I have been working on building a private, secure network accessible from anywhere. The goal was to connect my mobile phone and my local development laptop using a WireGuard VPN, hosting the central gateway on a free-tier Google Cloud Platform (GCP) e2-micro instance.

I wanted to access my self-hosted services, specifically my Docker-hosted Open WebUI, running on my local home Wi-Fi connected laptop, directly from my phone using mobile data.

It sounded straightforward. But if you read my other from scratch journeys, you might have already guessed, it was not.

The Setup

My architectural plan was a simple hub-and-spoke topology: