1
# Original credit: https://github.com/jpetazzo/dockvpn
6
LABEL maintainer="Kyle Manna <kyle@kylemanna.com>"
9
RUN echo "http://dl-cdn.alpinelinux.org/alpine/edge/testing/" >> /etc/apk/repositories && \
10
apk add --update openvpn iptables bash easy-rsa openvpn-auth-pam google-authenticator pamtester && \
11
ln -s /usr/share/easy-rsa/easyrsa /usr/local/bin && \
12
rm -rf /tmp/* /var/tmp/* /var/cache/apk/* /var/cache/distfiles/*
15
ENV OPENVPN /etc/openvpn
16
ENV EASYRSA /usr/share/easy-rsa
17
ENV EASYRSA_PKI $OPENVPN/pki
18
ENV EASYRSA_VARS_FILE $OPENVPN/vars
20
# Prevents refused client connection because of an expired CRL
21
ENV EASYRSA_CRL_DAYS 3650
23
VOLUME ["/etc/openvpn"]
25
# Internally uses port 1194/udp, remap using `docker run -p 443:1194/tcp`
30
ADD ./bin /usr/local/bin
31
RUN chmod a+x /usr/local/bin/*
33
# Add support for OTP authentication using a PAM module
34
ADD ./otp/openvpn /etc/pam.d/