Files
iclaoudezinandClaude Sonnet 5.5 5de0501cbc Compose: require JWT secret, seed admin via env, stop publishing internal ports
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
  APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
  host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:14:22 +00:00

2.1 KiB

Deployment: Docker

Uses docker-compose.yml from the repository root.

Services

Service Container Ports Notes
app-ui ovp-ui 80 Nginx + built UI; proxies /api/ and /profiles-api/
app-api ovp-api 5001 Flask monitoring API
app-gatherer ovp-gatherer - Parses openvpn-status.log
app-profiler ovp-profiler 8000, 1194/udp FastAPI + OpenVPN; needs NET_ADMIN and /dev/net/tun

Volumes: ovp_logs, ovp_config, ovp_pki, ovp_client_config, db_data.

Steps

  1. Create .env next to docker-compose.yml (JWT_SECRET is mandatory: compose refuses to start without it):
    cat > .env <<EOT
    JWT_SECRET=$(openssl rand -hex 32)
    OVPMON_INITIAL_ADMIN_USER=<login>
    OVPMON_INITIAL_ADMIN_PASSWORD=<strong password>
    EOT
    chmod 600 .env
    
  2. docker-compose up -d --build
  3. Open http://<host>, sign in, PKI Configuration → Initialize PKI.
  4. Remove OVPMON_INITIAL_ADMIN_* from .env and run docker-compose up -d app-api (the seed is used only while the users table is empty).

Compose settings

Item Value
Published ports 80/tcp (UI) and 1194/udp (VPN) only; 5001 and 8000 are exposed on ovp-net and reached through Nginx in app-ui
Secrets JWT_SECRET (required) → OVPMON_API_SECRET_KEY for both APIs
Initial admin OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD (optional, first start)
CORS OVPMON_CORS_ORIGINS (optional, comma-separated; off by default because the UI is same-origin)
Restart policy unless-stopped

Hardening

  • Terminate TLS in front of app-ui (reverse proxy or a certificate mounted into the UI container); see Nginx configuration. The container serves plain HTTP on 80.
  • ovp-profiler is privileged (NET_ADMIN, TUN): keep its API off the host network.
  • Back up the db_data and ovp_pki volumes; never commit .env.

Operations

docker-compose ps
docker-compose logs -f app-api app-profiler
docker-compose up -d --build app-ui      # after UI changes