{"id":21698614,"url":"https://github.com/theohbrothers/docker-openvpn","last_synced_at":"2025-10-29T12:02:27.952Z","repository":{"id":46029395,"uuid":"249625561","full_name":"theohbrothers/docker-openvpn","owner":"theohbrothers","description":"Dockerized openvpn 🐳","archived":false,"fork":false,"pushed_at":"2024-07-27T14:02:58.000Z","size":211,"stargazers_count":1,"open_issues_count":0,"forks_count":1,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-01-25T14:29:07.535Z","etag":null,"topics":["buildx","docker","generate-dockerimagevariants","openvpn"],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/theohbrothers.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-03-24T05:59:14.000Z","updated_at":"2024-07-29T18:51:05.000Z","dependencies_parsed_at":"2024-03-02T18:41:34.111Z","dependency_job_id":"1c64cf50-9ced-48a2-a4e7-98a1d28a7b3b","html_url":"https://github.com/theohbrothers/docker-openvpn","commit_stats":null,"previous_names":[],"tags_count":23,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/theohbrothers%2Fdocker-openvpn","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/theohbrothers%2Fdocker-openvpn/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/theohbrothers%2Fdocker-openvpn/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/theohbrothers%2Fdocker-openvpn/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/theohbrothers","download_url":"https://codeload.github.com/theohbrothers/docker-openvpn/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":244637369,"owners_count":20485499,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["buildx","docker","generate-dockerimagevariants","openvpn"],"created_at":"2024-11-25T19:35:31.343Z","updated_at":"2025-10-29T12:02:27.947Z","avatar_url":"https://github.com/theohbrothers.png","language":"Shell","funding_links":[],"categories":[],"sub_categories":[],"readme":"# docker-openvpn\n\n[![github-actions](https://github.com/theohbrothers/docker-openvpn/actions/workflows/ci-master-pr.yml/badge.svg?branch=master)](https://github.com/theohbrothers/docker-openvpn/actions/workflows/ci-master-pr.yml)\n[![github-release](https://img.shields.io/github/v/release/theohbrothers/docker-openvpn?style=flat-square)](https://github.com/theohbrothers/docker-openvpn/releases/)\n[![docker-image-size](https://img.shields.io/docker/image-size/theohbrothers/docker-openvpn/latest)](https://hub.docker.com/r/theohbrothers/docker-openvpn)\n\nDockerized `openvpn`.\n\n`easy-rsa` is not included, since is not best practice to be signing or be able to sign certs on the server. it is better to run [`easy-rsa`](https://github.com/theohbrothers/docker-easyrsa) in a separate container.\n\n## Tags\n\n| Tag | Dockerfile Build Context |\n|:-------:|:---------:|\n| `:2.6.14-alpine-3.22`, `:latest` | [View](variants/2.6.14-alpine-3.22) |\n| `:2.6.11-alpine-3.18` | [View](variants/2.6.11-alpine-3.18) |\n| `:2.5.10-alpine-3.17` | [View](variants/2.5.10-alpine-3.17) |\n| `:2.4.12-alpine-3.12` | [View](variants/2.4.12-alpine-3.12) |\n| `:2.4.11-alpine-3.11` | [View](variants/2.4.11-alpine-3.11) |\n| `:2.4.11-alpine-3.10` | [View](variants/2.4.11-alpine-3.10) |\n| `:2.4.6-alpine-3.9` | [View](variants/2.4.6-alpine-3.9) |\n| `:2.4.6-alpine-3.8` | [View](variants/2.4.6-alpine-3.8) |\n| `:2.4.4-alpine-3.7` | [View](variants/2.4.4-alpine-3.7) |\n| `:2.4.4-alpine-3.6` | [View](variants/2.4.4-alpine-3.6) |\n| `:2.3.18-alpine-3.5` | [View](variants/2.3.18-alpine-3.5) |\n| `:2.3.18-alpine-3.4` | [View](variants/2.3.18-alpine-3.4) |\n| `:2.3.18-alpine-3.3` | [View](variants/2.3.18-alpine-3.3) |\n\n## Usage\n\nIt is assumed that you have knowledge of configuring `openvpn`. If needed, refer to the official manuals:\n\n- [Openvpn 2.3 manual](https://openvpn.net/community-resources/reference-manual-for-openvpn-2-3/)\n- [Openvpn 2.4 manual](https://openvpn.net/community-resources/reference-manual-for-openvpn-2-4/)\n- [Openvpn 2.5 manual](https://openvpn.net/community-resources/reference-manual-for-openvpn-2-5/)\n- [Openvpn 2.6 manual](https://openvpn.net/community-resources/reference-manual-for-openvpn-2-6/)\n\nTo run the image, at the least you should mount a `/etc/openvpn/server.conf`, which may be a unified openvpn profile (see INLINE FILE SUPPORT section in the [openvpn manual](https://community.openvpn.net/openvpn/wiki/Openvpn24ManPage)).\n\n```sh\ndocker run --rm -it --cap-add NET_ADMIN -v /path/to/server.conf:/etc/openvpn/server.conf theohbrothers/docker-openvpn:2.6.14-alpine-3.22\n```\n\n## Environment variables\n\nThe defaults should work, so that there should be no need to specify any environment variable when running the container.\n\n| Environment variables | Description | Default Value |\n|:-------:|:-------:|:-------:|\n| `OPENVPN_CONFIG_FILE` | Absolute path to the server config | `/etc/openvpn/server.conf` |\n| `OPENVPN_ROUTES` | Space-delimited CIDRs to add iptables `POSTROUTING` `MASQUERADE` rules, performed only when `NAT=1` and `NAT_MASQUERADE=1` | `192.168.50.0/24 192.168.51.0/24` |\n| `NAT` | Whether to use NAT. `0` to disable. `1` to enable. | `1` |\n| `NAT_INTERFACE` | Interface on which to use NAT. E.g. `eth0` | `eth0` |\n| `NAT_MASQUERADE` | Whether to add iptables `POSTROUTING` `MASQUERADE` rules, if `NAT=1`. `0` to disable. `1` to enable. Disable this if running as a client. | `1` |\n| `CUSTOM_FIREWALL_SCRIPT` | Full path to a custom script for firewall. If present, this script is executed before any other `iptables` rules are provisioned | `/etc/openvpn/firewall.sh` |\n\n## `docker-entrypoint.sh`\n\nThe entrypoint script performs (in order):\n\n1. Normalize environment variables\n1. Provision the `tun` device\n1. Execute the `CUSTOM_FIREWALL_SCRIPT` if it exists\n1. Provision a `NAT` POSTROUTING iptables rule for tunnel-to-world packets\n1. Provision a `NAT` POSTROUTING iptables rule each entry in `OPENVPN_ROUTES`\n1. List iptables\n1. Generate the final `openvpn` command line\n\n## IPv4 and IPv6 forwarding\n\nIf not already enabled on the host, ipv4 and ipv6 forwarding may be enabled at container runtime by using the [`sysctls` key in `docker-compose.yml`](https://docs.docker.com/compose/compose-file/compose-file-v2/#sysctls), or with [`--sysctl` flag in `docker-run`](https://docs.docker.com/engine/reference/commandline/run/#/configure-namespaced-kernel-parameters-sysctls-at-runtime#configure-namespaced-kernel-parameters-sysctls-at-runtime)\n\n## Development\n\nRequires Windows `powershell` or [`pwsh`](https://github.com/PowerShell/PowerShell).\n\n```powershell\n# Install Generate-DockerImageVariants module: https://github.com/theohbrothers/Generate-DockerImageVariants\nInstall-Module -Name Generate-DockerImageVariants -Repository PSGallery -Scope CurrentUser -Force -Verbose\n\n# Edit ./generate templates\n\n# Generate the variants\nGenerate-DockerImageVariants .\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftheohbrothers%2Fdocker-openvpn","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftheohbrothers%2Fdocker-openvpn","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftheohbrothers%2Fdocker-openvpn/lists"}