A docker image to run strongSwan as a non-root user
1.9K
strongSwan build from source to run as a non-root user.
For full details, visit the github repository
useradd -M --system -s /usr/sbin/nologin strongswan
To show just one example, you may copy the default configuration like this:
docker pull lkpot/strongswan:latest
docker create --name strongswan lkpot/strongswan:latest
docker container cp strongswan:/etc/strongswan/swanctl swanctl
docker container rm strongswan
chown -R "$(id -u strongswan):$(id -g strongswan)" etc-strongswan
Add your certificates, connections and more to etc-strongswan while ensuring the strongSwan user has access to them and you're ready to go!
docker run --rm --user "$(id -u strongswan):$(id -g strongswan)" \
--network host --cap-drop ALL --cap-add NET_ADMIN \
-v ./swanctl:/etc/strongswan/swanctl lkpot/strongswan:latest
For docker compose, you may want to create an environment file (.env) for easier user mapping.
echo -e "UID=$(id -u strongswan)\nGID=$(id -g strongswan)" > .env
services:
strongswan:
container_name: strongswan
image: lkpot/strongswan:latest
network_mode: host
cap_drop:
- ALL
cap_add:
- NET_ADMIN
- NET_BIND_SERVICE
expose:
- "500"
- "4500"
user: ${UID}:${GID}
volumes:
- ./swanctl:/etc/strongswan/swanctl
restart: unless-stopped
Content type
Image
Digest
sha256:c181fe045…
Size
37.6 MB
Last updated
19 days ago
docker pull lkpot/strongswan