|
2 | 2 |
|
3 | 3 | * Add a new service in docker-compose.yml
|
4 | 4 |
|
5 |
| - version: '2' |
6 |
| - services: |
7 |
| - openvpn: |
8 |
| - cap_add: |
9 |
| - - NET_ADMIN |
10 |
| - image: kylemanna/openvpn |
11 |
| - ports: |
12 |
| - - "1194:1194/udp" |
13 |
| - restart: always |
14 |
| - volumes: |
15 |
| - - ./openvpn/conf:/etc/openvpn |
| 5 | +```yaml |
| 6 | +version: '2' |
| 7 | +services: |
| 8 | + openvpn: |
| 9 | + cap_add: |
| 10 | + - NET_ADMIN |
| 11 | + image: kylemanna/openvpn |
| 12 | + container_name: openvpn |
| 13 | + ports: |
| 14 | + - "1194:1194/udp" |
| 15 | + restart: always |
| 16 | + volumes: |
| 17 | + - ./openvpn-data/conf:/etc/openvpn |
| 18 | +``` |
| 19 | +
|
16 | 20 |
|
17 | 21 | * Initialize the configuration files and certificates
|
18 | 22 |
|
19 |
| - docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM |
20 |
| - docker-compose run --rm openvpn ovpn_initpki |
21 |
| - |
| 23 | +```bash |
| 24 | +docker-compose run --rm openvpn ovpn_genconfig -u udp://VPN.SERVERNAME.COM |
| 25 | +docker-compose run --rm openvpn ovpn_initpki |
| 26 | +``` |
| 27 | + |
22 | 28 | * Fix ownership (depending on how to handle your backups, this may not be needed)
|
23 | 29 |
|
24 |
| - sudo chown -R $(whoami): ./openvpn |
| 30 | +```bash |
| 31 | +sudo chown -R $(whoami): ./openvpn-data |
| 32 | +``` |
25 | 33 |
|
26 | 34 | * Start OpenVPN server process
|
27 | 35 |
|
28 |
| - docker-compose up -d openvpn |
| 36 | +```bash |
| 37 | +docker-compose up -d openvpn |
| 38 | +``` |
| 39 | + |
| 40 | +* You can access the container logs with |
| 41 | + |
| 42 | +```bash |
| 43 | +docker-compose logs -f |
| 44 | +``` |
29 | 45 |
|
30 |
| -* Generate a client certificate without a passphrase |
| 46 | +* Generate a client certificate |
31 | 47 |
|
32 |
| - docker-compose run --rm openvpn easyrsa build-client-full CLIENTNAME nopass |
| 48 | +```bash |
| 49 | +export CLIENTNAME="your_client_name" |
| 50 | +# with a passphrase (recommended) |
| 51 | +docker-compose exec openvpn easyrsa build-client-full $CLIENTNAME |
| 52 | +# without a passphrase (not recommended) |
| 53 | +docker-compose exec openvpn easyrsa build-client-full $CLIENTNAME nopass |
| 54 | +``` |
33 | 55 |
|
34 | 56 | * Retrieve the client configuration with embedded certificates
|
35 | 57 |
|
36 |
| - docker-compose run --rm openvpn ovpn_getclient CLIENTNAME > CLIENTNAME.ovpn |
| 58 | +```bash |
| 59 | +docker-compose exec openvpn ovpn_getclient $CLIENTNAME > $CLIENTNAME.ovpn |
| 60 | +``` |
37 | 61 |
|
38 | 62 | ## Debugging Tips
|
39 | 63 |
|
40 | 64 | * Create an environment variable with the name DEBUG and value of 1 to enable debug output (using "docker -e").
|
41 | 65 |
|
42 |
| - docker-compose run -e DEBUG=1 openvpn |
| 66 | +```bash |
| 67 | +docker-compose run -e DEBUG=1 openvpn |
| 68 | +``` |
0 commit comments