VPN of the base platform: WireGuard with DNS, forwarding to the admin network only, amd64/arm64
1.2K
The VPN of the base platform: WireGuard with its own DNS, so that the platform's administration interface is reachable from a few devices and from nowhere else.
Not a general-purpose WireGuard image. It is built for one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use linuxserver/wireguard, which this image is based on.
One tag per release, X.Y.Z, the same version as the other base-* images of that release (first:
2.3.0). There is no latest: deployments reference a version and its digest.
Platforms: linux/amd64, linux/arm64.
linuxserver/wireguard, pinned by digest: WireGuard, iptables and CoreDNS. On the first start it
creates the server key and, for each device, a config with key and QR code.caddy in the admin network. Every other name is forwarded.ListenPort, so a device picks a free port itself.ADMIN_SUBNET is empty, nothing is forwarded at all.| Variable | Meaning |
|---|---|
PEERS | devices, comma-separated; letters and digits only (other names are skipped with a log line) |
SERVERURL, SERVERPORT | endpoint written into the device configs |
INTERNAL_SUBNET | the tunnel's /24, given without mask; the server is .1 and the devices' DNS |
ALLOWEDIPS | what a device routes through the tunnel: the admin network and the tunnel's /24 |
ADMIN_SUBNET | the only network forwarding from the tunnel may reach |
PEERDNS | auto: the devices use the DNS of this container |
LOG_CONFS | set to false, otherwise the device configs, private keys included, go to the log |
| Path | Content |
|---|---|
/config | server key, device keys, configs and QR codes; keep it in a volume and back it up |
Port: 51820/udp. The host needs the wireguard kernel module.
services:
wireguard:
image: christianmaier/base-wireguard:2.3.0
environment:
PEERS: laptop,phone
SERVERURL: vpn.example.com
SERVERPORT: 51820
INTERNAL_SUBNET: 10.10.65.0
PEERDNS: auto
ALLOWEDIPS: 10.10.64.0/24, 10.10.65.0/24
ADMIN_SUBNET: 10.10.64.0/24
LOG_CONFS: "false"
ports: ["51820:51820/udp"]
volumes: ["wireguard-config:/config"]
networks: [vpn, admin]
read_only: true
tmpfs: ["/run:exec", "/tmp"] # the init system starts from /run
cap_drop: ["ALL"]
cap_add: ["NET_ADMIN"]
security_opt: ["no-new-privileges:true"]
sysctls:
net.ipv4.ip_forward: 1
net.ipv4.conf.all.src_valid_mark: 1
healthcheck:
test: ["CMD", "wg", "show", "wg0"]
networks:
vpn: {}
admin:
internal: true
ipam:
config: [{ subnet: 10.10.64.0/24 }]
volumes:
wireguard-config: {}
A device's config, and its QR code in the terminal:
docker exec <container> cat /config/peer_laptop/peer_laptop.conf
docker exec -it <container> /app/show-peer phone
Both contain the device's private key.
wg-quick need it, but with NET_ADMIN as the only
capability, a read-only root filesystem and no-new-privilegesContent type
Image
Digest
sha256:e5aba5f4d…
Size
38.8 MB
Last updated
1 day ago
docker pull christianmaier/base-wireguard:2.9.4