š³ Possibly the smallest ZeroTier Moon image. One-step setup for amd64, arm64 & arm/v7.
2.1K
š³ Possibly the smallest ZeroTier Moon image. One-step deployment for amd64, arm64 & arm/v7.
A minimal Alpine-based image that builds ZeroTierOne directly from source. Current compressed image sizes are approximately 7.3-11.8 MiB, depending on architecture.
A Moon is a user-operated ZeroTier root server that can improve peer discovery and connection stability. It does not replace ZeroTier Central or your network controller.
linux/amd64, linux/arm64, linux/arm/v7ONLINEThe following command automatically detects the public IPv4 and IPv6 addresses:
docker run -d \
--name zerotier-moon \
--restart unless-stopped \
-p 9993:9993/udp \
-v ./zerotier-one:/var/lib/zerotier-one \
--device /dev/net/tun \
--cap-add NET_ADMIN \
--cap-add SYS_ADMIN \
criogaid/zerotier-moon:latest
To specify the public endpoints explicitly:
docker run -d \
--name zerotier-moon \
--restart unless-stopped \
-p 9993:9993/udp \
-v ./zerotier-one:/var/lib/zerotier-one \
--device /dev/net/tun \
--cap-add NET_ADMIN \
--cap-add SYS_ADMIN \
criogaid/zerotier-moon:latest \
-4 YOUR_PUBLIC_IPV4 \
-6 YOUR_PUBLIC_IPV6 \
-p 9993
You may omit either -4 or -6 when that address family is unavailable. If both are omitted, the container attempts automatic detection.
The advertised endpoint must be reachable by ZeroTier peers. If the host is behind NAT, forward the configured UDP port to the container host.
| Parameter | Description | Default |
|---|---|---|
-4 ADDRESS | Public IPv4 endpoint; automatically detected when omitted | Auto |
-6 ADDRESS | Public IPv6 endpoint; automatically detected when omitted | Auto |
-p PORT | Moon UDP listening and advertised port | 9993 |
Ports must be between 1 and 65535. CIDR notation is not accepted.
services:
zerotier-moon:
image: criogaid/zerotier-moon:latest
container_name: zerotier-moon
restart: unless-stopped
ports:
- "9993:9993/udp"
volumes:
- ./zerotier-one:/var/lib/zerotier-one
devices:
- /dev/net/tun
cap_add:
- NET_ADMIN
- SYS_ADMIN
environment:
# Optional: space-separated 16-character hexadecimal network IDs.
ZEROTIER_JOIN_NETWORKS: ""
# Optional: custom local ZeroTier API token.
ZEROTIER_API_SECRET: ""
# Optional: provide both values to use a custom identity.
ZEROTIER_IDENTITY_PUBLIC: ""
ZEROTIER_IDENTITY_SECRET: ""
# Remove this section to use automatic IP detection.
command:
- "-4"
- "YOUR_PUBLIC_IPV4"
# Add these two entries when IPv6 is available:
# - "-6"
# - "YOUR_PUBLIC_IPV6"
- "-p"
- "9993"
Start the service:
docker compose up -d
Check its status:
docker compose ps
docker compose logs zerotier-moon
Joining a network is optional and is not required for Moon operation.
Set ZEROTIER_JOIN_NETWORKS to one or more space-separated network IDs:
environment:
ZEROTIER_JOIN_NETWORKS: "8888888888888888 6666666666666666"
Each network ID must contain exactly 16 hexadecimal characters.
Mount /var/lib/zerotier-one to preserve:
moon.json.moon fileWhen the effective IPv4, IPv6, or port changes, the image automatically regenerates the local Moon configuration while preserving the existing identity and Moon ID.
If automatic IP detection temporarily fails, a valid persisted endpoint for that address family is retained and updated to use the currently configured port.
A successful first startup produces output similar to:
=> IPv4 unset, auto detecting
=> IPv6 unset, auto detecting
=> StableEndpoints: ["203.0.113.10/9993"]
=> Generating ZeroTier identity
=> Generating Moon configuration
Starting Control Plane...
Starting V6 Control Plane...
Moon ID: xxxxxxxxxx
Orbit command: zerotier-cli orbit xxxxxxxxxx xxxxxxxxxx
Use the displayed command on each ZeroTier node that should orbit the Moon:
zerotier-cli orbit YOUR_MOON_ID YOUR_MOON_ID
latest - latest supported ZeroTierOne release1.x.x - immutable versioned releases matching upstream ZeroTierOneExample:
docker pull criogaid/zerotier-moon:1.16.2
Content type
Image
Digest
sha256:b20f85622ā¦
Size
11.6 MB
Last updated
about 1 month ago
docker pull criogaid/zerotier-moon