One multi-stage image (golang:1.26-alpine -> alpine:3.22, CGO off) serving
both roles via an env-driven entrypoint:
- client: SOCKS5 proxy, no special privileges, published on 127.0.0.1:1080
- exit-node: raw sockets + the kernel-RST drop, confined to the container's
network namespace (NET_RAW/NET_ADMIN via compose), so the iptables rule
can never touch the host — the containerized variant of the scoped rule
the README already recommends
docker-compose.yml runs the two ends behind separate profiles; .env.example
documents TRANSPORT (yandex|vyandex|oneme), DOC_URL, MAX_TOKEN/MAX_UID, etc.