https://interceptor.marconitschke.de/thread-154.html
2.6K
Create a web server with debian and docker in any country.
Open the following ports on your VPS: 443-TCP, 51820-UDP
Install the containers using docker-compose
Access the website at https://YOUR-WEBSERVER-IP
Save the setup.zip file
Scan the QR code or import the setup.zip file directly into the WireGuard app
# Ma Ni v0.4
#
#
name: openglee_vpn
#
# public IP queries are performed using the following providers: https://api.ipify.org -- https://ifconfig.me
#
services:
wg-vpn:
image: nitje/openglee-wg-vpn:latest
container_name: openglee-wg-vpn
restart: unless-stopped
cap_add:
- NET_ADMIN
# - SYS_MODULE
sysctls:
net.ipv4.ip_forward: "1"
net.ipv4.conf.all.src_valid_mark: "1"
net.ipv6.conf.all.forwarding: "1"
devices:
- /dev/net/tun:/dev/net/tun
environment:
# Optional: set this to a fixed public IP or domain. If empty, config-ui will auto-detect.
SERVERURL: "${SERVERURL:-}"
SERVERPORT: "${SERVERPORT:-51820}"
VPN_SUBNET: "${VPN_SUBNET:-10.0.0.0/24}"
VPN_SERVER_IP: "${VPN_SERVER_IP:-10.0.0.1/24}"
PIHOLE_VPN_IP: "${PIHOLE_VPN_IP:-10.0.0.2/32}"
# Default client AllowedIPs. Change to "10.0.0.0/24" for split tunnel to VPN-only.
CLIENT_ALLOWED_IPS: "${CLIENT_ALLOWED_IPS:-0.0.0.0/0, ::/0}"
# UI URL is only informational for README in the ZIP.
UI_HTTPS_PORT: "${UI_HTTPS_PORT:-443}"
TZ: "${TZ:-Europe/Berlin}"
ports:
- "${SERVERPORT:-51820}:51820/udp"
volumes:
- openglee_vpn_wg:/wgdata
healthcheck:
test: ["CMD-SHELL", "wg show wg0 >/dev/null 2>&1"]
interval: 10s
timeout: 5s
retries: 12
dns-filter:
image: pihole/pihole:latest
container_name: openglee-dns-filter
restart: unless-stopped
# IMPORTANT: Pi-hole is only reachable THROUGH the VPN tunnel
# because it shares the wg-vpn network namespace and we do NOT publish ports to the host.
network_mode: "service:wg-vpn"
depends_on:
wg-vpn:
condition: service_healthy
config-ui:
condition: service_started
environment:
TZ: "${TZ:-Europe/Berlin}"
FTLCONF_webserver_api_password: "${FTLCONF_webserver_api_password:-OpenGleeVPN}"
DNSMASQ_LISTENING: "all"
# Pi-hole will listen on wg0 (10.0.0.1) plus alias IP (10.0.0.2) added by wg-vpn entrypoint
FTLCONF_LOCAL_IPV4: "${PIHOLE_LOCAL_IPV4:-10.0.0.2}"
# ONLY HTTPS (443) -y optional IPv6
FTLCONF_webserver_port: "${FTLCONF_webserver_port:-443s,[::]:443s}"
# Our self-generated certificate (PEM = cert+key)
FTLCONF_webserver_tls_cert: "/etc/pihole/tls.pem"
# volumes:
# - openglee_vpn_etc_pihole:/etc/pihole
# - openglee_vpn_etc_dnsmasq:/etc/dnsmasq.d
config-ui:
image: nitje/openglee-config-ui:latest
container_name: openglee-config-ui
restart: unless-stopped
environment:
APPNAME: "OpenGlee VPN"
SERVERURL: "${SERVERURL:-}"
SERVERPORT: "${SERVERPORT:-51820}"
VPN_SUBNET: "${VPN_SUBNET:-10.0.0.0/24}"
VPN_SERVER_IP: "${VPN_SERVER_IP:-10.0.0.1/24}"
PIHOLE_DNS_IP: "${PIHOLE_DNS_IP:-10.0.0.2}"
CLIENT_ALLOWED_IPS: "${CLIENT_ALLOWED_IPS:-0.0.0.0/0, ::/0}"
UI_HTTPS_PORT: "${UI_HTTPS_PORT:-443}"
TZ: "${TZ:-Europe/Berlin}"
ports:
- "${UI_HTTPS_PORT:-443}:443/tcp"
volumes:
# - openglee_vpn_generated:/generated
- openglee_vpn_wg:/wgdata
- openglee_vpn_config_ui:/var/run/config-ui # This is required so that the setup route is not displayed after a restart or update.
healthcheck:
test: ["CMD-SHELL", "wget -qO- https://127.0.0.1/health --no-check-certificate >/dev/null 2>&1 || exit 1"]
interval: 15s
timeout: 5s
retries: 6
depends_on:
wg-vpn:
condition: service_started
volumes:
openglee_vpn_wg:
name: openglee_vpn_wg
# openglee_vpn_etc_pihole:
# name: openglee_vpn_etc_pihole
# openglee_vpn_etc_dnsmasq:
# name: openglee_vpn_etc_dnsmasq
# openglee_vpn_generated:
# name: openglee_vpn_generated
openglee_vpn_config_ui:
name: openglee_vpn_config_ui
v0.0.2 config-ui: worker 2, timeout, keepalive, health route and changes in docker compose
v0.3 change version on both container and config-ui: persistent traffic and install volume
v0.4 try to fix "network unreachable"
Content type
Image
Digest
sha256:ab5914780…
Size
34.5 MB
Last updated
7 months ago
docker pull nitje/openglee-config-ui