Sign inSign up

lkpot/strongswan

By lkpot

•Updated 19 days ago

A docker image to run strongSwan as a non-root user

Image
Networking
Security
0

1.9K

lkpot/strongswan repository overview

⁠Overview

strongSwan build from source to run as a non-root user.

For full details, visit the github repository⁠

⁠Quick Start

⁠Create a new user for strongSwan
This user will later be mapped into the container.
useradd -M --system -s /usr/sbin/nologin strongswan
⁠Prepare strongSwan data directory
There are multiple ways to achieve this.

To show just one example, you may copy the default configuration like this:

docker pull lkpot/strongswan:latest
docker create --name strongswan lkpot/strongswan:latest
docker container cp strongswan:/etc/strongswan/swanctl swanctl
docker container rm strongswan
chown -R "$(id -u strongswan):$(id -g strongswan)" etc-strongswan

Add your certificates, connections and more to etc-strongswan while ensuring the strongSwan user has access to them and you're ready to go!

⁠Starting the container
docker run --rm --user "$(id -u strongswan):$(id -g strongswan)" \
           --network host --cap-drop ALL --cap-add NET_ADMIN \
           -v ./swanctl:/etc/strongswan/swanctl lkpot/strongswan:latest
⁠docker-compose.yaml

For docker compose, you may want to create an environment file (.env)⁠ for easier user mapping.

echo -e "UID=$(id -u strongswan)\nGID=$(id -g strongswan)" > .env
services:
  strongswan:
    container_name: strongswan

    image: lkpot/strongswan:latest

    network_mode: host

    cap_drop:
      - ALL

    cap_add:
      - NET_ADMIN
      - NET_BIND_SERVICE

    expose:
      - "500"
      - "4500"

    user: ${UID}:${GID}

    volumes:
      - ./swanctl:/etc/strongswan/swanctl

    restart: unless-stopped

Tag summary

Content type

Image

Digest

sha256:c181fe045…

Size

37.6 MB

Last updated

19 days ago

docker pull lkpot/strongswan