mirror of
https://github.com/p1neappleXpress/OpenFlux.git
synced 2026-10-02 05:04:39 +08:00
One multi-stage image (golang:1.26-alpine -> alpine:3.22, CGO off) serving both roles via an env-driven entrypoint: - client: SOCKS5 proxy, no special privileges, published on 127.0.0.1:1080 - exit-node: raw sockets + the kernel-RST drop, confined to the container's network namespace (NET_RAW/NET_ADMIN via compose), so the iptables rule can never touch the host — the containerized variant of the scoped rule the README already recommends docker-compose.yml runs the two ends behind separate profiles; .env.example documents TRANSPORT (yandex|vyandex|oneme), DOC_URL, MAX_TOKEN/MAX_UID, etc.
30 lines
1.1 KiB
Docker
30 lines
1.1 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# OpenFlux (openflux) — one image, two roles:
|
|
# client — SOCKS5 proxy, no special privileges
|
|
# exit-node — raw sockets + RST-drop, needs NET_RAW/NET_ADMIN (see compose)
|
|
# Role is selected at runtime by the entrypoint from ROLE=client|exit-node.
|
|
|
|
FROM golang:1.26-alpine AS build
|
|
WORKDIR /src
|
|
|
|
# Cache module downloads across builds.
|
|
COPY go.mod go.sum ./
|
|
RUN --mount=type=cache,target=/go/pkg/mod \
|
|
go mod download
|
|
|
|
COPY . .
|
|
RUN --mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/root/.cache/go-build \
|
|
CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o /out/openflux .
|
|
|
|
FROM alpine:3.22
|
|
# ca-certificates: all transports are TLS (wss/https) to Yandex/MAX endpoints.
|
|
# iptables: the exit node must drop kernel RSTs inside its network namespace.
|
|
RUN apk add --no-cache ca-certificates iptables
|
|
|
|
COPY --from=build /out/openflux /usr/local/bin/openflux
|
|
COPY docker/entrypoint.sh /usr/local/bin/entrypoint.sh
|
|
RUN chmod +x /usr/local/bin/entrypoint.sh /usr/local/bin/openflux
|
|
|
|
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
|