68 lines
1.6 KiB
Markdown
68 lines
1.6 KiB
Markdown
# Docker and Container Deployment
|
|
|
|
`nx9-wg` can be run in Docker with native Linux WireGuard performance while maintaining full isolation.
|
|
|
|
---
|
|
|
|
## 1. Docker Run Example
|
|
|
|
```bash
|
|
docker run -d \
|
|
--name nx9-wg \
|
|
--restart unless-stopped \
|
|
--cap-add=NET_ADMIN \
|
|
--cap-add=NET_BIND_SERVICE \
|
|
-p 8080:8080 \
|
|
-p 51820:51820/udp \
|
|
-v nx9_data:/var/lib/nx9-wg \
|
|
-v /etc/nx9-wg:/etc/nx9-wg \
|
|
-e NX9_WG_ADMIN_PASSWORD="MyInitialSecurePassword123!" \
|
|
nx9/nx9-wg:latest
|
|
```
|
|
|
|
---
|
|
|
|
## 2. Docker Compose Example (`docker-compose.yml`)
|
|
|
|
```yaml
|
|
version: "3.8"
|
|
|
|
services:
|
|
nx9-wg:
|
|
image: nx9/nx9-wg:latest
|
|
container_name: nx9-wg
|
|
restart: unless-stopped
|
|
cap_add:
|
|
- NET_ADMIN
|
|
- NET_BIND_SERVICE
|
|
ports:
|
|
- "8080:8080"
|
|
- "51820:51820/udp"
|
|
volumes:
|
|
- ./data:/var/lib/nx9-wg
|
|
- ./config:/etc/nx9-wg
|
|
- ./backups:/var/lib/nx9-wg/backups
|
|
environment:
|
|
- NX9_WG_LOG_LEVEL=info
|
|
- NX9_WG_ADMIN_PASSWORD_FILE=/run/secrets/admin_password
|
|
secrets:
|
|
- admin_password
|
|
healthcheck:
|
|
test: ["CMD", "/usr/local/bin/nx9-wg", "system", "health"]
|
|
interval: 30s
|
|
timeout: 5s
|
|
retries: 3
|
|
|
|
secrets:
|
|
admin_password:
|
|
file: ./secrets/admin_password.txt
|
|
```
|
|
|
|
---
|
|
|
|
## Required Linux Capabilities
|
|
|
|
- `CAP_NET_ADMIN`: Required to configure WireGuard interfaces, manage IP addresses, routing tables, and manipulate `inet nx9_wg` nftables rules.
|
|
- `CAP_NET_BIND_SERVICE`: Allows binding to privileged network ports if needed.
|
|
- Host Kernel: The host operating system must have the `wireguard` kernel module loaded (`modprobe wireguard`).
|