Add fail-closed WireGuard container gateway
This commit is contained in:
1 parent
2f3bdde8b0
commit
0e5876f1a9
17 files changed
+365
-109
No files matched your search
+38
-4
@@ -27,6 +27,37 @@ x-llama-common: &llama-common
|
||||
start_period: 30s
|
||||
|
||||
services:
|
||||
wireguard-gateway:
|
||||
build: ./platform/docker/wireguard-gateway
|
||||
image: mike-ai/wireguard-gateway:local
|
||||
container_name: mike-ai-wireguard-gateway
|
||||
restart: unless-stopped
|
||||
cap_add: [NET_ADMIN]
|
||||
devices:
|
||||
- /dev/net/tun:/dev/net/tun
|
||||
sysctls:
|
||||
net.ipv4.ip_forward: "1"
|
||||
net.ipv4.conf.all.src_valid_mark: "1"
|
||||
net.ipv6.conf.all.forwarding: "1"
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /run:size=16m,mode=0755
|
||||
- /tmp:size=16m,mode=1777
|
||||
volumes:
|
||||
- "${WIREGUARD_CONFIG_FILE:-/etc/mike-ai/wireguard/fritz-athena.conf}:/run/secrets/fritz-athena.conf:ro"
|
||||
networks:
|
||||
frontend:
|
||||
ipv4_address: 172.30.10.254
|
||||
tools-egress:
|
||||
ipv4_address: 172.30.50.254
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
healthcheck:
|
||||
test: [CMD, /usr/local/sbin/mike-ai-wireguard-healthcheck]
|
||||
interval: 10s
|
||||
timeout: 3s
|
||||
retries: 12
|
||||
start_period: 10s
|
||||
|
||||
llama-fast:
|
||||
<<: *llama-common
|
||||
container_name: mike-ai-llama-fast
|
||||
@@ -416,8 +447,6 @@ services:
|
||||
TTS_VOICES: alloy
|
||||
TTS_DEFAULT_VOICE: alloy
|
||||
ENABLE_STT: "false"
|
||||
ports:
|
||||
- "${AI_BIND_ADDRESS:-127.0.0.1}:8081:8081"
|
||||
networks: [frontend, control, inference]
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
cap_drop: [ALL]
|
||||
@@ -433,6 +462,8 @@ services:
|
||||
retries: 24
|
||||
start_period: 5s
|
||||
depends_on:
|
||||
wireguard-gateway:
|
||||
condition: service_healthy
|
||||
profile-controller:
|
||||
condition: service_healthy
|
||||
piper:
|
||||
@@ -550,11 +581,11 @@ services:
|
||||
[{"url":"http://mike-ai-mcp-web:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"web-local","name":"Web (öffentlich, read-only)","description":"Für aktuelle öffentliche Internetdaten, Quellenprüfung, GitHub/Hugging Face und Produktsuche. Nicht für Home Assistant, Medienverwaltung oder NAS-Diagnose."}},{"url":"http://mike-ai-mcp-homeassistant:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"homeassistant-local","name":"Home Assistant (lokal)","description":"Nur für Home-Assistant-Entitäten, Zustände, Historie, Automationen, Dashboards und HA-Diagnose. Nicht für Unraid, Sonarr/Radarr oder allgemeine Websuche."}},{"url":"http://mike-ai-mcp-arr:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"arr-local","name":"Sonarr und Radarr (lokal)","description":"Nur für verwaltete Serien/Filme, fehlende Episoden, Queue und Suche über konfigurierte Indexer. Keine allgemeine Websuche; Schreibaktionen benötigen Vorschau und Freigabe."}},{"url":"http://mike-ai-mcp-unraid-official:8000/mcp","path":"","type":"mcp","auth_type":"none","headers":null,"key":"","config":{"enable":true,"access_grants":[]},"info":{"id":"unraid-readonly-local","name":"Unraid (Systemdiagnose)","description":"Nur für Unraid-Host, Array, Datenträger, Docker-Container, Shares, Netzwerk, UPS und Systemlogs. Nicht für Home Assistant oder Medieninhalte; Standardzugriff read-only."}}]
|
||||
DO_NOT_TRACK: "true"
|
||||
SCARF_NO_ANALYTICS: "true"
|
||||
ports:
|
||||
- "${AI_BIND_ADDRESS:-127.0.0.1}:8080:8080"
|
||||
dns: ["${AI_DNS:-1.1.1.1}"]
|
||||
networks: [frontend, tools]
|
||||
depends_on:
|
||||
wireguard-gateway:
|
||||
condition: service_healthy
|
||||
router:
|
||||
condition: service_healthy
|
||||
security_opt: ["no-new-privileges:true"]
|
||||
@@ -575,6 +606,9 @@ networks:
|
||||
tools:
|
||||
external: true
|
||||
name: mike-ai-tools
|
||||
tools-egress:
|
||||
external: true
|
||||
name: mike-ai-tools-egress
|
||||
|
||||
volumes:
|
||||
open-webui-data:
|
||||
|
||||
Reference in new issue
Block a user