OpenVPN client for MikroTik RouterOS: ARMv5, ARMv7, ARM64 and AMD64/CHR with REST route sync.
601
Multi-architecture OpenVPN client for MikroTik RouterOS containers. It reconnects automatically and synchronizes VPN routes and firewall address lists through the RouterOS REST API.
latest tag for linux/arm/v5, linux/arm/v7, linux/arm64, and linux/amd64./ip/route./ip/firewall/address-list.error, warn, info, debug.| MikroTik family | RouterOS arch | Docker platform |
|---|---|---|
| RB4011 and other ARM32 devices | arm | linux/arm/v5 |
| Generic ARMv7 | arm | linux/arm/v7 |
| RB5009 and ARM64 devices | arm64 | linux/arm64 |
| CHR and x86-64 | x86_64 | linux/amd64 |
RouterOS expects ARM32/ARMv5 container images for its arm architecture.
docker pull blackxdog/openvpn-client-ros:latest
RouterOS automatically selects the correct architecture from the multi-platform manifest.
Use the idempotent deployment script from GitHub:
container package and device-mode container=yes.client.ovpn to usb1/openvpn-client-ros/config/ or openvpn-client-ros/config/ on system storage.usb1 or system./import file-name=deploy-routeros.rsc verbose=yes
Full instructions: READMEβ Β· README Π½Π° ΡΡΡΡΠΊΠΎΠΌβ
LAN client
β
RouterOS route β container veth IP
β
container eth0 β forwarding + masquerade β tun0 β VPN
The route gateway is the container veth address, not the remote tunnel gateway.
Only one mount is required:
usb1/openvpn-client-ros/config β /config
It stores client.ovpn, referenced certificates/keys, optional CA files, and secret files.
| ENV | Default | Purpose |
|---|---|---|
OVPN_CONFIG | /config/client.ovpn | OpenVPN profile |
OVPN_USERNAME | β | VPN username |
OVPN_PASSWORD_FILE | β | Preferred VPN password file |
OVPN_RESTART_DELAY | 10 | Restart delay after OpenVPN exits |
OVPN_LOG_LEVEL | info | Container logging level |
OVPN_API_URL | β | RouterOS REST URL |
OVPN_API_USER | β | RouterOS REST user |
OVPN_API_PASSWORD_FILE | β | Preferred REST password file |
OVPN_API_VERIFY_TLS | true | Verify HTTPS certificate |
OVPN_CONTAINER_NAME | ovpn-client-ros | Identity and default tag |
OVPN_ROUTE_TAG | empty | Custom ownership comment |
OVPN_SYNC_ROUTES | true | Synchronize RouterOS routes |
OVPN_SYNC_ADDRESS_LIST | true | Synchronize address list |
OVPN_ADDRESS_LIST_NAME | empty | Empty uses container name |
OVPN_ROUTE_TABLE | main | Target routing table |
OVPN_ALLOW_DEFAULT_ROUTE | false | Allow pushed default route |
OVPN_EXTRA_ROUTES | empty | Extra space-separated CIDRs |
Legacy ROS_* route-synchronization names remain accepted as compatibility aliases.
/container/print
/log/print where topics~"container"
/ip/route/print where comment="ovpn-client-ros"
/ip/firewall/address-list/print where comment="ovpn-client-ros"
www-ssl; plain HTTP should only be an isolated fallback.OVPN_PASSWORD_FILE and OVPN_API_PASSWORD_FILE.If this image saves you time, you can support development on Boostyβ .
Source code and documentation: github.com/blackxd0g/openvpn-client-rosβ
Content type
Image
Digest
sha256:a50e567d7β¦
Size
19.3 MB
Last updated
28 days ago
docker pull blackxdog/openvpn-client-ros