- README: short overview, quick start, config table and links. - DOCS/General: Deployment_Docker.md and Deployment_Native.md (system services, HTTPS, host hardening); refresh Index.md. - DOCS/Changes: security hardening, admin username change and egress via Hysteria2 with results and verification. - Drop mentions of the built-in admin/password account. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
1.7 KiB
1.7 KiB
Deployment: Docker
Uses docker-compose.yml from the repository root.
Services
| Service | Container | Ports | Notes |
|---|---|---|---|
app-ui |
ovp-ui |
80 | Nginx + built UI; proxies /api/ and /profiles-api/ |
app-api |
ovp-api |
5001 | Flask monitoring API |
app-gatherer |
ovp-gatherer |
- | Parses openvpn-status.log |
app-profiler |
ovp-profiler |
8000, 1194/udp | FastAPI + OpenVPN; needs NET_ADMIN and /dev/net/tun |
Volumes: ovp_logs, ovp_config, ovp_pki, ovp_client_config, db_data.
Steps
- Set a random JWT secret and the initial admin (compose reads them from the environment /
.env):Pass the twocat > .env <<EOT JWT_SECRET=$(openssl rand -hex 32) OVPMON_INITIAL_ADMIN_USER=<login> OVPMON_INITIAL_ADMIN_PASSWORD=<strong password> EOT chmod 600 .envOVPMON_INITIAL_ADMIN_*variables toapp-api(environment:) for the first start. docker-compose up -d --build- Open
http://<host>, sign in, PKI Configuration → Initialize PKI. - Remove
OVPMON_INITIAL_ADMIN_*from.envand recreateapp-api.
Hardening
- Publish only what is needed: in production drop the
5001:5001and8000:8000mappings (Nginx already reaches them onovp-net). - Terminate TLS in front of
app-ui(reverse proxy or mount a cert into the UI container); see Nginx configuration. ovp-profileris privileged (NET_ADMIN, TUN): restrict access to its port to the UI network.- Back up the
db_dataandovp_pkivolumes.
Operations
docker-compose ps
docker-compose logs -f app-api app-profiler
docker-compose up -d --build app-ui # after UI changes