image: ghcr.io/linuxserver/wireguard
    volumes:
      - /etc/wireguard/${netname}:/config
      - /lib/modules:/lib/modules
      - /usr/src:/usr/src
    environment:
      - RUNMODE=server
      - NETNAME=${netname}
      - TZ=${TZ:-GMT}
      - SERVERPORT=${wg_port:-51820}
      - ALLOWEDIPS=${network_address}/${global_prefix:-16}
    cap_add:
      - NET_ADMIN
      - SYS_MODULE
    restart: always
    depends_on:
      - tinc
    sysctls:
      - net.ipv4.conf.all.src_valid_mark=1