Files
OpenFlux/docker-compose.yml
Maks Kukarin b2da6daf33 Add Docker image and compose for local client / exit-node runs
One multi-stage image (golang:1.26-alpine -> alpine:3.22, CGO off) serving
both roles via an env-driven entrypoint:

- client: SOCKS5 proxy, no special privileges, published on 127.0.0.1:1080
- exit-node: raw sockets + the kernel-RST drop, confined to the container's
  network namespace (NET_RAW/NET_ADMIN via compose), so the iptables rule
  can never touch the host — the containerized variant of the scoped rule
  the README already recommends

docker-compose.yml runs the two ends behind separate profiles; .env.example
documents TRANSPORT (yandex|vyandex|oneme), DOC_URL, MAX_TOKEN/MAX_UID, etc.
2026-09-12 14:22:08 +05:00

50 lines
1.6 KiB
YAML

# OpenFlux local runner. One image, two mutually independent services —
# the two ends never talk to each other directly; they meet on the transport
# channel (the Yandex doc / the MAX call). Start only the end you need:
#
# docker compose --profile client up -d --build # SOCKS5 on 127.0.0.1:1080
# docker compose --profile exit-node up -d --build
#
# Configure via .env (see .env.example) or inline env vars:
# DOC_URL=... MAX_TOKEN=... MAX_UID=... TRANSPORT=vyandex docker compose --profile client up -d
#
# Privileges, deliberately asymmetric:
# client — none. It dials out like a browser and serves SOCKS5 locally.
# exit-node — NET_RAW (raw sockets) + NET_ADMIN (the RST-drop rule), confined
# to this container's netns; the rule can never touch the host.
services:
client:
build: .
image: openflux:local
restart: unless-stopped
profiles: [client]
environment:
ROLE: client
TRANSPORT: ${TRANSPORT:-yandex}
URL: ${DOC_URL:-}
MAX_TOKEN: ${MAX_TOKEN:-}
MAX_UID: ${MAX_UID:-}
SOCKS5_LISTEN: ${SOCKS5_LISTEN:-:1080}
DEBUG: ${DEBUG:-0}
# No auth on the SOCKS5 server — keep it bound to the host loopback only.
ports:
- "127.0.0.1:1080:1080"
exit-node:
build: .
image: openflux:local
restart: unless-stopped
profiles: [exit-node]
environment:
ROLE: exit-node
TRANSPORT: ${TRANSPORT:-yandex}
URL: ${DOC_URL:-}
MAX_TOKEN: ${MAX_TOKEN:-}
MAX_UID: ${MAX_UID:-}
LOCAL_IP: ${EXIT_LOCAL_IP:-}
DEBUG: ${DEBUG:-0}
cap_add:
- NET_RAW
- NET_ADMIN