Sign inSign up

sicnull/devpn

By sicnull

•Updated 2 days ago

Image
0

56

sicnull/devpn repository overview

⁠DeVpn provider node

Docker image for a DeVpn⁠ provider node. On first start it runs the official installer from https://api.devpn.org/static/install-provider.sh, then keeps the provider agent in the foreground.

A container has no systemd. The image supplies a small stand-in so the installer can start WireGuard and the agent, including its reachability self-test.

⁠Run

Get a provisioning token at https://devpn.org/provider-signup⁠.

docker run -d --name devpn-provider --restart unless-stopped \
  --network host \
  --cap-add NET_ADMIN --cap-add NET_RAW \
  --security-opt systempaths=unconfined \
  --device /dev/net/tun \
  -e DEVPN_TOKEN=YOUR_TOKEN \
  -e [email protected] \
  -v devpn-opt:/opt/devpn \
  -v devpn-wg:/etc/wireguard \
  sicnull/devpn

DEVPN_EMAIL is optional. Set it only when the contact address should differ from the account that owns the token. The same values can be passed as arguments:

docker run -d --name devpn-provider --restart unless-stopped \
  --network host \
  --cap-add NET_ADMIN --cap-add NET_RAW \
  --security-opt systempaths=unconfined \
  --device /dev/net/tun \
  -v devpn-opt:/opt/devpn \
  -v devpn-wg:/etc/wireguard \
  sicnull/devpn --token YOUR_TOKEN --email [email protected]

The token is required only for the first start. Later starts of the same volumes reuse the saved provider identity and WireGuard keys.

Follow the first start with:

docker logs -f devpn-provider

The installer waits and rechecks for a couple of minutes, then prints either a verified node or the steps required to make it reachable. The dashboard is https://devpn.org/provider-dashboard⁠.

⁠What the flags are for

FlagWhy
--network hostWireGuard must listen on UDP 51820 on this machine's real address. The installer's NAT and UPnP checks have to see that address.
--cap-add NET_ADMINCreate the WireGuard interface and install its firewall rules.
--cap-add NET_RAWReachability and CGNAT probes.
--security-opt systempaths=unconfinedLets the agent write sysctls such as net.ipv4.ip_forward. Without this, wg-quick can create wg0 and then delete it when the sysctl write is denied.
--device /dev/net/tunUsed when this machine has no WireGuard kernel module. The container then runs wireguard-go on the TUN device.
-v devpn-opt:/opt/devpnProvider id, agent token, and agent script.
-v devpn-wg:/etc/wireguardWireGuard private key and wg0.conf.

⁠Kernel WireGuard and userspace fallback

On startup the container tries to create a kernel WireGuard interface.

  • When that works, the log says using kernel WireGuard.
  • When this machine has no WireGuard module, wg-quick starts wireguard-go instead, and the log says using wireguard-go on /dev/net/tun.

You do not need to run modprobe wireguard first. Keep --device /dev/net/tun in the run command so a machine without the kernel module can still start. Userspace mode is slower once the node is forwarding client traffic.

⁠Host effects

With --network host, the provider software turns IPv6 off on this machine's interfaces and installs its iptables rules on the host. It uses the wg0 interface. Stopping the container removes wg0.

If the node is behind a router, UPnP may fail. Forward UDP 51820 to this machine's LAN address. Heartbeats only show that the agent can reach the API. Peers: 0 means no client is connected yet. The dashboard re-test is what shows whether clients can reach the node.

⁠Logs that mean it is running

[devpn] using kernel WireGuard
net.ipv4.ip_forward = 1
[devpn] starting provider agent
Heartbeat OK | Peers: 0 (active: 0)

wg show wg0 inside the container should show listen port 51820.

Tag summary

Content type

Image

Digest

sha256:861758a7c…

Size

193 MB

Last updated

2 days ago

docker pull sicnull/devpn