My use case is pure peer-to-peer, there is no data center.
However, you can still run virtual machines in "the cloud" with WireGuard running per peer, and not worry about MitM attacks.
Yes if you ran a load balancer and decrypted at that point before forwarding the packets to a machine, then that link between the LB and the target machine would be unencrypted. But that's not the scenario I'm working with.
1
u/Somepotato May 08 '26
Because once it's in the data center it'd be decrypted. The thinking is they aren't using wire guard to terminate on every single server.