2014-06-04 03:35:44 +00:00
|
|
|
# Original credit: https://github.com/jpetazzo/dockvpn
|
|
|
|
|
2016-02-11 17:10:51 +00:00
|
|
|
# Smallest base image
|
2016-06-24 20:53:45 +00:00
|
|
|
FROM alpine:3.4
|
2014-06-04 03:35:44 +00:00
|
|
|
|
|
|
|
MAINTAINER Kyle Manna <kyle@kylemanna.com>
|
|
|
|
|
2016-08-31 16:57:42 +00:00
|
|
|
RUN echo "http://dl-4.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \
|
|
|
|
apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam pamtester && \
|
2016-02-11 17:10:51 +00:00
|
|
|
ln -s /usr/share/easy-rsa/easyrsa /usr/local/bin && \
|
2016-08-31 16:57:42 +00:00
|
|
|
rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/*
|
|
|
|
|
|
|
|
COPY alpine /tmp/local
|
|
|
|
RUN adduser -D -G abuild abuild && \
|
|
|
|
chown -R abuild:abuild /tmp/local && \
|
|
|
|
apk add --update alpine-sdk && \
|
|
|
|
su -s /bin/bash -c 'cd /tmp/local/google-authenticator && abuild-keygen -a && abuild -Fr' abuild && \
|
|
|
|
cp /home/abuild/.abuild/abuild*.pub /etc/apk/keys/ && \
|
|
|
|
apk add /home/abuild/packages/local/x86_64/google-authenticator-20160207-r1.apk && \
|
|
|
|
apk del --purge --rdepends alpine-sdk && rm -rf /home/abuild && \
|
|
|
|
rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/*
|
|
|
|
|
2014-06-04 03:54:47 +00:00
|
|
|
|
2014-06-04 17:52:59 +00:00
|
|
|
# Needed by scripts
|
|
|
|
ENV OPENVPN /etc/openvpn
|
2016-02-11 17:10:51 +00:00
|
|
|
ENV EASYRSA /usr/share/easy-rsa
|
2014-06-04 17:52:59 +00:00
|
|
|
ENV EASYRSA_PKI $OPENVPN/pki
|
|
|
|
ENV EASYRSA_VARS_FILE $OPENVPN/vars
|
|
|
|
|
2014-06-04 04:10:55 +00:00
|
|
|
VOLUME ["/etc/openvpn"]
|
2014-06-04 03:54:47 +00:00
|
|
|
|
2015-06-22 05:55:16 +00:00
|
|
|
# Internally uses port 1194/udp, remap using `docker run -p 443:1194/tcp`
|
2014-06-04 16:30:04 +00:00
|
|
|
EXPOSE 1194/udp
|
2014-06-04 03:54:47 +00:00
|
|
|
|
2014-06-04 18:13:59 +00:00
|
|
|
CMD ["ovpn_run"]
|
|
|
|
|
|
|
|
ADD ./bin /usr/local/bin
|
2015-09-08 02:21:55 +00:00
|
|
|
RUN chmod a+x /usr/local/bin/*
|
2016-02-06 19:23:59 +00:00
|
|
|
|
|
|
|
# Add support for OTP authentication using a PAM module
|
2016-02-07 13:45:28 +00:00
|
|
|
ADD ./otp/openvpn /etc/pam.d/
|