Files
nx9-wg/docs/docker.md
T
thakaresandCopilot 2ac6c81dfe cli: avoid data-dir initialization for version; create db parent dirs; redact generated passwords in CLI output
- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization.
- Create parent directories when an explicit --database path is provided.
- Redact printed generated administrator passwords; announce file path or redact instead.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-08-16 16:26:24 +05:30

1.6 KiB

Docker and Container Deployment

nx9-wg can be run in Docker with native Linux WireGuard performance while maintaining full isolation.


1. Docker Run Example

docker run -d \
  --name nx9-wg \
  --restart unless-stopped \
  --cap-add=NET_ADMIN \
  --cap-add=NET_BIND_SERVICE \
  -p 8080:8080 \
  -p 51820:51820/udp \
  -v nx9_data:/var/lib/nx9-wg \
  -v /etc/nx9-wg:/etc/nx9-wg \
  -e NX9_WG_ADMIN_PASSWORD="MyInitialSecurePassword123!" \
  nx9/nx9-wg:latest

2. Docker Compose Example (docker-compose.yml)

version: "3.8"

services:
  nx9-wg:
    image: nx9/nx9-wg:latest
    container_name: nx9-wg
    restart: unless-stopped
    cap_add:
      - NET_ADMIN
      - NET_BIND_SERVICE
    ports:
      - "8080:8080"
      - "51820:51820/udp"
    volumes:
      - ./data:/var/lib/nx9-wg
      - ./config:/etc/nx9-wg
      - ./backups:/var/lib/nx9-wg/backups
    environment:
      - NX9_WG_LOG_LEVEL=info
      - NX9_WG_ADMIN_PASSWORD_FILE=/run/secrets/admin_password
    secrets:
      - admin_password
    healthcheck:
      test: ["CMD", "/usr/local/bin/nx9-wg", "system", "health"]
      interval: 30s
      timeout: 5s
      retries: 3

secrets:
  admin_password:
    file: ./secrets/admin_password.txt

Required Linux Capabilities

  • CAP_NET_ADMIN: Required to configure WireGuard interfaces, manage IP addresses, routing tables, and manipulate inet nx9_wg nftables rules.
  • CAP_NET_BIND_SERVICE: Allows binding to privileged network ports if needed.
  • Host Kernel: The host operating system must have the wireguard kernel module loaded (modprobe wireguard).