- JWT_SECRET is mandatory (no more "supersecret" fallback). - Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the APIs; add restart policy and drop the obsolete compose "version". - Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net. - CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded host (default: same-origin only). - Update Docker/native deployment docs and README accordingly. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2.1 KiB
2.1 KiB
Deployment: Docker
Uses docker-compose.yml from the repository root.
Services
| Service | Container | Ports | Notes |
|---|---|---|---|
app-ui |
ovp-ui |
80 | Nginx + built UI; proxies /api/ and /profiles-api/ |
app-api |
ovp-api |
5001 | Flask monitoring API |
app-gatherer |
ovp-gatherer |
- | Parses openvpn-status.log |
app-profiler |
ovp-profiler |
8000, 1194/udp | FastAPI + OpenVPN; needs NET_ADMIN and /dev/net/tun |
Volumes: ovp_logs, ovp_config, ovp_pki, ovp_client_config, db_data.
Steps
- Create
.envnext todocker-compose.yml(JWT_SECRETis mandatory: compose refuses to start without it):cat > .env <<EOT JWT_SECRET=$(openssl rand -hex 32) OVPMON_INITIAL_ADMIN_USER=<login> OVPMON_INITIAL_ADMIN_PASSWORD=<strong password> EOT chmod 600 .env docker-compose up -d --build- Open
http://<host>, sign in, PKI Configuration → Initialize PKI. - Remove
OVPMON_INITIAL_ADMIN_*from.envand rundocker-compose up -d app-api(the seed is used only while the users table is empty).
Compose settings
| Item | Value |
|---|---|
| Published ports | 80/tcp (UI) and 1194/udp (VPN) only; 5001 and 8000 are exposed on ovp-net and reached through Nginx in app-ui |
| Secrets | JWT_SECRET (required) → OVPMON_API_SECRET_KEY for both APIs |
| Initial admin | OVPMON_INITIAL_ADMIN_USER / OVPMON_INITIAL_ADMIN_PASSWORD (optional, first start) |
| CORS | OVPMON_CORS_ORIGINS (optional, comma-separated; off by default because the UI is same-origin) |
| Restart policy | unless-stopped |
Hardening
- Terminate TLS in front of
app-ui(reverse proxy or a certificate mounted into the UI container); see Nginx configuration. The container serves plain HTTP on 80. ovp-profileris privileged (NET_ADMIN, TUN): keep its API off the host network.- Back up the
db_dataandovp_pkivolumes; never commit.env.
Operations
docker-compose ps
docker-compose logs -f app-api app-profiler
docker-compose up -d --build app-ui # after UI changes