Add fail-closed WireGuard container gateway

This commit is contained in:
Mikei386 committed 2026-08-22 20:48:49 +02:00
1 parent 2f3bdde8b0
commit 0e5876f1a9
17 files changed
+365 -109

No files matched your search

+38 -4
View File
@@ -27,6 +27,37 @@ x-llama-common: &llama-common
start_period: 30s
services:
wireguard-gateway:
build: ./platform/docker/wireguard-gateway
image: mike-ai/wireguard-gateway:local
container_name: mike-ai-wireguard-gateway
restart: unless-stopped
cap_add: [NET_ADMIN]
devices:
- /dev/net/tun:/dev/net/tun
sysctls:
net.ipv4.ip_forward: "1"
net.ipv4.conf.all.src_valid_mark: "1"
net.ipv6.conf.all.forwarding: "1"
read_only: true
tmpfs:
- /run:size=16m,mode=0755
- /tmp:size=16m,mode=1777
volumes:
- "${WIREGUARD_CONFIG_FILE:-/etc/mike-ai/wireguard/fritz-athena.conf}:/run/secrets/fritz-athena.conf:ro"
networks:
frontend:
ipv4_address: 172.30.10.254
tools-egress:
ipv4_address: 172.30.50.254
security_opt: ["no-new-privileges:true"]
healthcheck:
test: [CMD, /usr/local/sbin/mike-ai-wireguard-healthcheck]
interval: 10s
timeout: 3s
retries: 12
start_period: 10s
llama-fast:
<<: *llama-common
container_name: mike-ai-llama-fast
@@ -416,8 +447,6 @@ services:
TTS_VOICES: alloy
TTS_DEFAULT_VOICE: alloy
ENABLE_STT: "false"
ports:
- "${AI_BIND_ADDRESS:-127.0.0.1}:8081:8081"
networks: [frontend, control, inference]
security_opt: ["no-new-privileges:true"]
cap_drop: [ALL]
@@ -433,6 +462,8 @@ services:
retries: 24
start_period: 5s
depends_on:
wireguard-gateway:
condition: service_healthy
profile-controller:
condition: service_healthy
piper:
@@ -550,11 +581,11 @@ services:
[{"url":"http://mike-ai-mcp-web:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"web-local","name":"Web (öffentlich, read-only)","description":"Für aktuelle öffentliche Internetdaten, Quellenprüfung, GitHub/Hugging Face und Produktsuche. Nicht für Home Assistant, Medienverwaltung oder NAS-Diagnose."}},{"url":"http://mike-ai-mcp-homeassistant:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"homeassistant-local","name":"Home Assistant (lokal)","description":"Nur für Home-Assistant-Entitäten, Zustände, Historie, Automationen, Dashboards und HA-Diagnose. Nicht für Unraid, Sonarr/Radarr oder allgemeine Websuche."}},{"url":"http://mike-ai-mcp-arr:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"arr-local","name":"Sonarr und Radarr (lokal)","description":"Nur für verwaltete Serien/Filme, fehlende Episoden, Queue und Suche über konfigurierte Indexer. Keine allgemeine Websuche; Schreibaktionen benötigen Vorschau und Freigabe."}},{"url":"http://mike-ai-mcp-unraid-official:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"unraid-readonly-local","name":"Unraid (Systemdiagnose)","description":"Nur für Unraid-Host, Array, Datenträger, Docker-Container, Shares, Netzwerk, UPS und Systemlogs. Nicht für Home Assistant oder Medieninhalte; Standardzugriff read-only."}}]
DO_NOT_TRACK: "true"
SCARF_NO_ANALYTICS: "true"
ports:
- "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080"
dns: ["${AI_DNS:-1.1.1.1}"]
networks: [frontend, tools]
depends_on:
wireguard-gateway:
condition: service_healthy
router:
condition: service_healthy
security_opt: ["no-new-privileges:true"]
@@ -575,6 +606,9 @@ networks:
tools:
external: true
name: mike-ai-tools
tools-egress:
external: true
name: mike-ai-tools-egress
volumes:
open-webui-data: