Sign inSign up

blackxdog/openvpn-client-ros

By blackxdog

β€’Updated 28 days ago

OpenVPN client for MikroTik RouterOS: ARMv5, ARMv7, ARM64 and AMD64/CHR with REST route sync.

Image
0

601

blackxdog/openvpn-client-ros repository overview

⁠openvpn-client-ros

Multi-architecture OpenVPN client for MikroTik RouterOS containers. It reconnects automatically and synchronizes VPN routes and firewall address lists through the RouterOS REST API.

Platforms RouterOS GitHub

⁠✨ Features

  • πŸ“¦ One latest tag for linux/arm/v5, linux/arm/v7, linux/arm64, and linux/amd64.
  • βœ… Supports ARM models, RB4011, RB5009, x86, and CHR.
  • πŸ”„ Automatic OpenVPN reconnect with lifecycle messages in RouterOS logs.
  • πŸ›£ Synchronizes server-pushed IPv4 networks with /ip/route.
  • 🧾 Synchronizes the same networks with /ip/firewall/address-list.
  • 🏷 Uses the container name or a custom ownership tag/comment.
  • ♻️ Keeps valid records unchanged and removes stale owned records.
  • πŸ” RouterOS REST over HTTPS with file-based secrets.
  • πŸͺ΅ Logging levels: error, warn, info, debug.

⁠🧱 Supported platforms

MikroTik familyRouterOS archDocker platform
RB4011 and other ARM32 devicesarmlinux/arm/v5
Generic ARMv7armlinux/arm/v7
RB5009 and ARM64 devicesarm64linux/arm64
CHR and x86-64x86_64linux/amd64

RouterOS expects ARM32/ARMv5 container images for its arm architecture.

⁠⚑ Get the image

docker pull blackxdog/openvpn-client-ros:latest

RouterOS automatically selects the correct architecture from the multi-platform manifest.

β πŸš€ RouterOS installation

Use the idempotent deployment script from GitHub:

  1. Enable the RouterOS container package and device-mode container=yes.
  2. Upload client.ovpn to usb1/openvpn-client-ros/config/ or openvpn-client-ros/config/ on system storage.
  3. Download deploy-routeros.rsc⁠.
  4. Upload it to RouterOS and run it from an interactive terminal; select usb1 or system.
  5. Enter the VPN login and password when prompted; the REST API password is generated automatically.
/import file-name=deploy-routeros.rsc verbose=yes

Full instructions: README⁠ Β· README Π½Π° русском⁠

⁠🌐 Traffic flow

LAN client
    ↓
RouterOS route β†’ container veth IP
    ↓
container eth0 β†’ forwarding + masquerade β†’ tun0 β†’ VPN

The route gateway is the container veth address, not the remote tunnel gateway.

β πŸ“ Persistent mount

Only one mount is required:

usb1/openvpn-client-ros/config  β†’  /config

It stores client.ovpn, referenced certificates/keys, optional CA files, and secret files.

β βš™οΈ Main environment variables

ENVDefaultPurpose
OVPN_CONFIG/config/client.ovpnOpenVPN profile
OVPN_USERNAMEβ€”VPN username
OVPN_PASSWORD_FILEβ€”Preferred VPN password file
OVPN_RESTART_DELAY10Restart delay after OpenVPN exits
OVPN_LOG_LEVELinfoContainer logging level
OVPN_API_URLβ€”RouterOS REST URL
OVPN_API_USERβ€”RouterOS REST user
OVPN_API_PASSWORD_FILEβ€”Preferred REST password file
OVPN_API_VERIFY_TLStrueVerify HTTPS certificate
OVPN_CONTAINER_NAMEovpn-client-rosIdentity and default tag
OVPN_ROUTE_TAGemptyCustom ownership comment
OVPN_SYNC_ROUTEStrueSynchronize RouterOS routes
OVPN_SYNC_ADDRESS_LISTtrueSynchronize address list
OVPN_ADDRESS_LIST_NAMEemptyEmpty uses container name
OVPN_ROUTE_TABLEmainTarget routing table
OVPN_ALLOW_DEFAULT_ROUTEfalseAllow pushed default route
OVPN_EXTRA_ROUTESemptyExtra space-separated CIDRs

Legacy ROS_* route-synchronization names remain accepted as compatibility aliases.

β πŸ›  Diagnostics

/container/print
/log/print where topics~"container"
/ip/route/print where comment="ovpn-client-ros"
/ip/firewall/address-list/print where comment="ovpn-client-ros"

β πŸ›‘ Security

  • Use dedicated VPN and RouterOS REST accounts.
  • Restrict REST access to the isolated container address.
  • Prefer www-ssl; plain HTTP should only be an isolated fallback.
  • Store passwords with OVPN_PASSWORD_FILE and OVPN_API_PASSWORD_FILE.
  • Never bake private profiles, keys, or password files into the image.

β πŸ’– Support

If this image saves you time, you can support development on Boosty⁠.

Source code and documentation: github.com/blackxd0g/openvpn-client-ros⁠

Tag summary

Content type

Image

Digest

sha256:a50e567d7…

Size

19.3 MB

Last updated

28 days ago

docker pull blackxdog/openvpn-client-ros