2014-06-03 20:35:44 -07:00
|
|
|
# Original credit: https://github.com/jpetazzo/dockvpn
|
|
|
|
|
2016-02-11 18:10:51 +01:00
|
|
|
# Smallest base image
|
2017-05-26 12:25:43 -07:00
|
|
|
FROM alpine:latest
|
2014-06-03 20:35:44 -07:00
|
|
|
|
2017-10-31 20:12:28 -07:00
|
|
|
LABEL maintainer="Kyle Manna <kyle@kylemanna.com>"
|
2014-06-03 20:35:44 -07:00
|
|
|
|
2017-05-11 11:19:39 -07:00
|
|
|
# Testing: pamtester
|
2017-05-17 09:27:30 -07:00
|
|
|
RUN echo "http://dl-cdn.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \
|
2016-09-02 21:57:23 -07:00
|
|
|
apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam google-authenticator pamtester && \
|
2016-02-11 18:10:51 +01:00
|
|
|
ln -s /usr/share/easy-rsa/easyrsa /usr/local/bin && \
|
2016-08-31 09:57:42 -07:00
|
|
|
rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/*
|
|
|
|
|
2014-06-04 10:52:59 -07:00
|
|
|
# Needed by scripts
|
|
|
|
ENV OPENVPN /etc/openvpn
|
2016-02-11 18:10:51 +01:00
|
|
|
ENV EASYRSA /usr/share/easy-rsa
|
2014-06-04 10:52:59 -07:00
|
|
|
ENV EASYRSA_PKI $OPENVPN/pki
|
|
|
|
ENV EASYRSA_VARS_FILE $OPENVPN/vars
|
|
|
|
|
2017-06-17 13:01:24 +02:00
|
|
|
# Prevents refused client connection because of an expired CRL
|
|
|
|
ENV EASYRSA_CRL_DAYS 3650
|
|
|
|
|
2014-06-03 21:10:55 -07:00
|
|
|
VOLUME ["/etc/openvpn"]
|
2014-06-03 20:54:47 -07:00
|
|
|
|
2015-06-21 22:55:16 -07:00
|
|
|
# Internally uses port 1194/udp, remap using `docker run -p 443:1194/tcp`
|
2014-06-04 09:30:04 -07:00
|
|
|
EXPOSE 1194/udp
|
2014-06-03 20:54:47 -07:00
|
|
|
|
2014-06-04 11:13:59 -07:00
|
|
|
CMD ["ovpn_run"]
|
|
|
|
|
|
|
|
ADD ./bin /usr/local/bin
|
2015-09-07 19:21:55 -07:00
|
|
|
RUN chmod a+x /usr/local/bin/*
|
2016-02-06 20:23:59 +01:00
|
|
|
|
|
|
|
# Add support for OTP authentication using a PAM module
|
2016-02-07 14:45:28 +01:00
|
|
|
ADD ./otp/openvpn /etc/pam.d/
|