fix: get cloudflared WireGuard tunnel actually serving
- Dockerfile.cloudflared: add iptables + ip6tables (wg-quick needs them for ::/0 full tunnel) - docker-compose: privileged:true for cloudflared so wg-quick can set net.ipv4.conf.all.src_valid_mark - start-cloudflared.sh: restore resolv.conf after wg-quick (resolvconf wiped docker DNS 127.0.0.11 => app unresolvable => Host Error)
This commit is contained in:
@@ -6,7 +6,7 @@
|
|||||||
FROM cloudflare/cloudflared:latest AS cf
|
FROM cloudflare/cloudflared:latest AS cf
|
||||||
|
|
||||||
FROM alpine:3.20
|
FROM alpine:3.20
|
||||||
RUN apk add --no-cache wireguard-tools iproute2
|
RUN apk add --no-cache wireguard-tools iproute2 iptables ip6tables
|
||||||
COPY --from=cf /usr/local/bin/cloudflared /usr/bin/cloudflared
|
COPY --from=cf /usr/local/bin/cloudflared /usr/bin/cloudflared
|
||||||
COPY start-cloudflared.sh /start-cloudflared.sh
|
COPY start-cloudflared.sh /start-cloudflared.sh
|
||||||
ENTRYPOINT ["/bin/sh", "/start-cloudflared.sh"]
|
ENTRYPOINT ["/bin/sh", "/start-cloudflared.sh"]
|
||||||
|
|||||||
@@ -79,6 +79,7 @@ services:
|
|||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
cap_add:
|
cap_add:
|
||||||
- NET_ADMIN
|
- NET_ADMIN
|
||||||
|
privileged: true
|
||||||
volumes:
|
volumes:
|
||||||
- ./wg:/etc/wireguard:ro
|
- ./wg:/etc/wireguard:ro
|
||||||
environment:
|
environment:
|
||||||
|
|||||||
@@ -6,7 +6,11 @@ set -e
|
|||||||
# cloudflared стартует сразу, как в базовой схеме Quick Tunnel.
|
# cloudflared стартует сразу, как в базовой схеме Quick Tunnel.
|
||||||
if [ -f /etc/wireguard/wg0.conf ]; then
|
if [ -f /etc/wireguard/wg0.conf ]; then
|
||||||
echo "WireGuard config found, bringing up wg0..."
|
echo "WireGuard config found, bringing up wg0..."
|
||||||
|
cp /etc/resolv.conf /tmp/resolv.conf.default
|
||||||
wg-quick up wg0
|
wg-quick up wg0
|
||||||
|
# wg-quick/resolvconf перезаписывает resolv.conf (убирает docker-DNS 127.0.0.11),
|
||||||
|
# из-за чего внутреннее имя app не резолвится. Восстанавливаем прежний конфиг.
|
||||||
|
cat /tmp/resolv.conf.default > /etc/resolv.conf
|
||||||
echo "Waiting for WireGuard handshake..."
|
echo "Waiting for WireGuard handshake..."
|
||||||
# Формат `wg show wg0 latest-handshakes`: "<pubkey> <epoch-ts>"; 0 = handshake ещё не было.
|
# Формат `wg show wg0 latest-handshakes`: "<pubkey> <epoch-ts>"; 0 = handshake ещё не было.
|
||||||
until wg show wg0 latest-handshakes | awk '{ if ($2 != 0) found=1 } END { exit !found }'; do
|
until wg show wg0 latest-handshakes | awk '{ if ($2 != 0) found=1 } END { exit !found }'; do
|
||||||
|
|||||||
Reference in New Issue
Block a user