Xiid's STLink enables Terniion SealedTunnel connections and enforces which processes can connect
1.6K
A production-ready containerized deployment of Xiid STLink for Linux, supporting both AMD64 (x86_64) and ARM64 architectures. This image provides a seamless way to run STLink in containerized environments including Docker, Podman, and Kubernetes.
docker run -d -p 10479:10479 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:latest
Replace your_activation_code_here with your valid Xiid STLink activation code.
You can access the STLink Portal at exposed port 10479 (HTTPS).
This container is meant to be used alongside other applications (e.g. as a Kubernetes sidecar).
To shell into the container for testing/debugging, use:
docker run -it -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1 /bin/bash
Run STLink as a standalone container, replacing 4.0.1 with latest or a specific, tagged version number:
docker run -d -p 10479:10479 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1
The container will:
To explicitly specify the platform:
# For AMD64/x86_64
docker run -d -p 10479:10479 --platform linux/amd64 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1
# For ARM64
docker run -d -p 10479:10479 --platform linux/arm64 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1
Deploy STLink as a sidecar container alongside your application (skeleton shown below):
Important note: a PersistentVolumeClaim on /opt/Xiid inside the STLink container is required to persist STLink data.
For binding-only STLink deployments (e.g., consumer-only or end-user-only endpoints), this is not required
and the STLink will remain ephemeral.
For STLinks that have mappings (i.e., are serving resources), this is required, as without persistence,
the STLink will be lost if the container is torn down and recreated, breaking connectivity with any resources
that were mapped to this STLink.
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: stlink-opt-xiid
spec:
accessModes:
- ReadWriteOnce
storageClassName: gp2 # Change this to your cluster's block storage class
resources:
requests:
storage: 1Gi
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
name: stlink-xdg-xiid
spec:
accessModes:
- ReadWriteOnce
storageClassName: gp2 # Change this to your cluster's block storage class
resources:
requests:
storage: 5Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-application
spec:
replicas: 1
strategy:
type: Recreate # Ensures the PVC is released before the new pod starts
selector:
matchLabels:
app: my-application
template:
metadata:
labels:
app: my-application
spec:
containers:
- name: xiid-stlink
image: xiidcorporation/stlink:latest
securityContext:
capabilities:
add:
- NET_ADMIN
startupProbe:
tcpSocket:
port: 10479
periodSeconds: 5
failureThreshold: 12
env:
- name: XIID_ACTIVATION_CODE
value: #<- Insert your STLink Activation Code here
volumeMounts:
- name: stlink-opt-xiid
mountPath: /opt/Xiid
- name: stlink-xdg-xiid
mountPath: /etc/xdg/Xiid
- name: my-application
image: your-application:latest
ports:
- containerPort: 80
volumes:
- name: stlink-opt-xiid
persistentVolumeClaim:
claimName: stlink-opt-xiid
- name: stlink-xdg-xiid
persistentVolumeClaim:
claimName: stlink-xdg-xiid
The startup probe ensures STLink is fully initialized. If you'd like, you can prevent other container(s) from starting
until the STLink is active and your services are reachable via SealedTunnel using initContainers:
initContainers:
- name: xiid-stlink
image: xiidcorporation/stlink:latest
restartPolicy: Always
securityContext:
capabilities:
add: [ "NET_ADMIN" ]
startupProbe: # Ensures STLink is ready before other containers start
exec:
command:
- sh
- -c
- "curl -sk --max-time 4 https://yourservice.acme.com" #<- Insert your service URL here
initialDelaySeconds: 20
periodSeconds: 10
failureThreshold: 30
env:
- name: XIID_ACTIVATION_CODE
value: #<- Insert your STLink Activation Code here
volumeMounts:
- name: opt-xiid
mountPath: /opt/Xiid
| Variable | Required | Description |
|---|---|---|
XIID_ACTIVATION_CODE | Yes | Your Xiid STLink activation code |
STLINK_PORT | No | (>= v4.0.2) The port the STLink service will bind to (defaults to 10479 if not specified) |
This image supports multiple architectures through multi-arch manifests:
linux/amd64 - x86_64 systemslinux/arm64 - ARM64/aarch64 systemsThe appropriate image will be automatically selected based on your system architecture.
NET_ADMIN capability in Kubernetes to enable binding to any address in the 127.0.0.0/8 range for STLink's dynamic loopback bindingsSTLink exposes a status endpoint for health monitoring:
https://localhost:10479/p1/statusTo debug or inspect the container:
docker run -it -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1 /bin/bash
For assistance with:
This container image includes Xiid STLink software. Use of this software requires a valid activation code and is subject to Xiid's licensing terms.
Content type
Image
Digest
sha256:92f587f25…
Size
109.5 MB
Last updated
6 months ago
docker pull xiidcorporation/stlink