Files
Maks Kukarin b2da6daf33 Add Docker image and compose for local client / exit-node runs
One multi-stage image (golang:1.26-alpine -> alpine:3.22, CGO off) serving
both roles via an env-driven entrypoint:

- client: SOCKS5 proxy, no special privileges, published on 127.0.0.1:1080
- exit-node: raw sockets + the kernel-RST drop, confined to the container's
  network namespace (NET_RAW/NET_ADMIN via compose), so the iptables rule
  can never touch the host — the containerized variant of the scoped rule
  the README already recommends

docker-compose.yml runs the two ends behind separate profiles; .env.example
documents TRANSPORT (yandex|vyandex|oneme), DOC_URL, MAX_TOKEN/MAX_UID, etc.
2026-09-12 14:22:08 +05:00

30 lines
1.1 KiB
Docker

# syntax=docker/dockerfile:1
# OpenFlux (openflux) — one image, two roles:
# client — SOCKS5 proxy, no special privileges
# exit-node — raw sockets + RST-drop, needs NET_RAW/NET_ADMIN (see compose)
# Role is selected at runtime by the entrypoint from ROLE=client|exit-node.
FROM golang:1.26-alpine AS build
WORKDIR /src
# Cache module downloads across builds.
COPY go.mod go.sum ./
RUN --mount=type=cache,target=/go/pkg/mod \
go mod download
COPY . .
RUN --mount=type=cache,target=/go/pkg/mod \
--mount=type=cache,target=/root/.cache/go-build \
CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /out/openflux .
FROM alpine:3.22
# ca-certificates: all transports are TLS (wss/https) to Yandex/MAX endpoints.
# iptables: the exit node must drop kernel RSTs inside its network namespace.
RUN apk add --no-cache ca-certificates iptables
COPY --from=build /out/openflux /usr/local/bin/openflux
COPY docker/entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh /usr/local/bin/openflux
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]