridge works

Keep cloud workloads private while the automation path remains reachable.

Docker bridge

The Python worker originates automation traffic from the IntelliconOps container network.

Host forwarding

The Docker host routes and, where required, translates container traffic onto wg0.

Encrypted tunnel

WireGuard carries authenticated traffic to the selected cloud router over its UDP endpoint.

VPC or VNet router

The router forwards tunnel traffic to workload private IPs and handles the return path.

Provider-specific network paths

The tunnel pattern is shared. The cloud resources are not.

Each guided plan uses the selected provider’s network, firewall, addressing and router primitives while producing a consistent worker-side WireGuard outcome.

AWS VPC

Network
VPC and workload subnets
Router
EC2 WireGuard router
Boundary
Security and routing rules
Scope
AWS account and region

Azure VNet

Network
VNet and workload subnet
Router
Azure VM WireGuard router
Boundary
NSG, address and routing controls
Scope
Subscription and Azure region

Google Cloud VPC

Network
Custom VPC and regional subnet
Router
Compute Engine WireGuard router
Boundary
Firewall rule and regional static IP
Scope
Project, region and zone

Azure walkthrough example

Configure, provision, connect and verify the tunnel.

These screenshots show the Azure path. AWS and Google Cloud follow the same controlled stages with provider-specific VPC, router, firewall and addressing steps.

Select any screenshot to inspect it at full size.

Where the tunnel fits

Cloud control calls and private guest traffic use different paths.

The WireGuard route does not replace AWS, Azure or Google Cloud authentication. It gives IntelliconOps a controlled network path to private workload addresses after provider operations have created or discovered the infrastructure.

OpenTofuCalls provider APIs using scoped cloud credentials
PythonRuns discovery, preflight and lifecycle operations through provider APIs
SSH / AnsibleUses WireGuard to reach private guest IP addresses
VerificationChecks router reachability, workload route and recent handshake

Supported host patterns

Put the peer on the host that owns Docker networking.

WSL development

Install WireGuard in the WSL distribution that owns wg0 and persist the Docker bridge forwarding rules across restarts.

DigitalOcean deployment

Use the customer droplet as the initiating peer and route its IntelliconOps container traffic through the tunnel.

Other Linux Docker hosts

Apply the same host-level pattern where the server supports WireGuard, forwarding, firewall rules and persistent services.

Network safeguards

Make private reachability observable and reversible.

  • Reject overlapping tunnel, Docker and workload address ranges
  • Keep WireGuard private keys on their respective hosts
  • Allow workload SSH from the tunnel boundary rather than the public internet
  • Verify router reachability, workload routing and handshake freshness
  • Expose ordered teardown steps for provisioned networking resources
Current operating boundary: the guided setup still includes host-level installation, peer key exchange and forwarding steps that an authorised operator must complete.

Private infrastructure automation

Connect the worker to private workloads across all three clouds.

Use a guided WireGuard route from the Docker host into an AWS VPC, Azure VNet or Google Cloud VPC, then let governed SSH and Ansible workflows operate over private addresses.

Explore OpenTofu, Python and Ansible

See IntelliconOps in action

Give every cloud request a clear, controlled path.

Tell us how your teams manage infrastructure today. We will show you how IntelliconOps can simplify the work.

Book a demonstration