# Docker and Container Deployment `nx9-wg` can be run in Docker with native Linux WireGuard performance while maintaining full isolation. --- ## 1. Docker Run Example ```bash docker run -d \ --name nx9-wg \ --restart unless-stopped \ --cap-add=NET_ADMIN \ --cap-add=NET_BIND_SERVICE \ -p 8080:8080 \ -p 51820:51820/udp \ -v nx9_data:/var/lib/nx9-wg \ -v /etc/nx9-wg:/etc/nx9-wg \ -e NX9_WG_ADMIN_PASSWORD="MyInitialSecurePassword123!" \ nx9/nx9-wg:latest ``` --- ## 2. Docker Compose Example (`docker-compose.yml`) ```yaml version: "3.8" services: nx9-wg: image: nx9/nx9-wg:latest container_name: nx9-wg restart: unless-stopped cap_add: - NET_ADMIN - NET_BIND_SERVICE ports: - "8080:8080" - "51820:51820/udp" volumes: - ./data:/var/lib/nx9-wg - ./config:/etc/nx9-wg - ./backups:/var/lib/nx9-wg/backups environment: - NX9_WG_LOG_LEVEL=info - NX9_WG_ADMIN_PASSWORD_FILE=/run/secrets/admin_password secrets: - admin_password healthcheck: test: ["CMD", "/usr/local/bin/nx9-wg", "system", "health"] interval: 30s timeout: 5s retries: 3 secrets: admin_password: file: ./secrets/admin_password.txt ``` --- ## Required Linux Capabilities - `CAP_NET_ADMIN`: Required to configure WireGuard interfaces, manage IP addresses, routing tables, and manipulate `inet nx9_wg` nftables rules. - `CAP_NET_BIND_SERVICE`: Allows binding to privileged network ports if needed. - Host Kernel: The host operating system must have the `wireguard` kernel module loaded (`modprobe wireguard`).