Docker image for a DeVpn provider node. On first start it runs the official installer from https://api.devpn.org/static/install-provider.sh, then keeps the provider agent in the foreground.
A container has no systemd. The image supplies a small stand-in so the installer can start WireGuard and the agent, including its reachability self-test.
Get a provisioning token at https://devpn.org/provider-signup.
docker run -d --name devpn-provider --restart unless-stopped \
--network host \
--cap-add NET_ADMIN --cap-add NET_RAW \
--security-opt systempaths=unconfined \
--device /dev/net/tun \
-e DEVPN_TOKEN=YOUR_TOKEN \
-e [email protected] \
-v devpn-opt:/opt/devpn \
-v devpn-wg:/etc/wireguard \
sicnull/devpn
DEVPN_EMAIL is optional. Set it only when the contact address should differ from the account that owns the token. The same values can be passed as arguments:
docker run -d --name devpn-provider --restart unless-stopped \
--network host \
--cap-add NET_ADMIN --cap-add NET_RAW \
--security-opt systempaths=unconfined \
--device /dev/net/tun \
-v devpn-opt:/opt/devpn \
-v devpn-wg:/etc/wireguard \
sicnull/devpn --token YOUR_TOKEN --email [email protected]
The token is required only for the first start. Later starts of the same volumes reuse the saved provider identity and WireGuard keys.
Follow the first start with:
docker logs -f devpn-provider
The installer waits and rechecks for a couple of minutes, then prints either a verified node or the steps required to make it reachable. The dashboard is https://devpn.org/provider-dashboard.
| Flag | Why |
|---|---|
--network host | WireGuard must listen on UDP 51820 on this machine's real address. The installer's NAT and UPnP checks have to see that address. |
--cap-add NET_ADMIN | Create the WireGuard interface and install its firewall rules. |
--cap-add NET_RAW | Reachability and CGNAT probes. |
--security-opt systempaths=unconfined | Lets the agent write sysctls such as net.ipv4.ip_forward. Without this, wg-quick can create wg0 and then delete it when the sysctl write is denied. |
--device /dev/net/tun | Used when this machine has no WireGuard kernel module. The container then runs wireguard-go on the TUN device. |
-v devpn-opt:/opt/devpn | Provider id, agent token, and agent script. |
-v devpn-wg:/etc/wireguard | WireGuard private key and wg0.conf. |
On startup the container tries to create a kernel WireGuard interface.
using kernel WireGuard.wg-quick starts wireguard-go instead, and the log says using wireguard-go on /dev/net/tun.You do not need to run modprobe wireguard first. Keep --device /dev/net/tun in the run command so a machine without the kernel module can still start. Userspace mode is slower once the node is forwarding client traffic.
With --network host, the provider software turns IPv6 off on this machine's interfaces and installs its iptables rules on the host. It uses the wg0 interface. Stopping the container removes wg0.
If the node is behind a router, UPnP may fail. Forward UDP 51820 to this machine's LAN address. Heartbeats only show that the agent can reach the API. Peers: 0 means no client is connected yet. The dashboard re-test is what shows whether clients can reach the node.
[devpn] using kernel WireGuard
net.ipv4.ip_forward = 1
[devpn] starting provider agent
Heartbeat OK | Peers: 0 (active: 0)
wg show wg0 inside the container should show listen port 51820.
Content type
Image
Digest
sha256:861758a7c…
Size
193 MB
Last updated
2 days ago
docker pull sicnull/devpn