docker-compose.yaml 1.4 KB

12345678910111213141516171819202122232425262728293031
  1. {% set tpl = ix_lib.base.render.Render(values) %}
  2. {% set c1 = tpl.add_container(values.consts.wg_easy_container_name, "image") %}
  3. {% do c1.set_user(0, 0) %}
  4. {% do c1.add_caps(["NET_ADMIN", "SYS_MODULE", "NET_RAW"]) %}
  5. {% do c1.healthcheck.set_custom_test("/usr/bin/wg show | /bin/grep -q interface") %}
  6. {% do c1.environment.add_env("PORT", values.network.web_port.port_number) %}
  7. {% do c1.environment.add_env("INSECURE", values.wg_easy.insecure) %}
  8. {% do c1.environment.add_user_envs(values.wg_easy.additional_envs) %}
  9. {% if not values.network.host_network %}
  10. {% do c1.sysctls.add("net.ipv4.ip_forward", 1) %}
  11. {% do c1.sysctls.add("net.ipv4.conf.all.src_valid_mark", 1) %}
  12. {% do c1.sysctls.add("net.ipv6.conf.all.disable_ipv6", 0) %}
  13. {% do c1.sysctls.add("net.ipv6.conf.all.forwarding", 1) %}
  14. {% do c1.sysctls.add("net.ipv6.conf.default.forwarding", 1) %}
  15. {% do c1.add_port(values.network.web_port) %}
  16. {% do c1.add_port(values.network.udp_port, {"protocol": "udp"}) %}
  17. {% endif %}
  18. {% do c1.add_storage("/lib/modules", {"type": "host_path", "read_only": true, "host_path_config": {"path": "/lib/modules"}}) %}
  19. {% do c1.add_storage("/etc/wireguard", values.storage.config) %}
  20. {% for store in values.storage.additional_storage %}
  21. {% do c1.add_storage(store.mount_path, store) %}
  22. {% endfor %}
  23. {% do tpl.portals.add(values.network.web_port) %}
  24. {{ tpl.render() | tojson }}