Dockerfile linksDante consists of a SOCKS server and a SOCKS client, implementing RFC 1928 and related standards. It can in most cases be made transparent to clients, providing functionality somewhat similar to what could be described as a non-transparent Layer 4 router. For customers interested in controlling and monitoring access in or out of their network, the Dante SOCKS server can provide several benefits, including security and TCP/IP termination (no direct contact between hosts inside and outside of the customer network), resource control (bandwidth, sessions), logging (host information, data transferred), and authentication.
docker create \
--name=dante \
-e PUID=1000 \
-e PGID=1000 \
-p 1080:1080 \
-v /path/to/config:/config \
--restart always \
tsubus/dante
Change its configuration by modifying the file at /path/to/config/sockd.conf
(see sample config files).
You need to restart the container whenever you modify this file.
Container images are configured using parameters passed at runtime (such as those above). These parameters are separated by a colon and indicate <external>:<internal> respectively. For example, -p 1010:1080 would expose port 1080 from inside the container to be accessible from the host's IP on port 1010 outside the container.
| Parameter | Function |
|---|---|
-p 1080:1080 | sockd port |
-e PUID=1000 | for UserID - see below for explanation |
-e PGID=1000 | for GroupID - see below for explanation |
-v /config | where dante will read its configuration file on start |
When using volumes (-v flags) permissions issues can arise between the host OS and the container, we avoid this issue by allowing you to specify the user PUID and group PGID.
Ensure any volume directories on the host are owned by the same user you specify and any permissions issues will vanish like magic.
In this instance PUID=1000 and PGID=1000, to find yours use id user as below:
$ id username
uid=1000(dockeruser) gid=1000(dockergroup) groups=1000(dockergroup)
Set your browser or application to use SOCKS v4 or v5 proxy localhost on port 1080,
like for example:
$ curl --proxy socks5://localhost:1080 https://example.com
... or set to use PAC script like:
function FindProxyForURL(url, host) {
return "SOCKS localhost:1080";
}
The default config in this image allows everyone to use the proxy. You can add a simple authentication (which will send data unencrypted) by setting up a Dockerfile like:
FROM tsubus/dante
# TODO: Replace 'john' and 'MyPassword' by any username/password you want.
RUN printf 'MyPassword\nMyPassword\n' | adduser john
Uncomment line in sockd.conf:
socksmethod: username
Then use SOCKS v5, for example:
$ curl --proxy socks5://john:MyPassword@localhost:1080 https://example.com
Note: SOCKS v4 will be blocked.
WARNING: Many browsers do not support SOCKS authentication (e.g. see this Chrome bug).
Content type
Image
Digest
Size
9.9 MB
Last updated
almost 6 years ago
docker pull tsubus/dante