Files
ihasvpn/docker-compose.host.yml
jcoffey-dev 065a0905da Point image references at the new registry
ghcr.io went dark with the GitHub account, so every `docker pull` and
template that named it has been failing. The images are republished,
multi-arch as before, at registry.coffeylabs.org under the same names, and
pull anonymously -- nothing needs a login.

Where a link pointed at an issue list, it now goes to /-/work_items: in
GitLab 19 that is the public list, and /-/issues returns 404 to anyone not
signed in. Issues themselves did not come across from GitHub, so a link to
a specific old issue is replaced with a note saying where it was.
2026-09-20 22:49:14 -07:00

38 lines
1.5 KiB
YAML

# ihasvpn on the host network: the fastest way to run it.
#
# With `network_mode: host` the WireGuard socket sits directly on the host's
# interfaces. There is no port mapping, no conntrack entry per client packet
# and no second NAT hop, which is worth a few percent of throughput and a
# little latency on a busy server. The trade-offs: wg0 is created in the
# host's namespace (you will see it in `ip link` and it is removed on
# shutdown), the NAT rules land in the host's nftables as a table named
# `ihasvpn`, and the admin UI listens on the host directly -- so it is bound to
# localhost below. Put a reverse proxy in front of it or set
# IHASVPN_TLS_SELF_SIGNED to reach it from elsewhere.
services:
ihasvpn:
image: registry.coffeylabs.org/coffey-labs/ihasvpn:latest
container_name: ihasvpn
restart: unless-stopped
network_mode: host
cap_add:
- NET_ADMIN
environment:
IHASVPN_ENDPOINT: vpn.example.com
IHASVPN_PORT: "51820"
IHASVPN_SUBNET: 10.8.0.0/24
IHASVPN_DNS: 1.1.1.1, 1.0.0.1
IHASVPN_HTTP_LISTEN: "127.0.0.1:51821"
# In host mode the forwarding sysctls are the host's own; ihasvpn sets
# them itself since it has NET_ADMIN, but if you prefer to own them
# add `net.ipv4.ip_forward = 1` to /etc/sysctl.d/ and turn this off.
# IHASVPN_MANAGE_SYSCTL: "false"
# Pick the interface to masquerade on if auto-detection picks the
# wrong one (it uses the default route).
# IHASVPN_EGRESS_INTERFACE: eth0
volumes:
- ihasvpn-data:/data
volumes:
ihasvpn-data: