fix: get cloudflared WireGuard tunnel actually serving

- Dockerfile.cloudflared: add iptables + ip6tables (wg-quick needs them for ::/0 full tunnel)

- docker-compose: privileged:true for cloudflared so wg-quick can set net.ipv4.conf.all.src_valid_mark

- start-cloudflared.sh: restore resolv.conf after wg-quick (resolvconf wiped docker DNS 127.0.0.11 => app unresolvable => Host Error)
This commit is contained in:
dev
2026-09-12 18:51:19 +03:00
parent dd4d306a4e
commit 3c40e94a57
3 changed files with 6 additions and 1 deletions
+1
View File
@@ -79,6 +79,7 @@ services:
restart: unless-stopped
cap_add:
- NET_ADMIN
privileged: true
volumes:
- ./wg:/etc/wireguard:ro
environment: