Sign inSign up

xiidcorporation/stlink

By xiidcorporation

•Updated about 2 months ago

Xiid's STLink enables Terniion SealedTunnel connections and enforces which processes can connect

Image
0

1.6K

xiidcorporation/stlink repository overview

A production-ready containerized deployment of Xiid STLink for Linux, supporting both AMD64 (x86_64) and ARM64 architectures. This image provides a seamless way to run STLink in containerized environments including Docker, Podman, and Kubernetes.

⁠Quick Start

docker run -d -p 10479:10479 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:latest

Replace your_activation_code_here with your valid Xiid STLink activation code.

You can access the STLink Portal at exposed port 10479 (HTTPS).

This container is meant to be used alongside other applications (e.g. as a Kubernetes sidecar).

To shell into the container for testing/debugging, use:

docker run -it -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1 /bin/bash

⁠Prerequisites

  • Activation Code: A valid Xiid STLink activation code from an Xiid Commander is required to run this container. Contact Xiid for additional assistance.
  • Container Runtime: Docker, Podman, or any OCI-compatible container runtime
  • Architecture: AMD64 (x86_64) or ARM64 (aarch64)

⁠Usage

⁠Basic Deployment

Run STLink as a standalone container, replacing 4.0.1 with latest or a specific, tagged version number:

docker run -d -p 10479:10479 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1

The container will:

  • Automatically detect your system architecture
  • Install and activate STLink with your provided activation code
  • Start the STLink service
  • (>= v4.0.2) Upgrade the STLink if already activated with the same code
⁠Specifying Architecture

To explicitly specify the platform:

# For AMD64/x86_64
docker run -d -p 10479:10479 --platform linux/amd64 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1

# For ARM64
docker run -d -p 10479:10479 --platform linux/arm64 -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1
⁠Kubernetes Deployment

Deploy STLink as a sidecar container alongside your application (skeleton shown below):

Important note: a PersistentVolumeClaim on /opt/Xiid inside the STLink container is required to persist STLink data. For binding-only STLink deployments (e.g., consumer-only or end-user-only endpoints), this is not required and the STLink will remain ephemeral. For STLinks that have mappings (i.e., are serving resources), this is required, as without persistence, the STLink will be lost if the container is torn down and recreated, breaking connectivity with any resources that were mapped to this STLink.

apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: stlink-opt-xiid
spec:
  accessModes:
    - ReadWriteOnce
  storageClassName: gp2  # Change this to your cluster's block storage class
  resources:
    requests:
      storage: 1Gi
---
apiVersion: v1
kind: PersistentVolumeClaim
metadata:
  name: stlink-xdg-xiid
spec:
  accessModes:
    - ReadWriteOnce
  storageClassName: gp2  # Change this to your cluster's block storage class
  resources:
    requests:
      storage: 5Gi
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-application
spec:
  replicas: 1
  strategy:
    type: Recreate  # Ensures the PVC is released before the new pod starts
  selector:
    matchLabels:
      app: my-application
  template:
    metadata:
      labels:
        app: my-application
    spec:
      containers:
        - name: xiid-stlink
          image: xiidcorporation/stlink:latest
          securityContext:
            capabilities:
              add:
                - NET_ADMIN
          startupProbe:
            tcpSocket:
              port: 10479
            periodSeconds: 5
            failureThreshold: 12
          env:
            - name: XIID_ACTIVATION_CODE
              value: #<- Insert your STLink Activation Code here
          volumeMounts:
            - name: stlink-opt-xiid
              mountPath: /opt/Xiid
            - name: stlink-xdg-xiid
              mountPath: /etc/xdg/Xiid
        - name: my-application
          image: your-application:latest
          ports:
            - containerPort: 80
      volumes:
        - name: stlink-opt-xiid
          persistentVolumeClaim:
            claimName: stlink-opt-xiid
        - name: stlink-xdg-xiid
          persistentVolumeClaim:
            claimName: stlink-xdg-xiid

The startup probe ensures STLink is fully initialized. If you'd like, you can prevent other container(s) from starting until the STLink is active and your services are reachable via SealedTunnel using initContainers:

initContainers:
- name: xiid-stlink
  image: xiidcorporation/stlink:latest
  restartPolicy: Always
  securityContext:
    capabilities:
      add: [ "NET_ADMIN" ]
  startupProbe: # Ensures STLink is ready before other containers start
    exec:
      command:
        - sh
        - -c
        - "curl -sk --max-time 4 https://yourservice.acme.com" #<- Insert your service URL here
    initialDelaySeconds: 20
    periodSeconds: 10
    failureThreshold: 30
  env:
    - name: XIID_ACTIVATION_CODE
      value: #<- Insert your STLink Activation Code here
  volumeMounts:
    - name: opt-xiid
      mountPath: /opt/Xiid

⁠Environment Variables

VariableRequiredDescription
XIID_ACTIVATION_CODEYesYour Xiid STLink activation code
STLINK_PORTNo(>= v4.0.2) The port the STLink service will bind to (defaults to 10479 if not specified)

⁠Supported Architectures

This image supports multiple architectures through multi-arch manifests:

  • linux/amd64 - x86_64 systems
  • linux/arm64 - ARM64/aarch64 systems

The appropriate image will be automatically selected based on your system architecture.

⁠Technical Details

  • Base Image: Red Hat Universal Base Image 9 (UBI9)
  • Service Port: 10479 (HTTPS)
  • Installation: Automatic on first run or when activation code changes
  • Persistence: Activation state is maintained across container restarts
  • Root Privileges: Not required on the host system
  • Network Requirements: Requires NET_ADMIN capability in Kubernetes to enable binding to any address in the 127.0.0.0/8 range for STLink's dynamic loopback bindings

⁠Health Checks

STLink exposes a status endpoint for health monitoring:

  • Endpoint: https://localhost:10479/p1/status
  • Protocol: HTTPS
  • Use Case: Kubernetes startup/liveness probes, monitoring systems, enumerating active STLink mappings/bindings, etc.

⁠Troubleshooting

⁠Interactive Shell Access

To debug or inspect the container:

docker run -it -e XIID_ACTIVATION_CODE=your_activation_code_here xiidcorporation/stlink:4.0.1 /bin/bash

⁠Support

For assistance with:

  • Activation codes: Contact Xiid support or your Xiid sales representative
  • Container issues: Check container logs and verify environment variables
  • Kubernetes deployment: Review the example YAML configuration

⁠License

This container image includes Xiid STLink software. Use of this software requires a valid activation code and is subject to Xiid's licensing terms.

⁠Security

  • The container can run without requiring root privileges on the host (e.g., using rootless Podman)
  • Activation codes should be managed securely
  • HTTPS is used for all STLink service communications

Tag summary

Content type

Image

Digest

sha256:92f587f25…

Size

109.5 MB

Last updated

6 months ago

docker pull xiidcorporation/stlink