Sign inSign up

tempered/awls-ubuntu18

By tempered

•Updated almost 5 years ago

Airwall Linux Server Ubuntu18

Image
0

377

tempered/awls-ubuntu18 repository overview

⁠Airwall Linux server Ubuntu18 for Docker

⁠Introduction

The Airwall Linux server examples demonstrate support for Ubuntu18 and Docker. It is assumes that at the foundation of the operating system is systemd and can invoke multiple services. Airwall Linux server need to be executed with Docker privileges.

⁠Using the Dockerfile

This Dockerfile is an example of adding a service that will be protected by Airwall Linux server. This example uses the Ubuntu18 image with Airwall installed and will add the lighttpd server.

FROM tempered/awls-ubuntu18:airwall-v3.0.0
LABEL maintainer="Tempered Networks, Inc. <[email protected]>"

EXPOSE 8096:8096/tcp

ENV container docker

RUN apt-get -y update \
    && apt-get -y install lighttpd \
    && apt-get clean \
    && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*

RUN systemctl enable lighttpd.service
# Optional
# RUN airsh conf conductor myconductor.example.com
⁠Build the image

Build the image using the Dockerfile.

docker image build --squash --rm --no-cache  -t awls-ubuntu18-webserver .
⁠Prepare the systemd setup script
cat << EOF > setup
#!/bin/sh
set -eu

if nsenter --mount=/host/proc/1/ns/mnt -- mount | grep /sys/fs/cgroup/systemd >/dev/null 2>&1; then
  echo 'The systemd cgroup hierarchy is already mounted at /sys/fs/cgroup/systemd.'
else
  if [ -d /host/sys/fs/cgroup/systemd ]; then
    echo 'The mount point for the systemd cgroup hierarchy already exists at /sys/fs/cgroup/systemd.'
  else
    echo 'Creating the mount point for the systemd cgroup hierarchy at /sys/fs/cgroup/systemd.'
    mkdir -p /host/sys/fs/cgroup/systemd
  fi

  echo 'Mounting the systemd cgroup hierarchy.'
  nsenter --mount=/host/proc/1/ns/mnt -- mount -t cgroup cgroup -o none,name=systemd /sys/fs/cgroup/systemd
fi
echo 'Your Docker host is now configured for running systemd containers!'
EOF

⁠Run setup

Before you start the Airwall container, run the following command to set up your Docker host. It uses special privileges to create a cgroup hierarchy for systemd and Airwall Linux service. This setup step allows us to run the container in unprivileged containers. This only needs to be done once before the first run.

docker run --rm --privileged -v /:/host tempered/awls-ubuntu18-webserver setup
⁠Run container

Use the MAPCONFIG enviroment variable to register the Airwall protected container with the managing Conductor.

docker run -e MAPCONFIG=conductor.example.com -d --network host --security-opt seccomp=unconfined --privileged --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro -t awls-ubuntu18-webserver
⁠Access container
docker exec -it awls-ubuntu18-webserver systemctl journalctl
docker exec -it awls-ubuntu18-webserver systemctl status
docker exec -it awls-ubuntu18-webserver /bin/bash
⁠Options for registering with Conductor

Notice the option of using the command to provision the Airwall to a Conductor. This is an alternative method uses an environment variable.

⁠Add to Dockerfile
RUN airsh conf conductor myconductor.example.com
⁠After running the container
docker exec -it awls-ubuntu18-webserver airsh conf conductor myconductor.example.com
⁠Set MAPCONFIG environment variable

If set, a systemd unit file will be executed once using the value in MAPCONFIG environment variable

docker run -e MAPCONFIG=conductor.example.com -d --network host --security-opt seccomp=unconfined --privileged --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro -t awls-ubuntu18-webserver

Tag summary

Content type

Image

Digest

Size

65.8 MB

Last updated

almost 5 years ago

docker pull tempered/awls-ubuntu18:airwall-v3.0.0-webserver