feat: cloudflared container with optional WireGuard egress
- Dockerfile.cloudflared builds cloudflared (official static binary) on Alpine with wireguard-tools
This commit is contained in:
Executable
+20
@@ -0,0 +1,20 @@
|
||||
#!/bin/sh
|
||||
set -e
|
||||
|
||||
# Опциональный WireGuard: если в wg/wg0.conf лежит конфиг — поднимаем VPN
|
||||
# и только после установки handshake запускаем туннель. Без конфига —
|
||||
# cloudflared стартует сразу, как в базовой схеме Quick Tunnel.
|
||||
if [ -f /etc/wireguard/wg0.conf ]; then
|
||||
echo "WireGuard config found, bringing up wg0..."
|
||||
wg-quick up wg0
|
||||
echo "Waiting for WireGuard handshake..."
|
||||
# Формат `wg show wg0 latest-handshakes`: "<pubkey> <epoch-ts>"; 0 = handshake ещё не было.
|
||||
until wg show wg0 latest-handshakes | awk '{ if ($2 != 0) found=1 } END { exit !found }'; do
|
||||
sleep 2
|
||||
done
|
||||
echo "WireGuard is up, starting Cloudflare tunnel through VPN..."
|
||||
else
|
||||
echo "No WireGuard config, starting Cloudflare tunnel directly..."
|
||||
fi
|
||||
|
||||
exec cloudflared --no-autoupdate tunnel --url "$CLOUDFLARE_TUNNEL_URL"
|
||||
Reference in New Issue
Block a user