diff --git a/Dockerfile b/Dockerfile index a85cb24b..82943715 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,10 +1,13 @@ # Original credit: https://github.com/jpetazzo/dockvpn +# Forked from https://github.com/kylemanna/docker-openvpn # Smallest base image + FROM alpine:latest LABEL maintainer="Kyle Manna " + # Testing: pamtester RUN echo "http://dl-cdn.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \ apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam google-authenticator pamtester && \ diff --git a/Dockerfile.arm32v6 b/Dockerfile.arm32v6 new file mode 100644 index 00000000..41e8bcdd --- /dev/null +++ b/Dockerfile.arm32v6 @@ -0,0 +1,34 @@ +# Original credit: https://github.com/jpetazzo/dockvpn + +# Smallest base image +FROM arm32v6/alpine:latest + +LABEL maintainer="Kyle Manna " + +# Testing: pamtester +RUN echo "http://dl-cdn.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \ + apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam google-authenticator pamtester && \ + ln -s /usr/share/easy-rsa/easyrsa /usr/local/bin && \ + rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/* + +# Needed by scripts +ENV OPENVPN /etc/openvpn +ENV EASYRSA /usr/share/easy-rsa +ENV EASYRSA_PKI $OPENVPN/pki +ENV EASYRSA_VARS_FILE $OPENVPN/vars + +# Prevents refused client connection because of an expired CRL +ENV EASYRSA_CRL_DAYS 3650 + +VOLUME ["/etc/openvpn"] + +# Internally uses port 1194/udp, remap using `docker run -p 443:1194/tcp` +EXPOSE 1194/udp + +CMD ["ovpn_run"] + +ADD ./bin /usr/local/bin +RUN chmod a+x /usr/local/bin/* + +# Add support for OTP authentication using a PAM module +ADD ./otp/openvpn /etc/pam.d/