Sign inSign up

gkweb76/dnscrypt-proxy

By gkweb76

•Updated over 8 years ago

DNSCrypt proxy container based on Alpine Linux and LibreSSL.

Image
0

1.0K

gkweb76/dnscrypt-proxy repository overview

⁠Supported tags

⁠What is DNSCrypt proxy

DNSCrypt proxy⁠ is a DNS resolver using DNScrypt protocol, which works with encrypted DNS requests to DNSCrypt enabled servers.

⁠Why using this image ?

This image is a vanilla DNSCrypt proxy software without any additional packages installed. This enables you to run it concurrently with the DNS caching service of your choice (e.g Unbound). Additionnally, a healthcheck is already configured.

This image is based on Alpine Linux⁠ and therefore is built with LibreSSL⁠, which is a more secure fork of OpenSSL made by the OpenBSD⁠ team. Also Alpine Linux is generally immune to vulnerabilities targetting components not installed in this Operating System, such as: bash (e.g. Shellshock vulnerability), OpenSSL (e.g. Heartbleed vulnerability), glibc (e.g Ghost vulnerability). Also, Alpine Linux has a much smaller image size compared to other OS thanks to less packages installed by default and not relying on glibc, providing faster image download, and reduced attack surface, hence better security.

⁠Maintained by

Guillaume Kaddouch
Blog: https://networkfilter.blogspot.com/⁠
Twitter: @gkweb76⁠
Github: gkweb76⁠

⁠How to use this image from command line

Start your container with the local port of your choice:
docker container run --rm --read-only=true --name dnscrypt-proxy \
-e LOCAL_IP=0.0.0.0 -e LOCAL_PORT=53 -e SERVER=dnscrypt.eu-dk gkweb76/dnscrypt-proxy

⁠Docker compose example

version: "3.5"

services:
   dnscrypt:
   image: gkweb76/dnscrypt-proxy:latest
   container_name: dnscrypt-proxy
   read_only: yes
   networks:
     - dnscrypt
   environment:
     - LOCAL_IP=0.0.0.0 # host IP
     - LOCAL_PORT=53 # container port
     - SERVER=dnscrypt.eu-dk
   volumes:
     - /etc/localtime:/etc/localtime:ro # keep container clock in sync with host
   restart: "unless-stopped"

# Networks declaration
networks:
   dnscrypt:

If you need help with your compose file, check the official documentation⁠.

⁠Tested on

Ubuntu⁠ 18.04 LTS and Docker 18.04.0 CE (Community Edition).

⁠License

MIT License

Tag summary

Content type

Image

Digest

Size

2.5 MB

Last updated

over 8 years ago

docker pull gkweb76/dnscrypt-proxy