The Airwall Linux server examples demonstrate support for Ubuntu18 and Docker. It is assumes that at the foundation of the operating system is systemd and can invoke multiple services. Airwall Linux server need to be executed with Docker privileges.
This Dockerfile is an example of adding a service that will be protected by Airwall Linux server. This example uses the Ubuntu18 image with Airwall installed and will add the lighttpd server.
FROM tempered/awls-ubuntu18:airwall-v3.0.0
LABEL maintainer="Tempered Networks, Inc. <[email protected]>"
EXPOSE 8096:8096/tcp
ENV container docker
RUN apt-get -y update \
&& apt-get -y install lighttpd \
&& apt-get clean \
&& rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
RUN systemctl enable lighttpd.service
# Optional
# RUN airsh conf conductor myconductor.example.com
Build the image using the Dockerfile.
docker image build --squash --rm --no-cache -t awls-ubuntu18-webserver .
cat << EOF > setup
#!/bin/sh
set -eu
if nsenter --mount=/host/proc/1/ns/mnt -- mount | grep /sys/fs/cgroup/systemd >/dev/null 2>&1; then
echo 'The systemd cgroup hierarchy is already mounted at /sys/fs/cgroup/systemd.'
else
if [ -d /host/sys/fs/cgroup/systemd ]; then
echo 'The mount point for the systemd cgroup hierarchy already exists at /sys/fs/cgroup/systemd.'
else
echo 'Creating the mount point for the systemd cgroup hierarchy at /sys/fs/cgroup/systemd.'
mkdir -p /host/sys/fs/cgroup/systemd
fi
echo 'Mounting the systemd cgroup hierarchy.'
nsenter --mount=/host/proc/1/ns/mnt -- mount -t cgroup cgroup -o none,name=systemd /sys/fs/cgroup/systemd
fi
echo 'Your Docker host is now configured for running systemd containers!'
EOF
Before you start the Airwall container, run the following command to set up your Docker host. It uses special privileges to create a cgroup hierarchy for systemd and Airwall Linux service. This setup step allows us to run the container in unprivileged containers. This only needs to be done once before the first run.
docker run --rm --privileged -v /:/host tempered/awls-ubuntu18-webserver setup
Use the MAPCONFIG enviroment variable to register the Airwall protected container with the managing Conductor.
docker run -e MAPCONFIG=conductor.example.com -d --network host --security-opt seccomp=unconfined --privileged --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro -t awls-ubuntu18-webserver
docker exec -it awls-ubuntu18-webserver systemctl journalctl
docker exec -it awls-ubuntu18-webserver systemctl status
docker exec -it awls-ubuntu18-webserver /bin/bash
Notice the option of using the command to provision the Airwall to a Conductor. This is an alternative method uses an environment variable.
RUN airsh conf conductor myconductor.example.com
docker exec -it awls-ubuntu18-webserver airsh conf conductor myconductor.example.com
If set, a systemd unit file will be executed once using the value in MAPCONFIG environment variable
docker run -e MAPCONFIG=conductor.example.com -d --network host --security-opt seccomp=unconfined --privileged --tmpfs /run --tmpfs /run/lock -v /sys/fs/cgroup:/sys/fs/cgroup:ro -t awls-ubuntu18-webserver
Content type
Image
Digest
Size
65.8 MB
Last updated
almost 5 years ago
docker pull tempered/awls-ubuntu18:airwall-v3.0.0-webserver