Compare commits
2 Commits
f44f93e35a
...
fix/vpn-ip
| Author | SHA1 | Date | |
|---|---|---|---|
| f4fd15643d | |||
| 2bf31c7ccc |
@@ -1,16 +1,9 @@
|
|||||||
# Custom wg-easy with iptables-nft (nftables-backed iptables)
|
# Custom wg-easy with iptables-nft (nftables-backed iptables)
|
||||||
# Fixes crash-loop when host kernel lacks legacy iptable_nat module.
|
# Fixes crash-loop when host kernel lacks legacy iptable_nat module.
|
||||||
FROM weejewel/wg-easy:latest
|
FROM ghcr.io/wg-easy/wg-easy:latest
|
||||||
|
|
||||||
# Alpine's iptables-nft provides iptables that uses nftables kernel API
|
# The upstream image defaults to iptables-legacy via update-alternatives.
|
||||||
# instead of the legacy iptable_nat module. This works on kernels
|
# Switch iptables to the nftables backend (already provided by the 'iptables'
|
||||||
# where only nftables netfilter modules are available.
|
# package on Alpine 3.18+). No apk add needed — iptables-nft is built-in.
|
||||||
RUN apk add --no-cache iptables-nft
|
RUN update-alternatives --set iptables /usr/sbin/iptables-nft && \
|
||||||
|
update-alternatives --set ip6tables /usr/sbin/ip6tables-nft
|
||||||
# Ensure iptables-nft takes priority over legacy iptables
|
|
||||||
RUN ln -sf /sbin/iptables-nft /sbin/iptables && \
|
|
||||||
ln -sf /sbin/iptables-nft-save /sbin/iptables-save && \
|
|
||||||
ln -sf /sbin/iptables-nft-restore /sbin/iptables-restore && \
|
|
||||||
ln -sf /sbin/ip6tables-nft /sbin/ip6tables && \
|
|
||||||
ln -sf /sbin/ip6tables-nft-save /sbin/ip6tables-save && \
|
|
||||||
ln -sf /sbin/ip6tables-nft-restore /sbin/ip6tables-restore
|
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ version: "3.8"
|
|||||||
services:
|
services:
|
||||||
wireguard:
|
wireguard:
|
||||||
build:
|
build:
|
||||||
context: ./vpn
|
context: .
|
||||||
dockerfile: Dockerfile
|
dockerfile: Dockerfile
|
||||||
image: wg-easy-iptables-nft:latest
|
image: wg-easy-iptables-nft:latest
|
||||||
container_name: wireguard
|
container_name: wireguard
|
||||||
|
|||||||
Reference in New Issue
Block a user