{"repo":"gifi71/ocserv-docker","free":true,"listed":false,"github":"https://github.com/gifi71/ocserv-docker","clone":"git clone https://github.com/gifi71/ocserv-docker.git","description":"A containerized version of ocserv (OpenConnect VPN server), built from source for security, flexibility, and minimal overhead.","language":"Dockerfile","stars":36,"topics":["container","docker","docker-compose","docker-container","docker-image","minimal","ocserv","openconnect","selfhosted","vpn"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"ocserv-docker Production-ready ocserv (OpenConnect VPN server) in Docker. Built from source with GPG verification, supervised by s6-overlay, with optional Prometheus metrics via ocserv-exporter. Key highlights: - Multi-stage build on debian:bookworm-slim — minimal final image, no build toolchain - Latest ocserv built from source with OIDC auth support (see releases for version) - Multi-architecture support: amd64 , arm64 - Optional Prometheus metrics via ocserv-exporter - Idempotent iptables setup with clean teardown on shutdown --- Quick Start Or with docker run : --- Requirements Requirement Why --- --- Docker with BuildKit Multi-stage build, cache mounts --cap-add NET ADMIN iptables rules and TUN device creation --device /dev/net/tun Kernel interface for VPN tunnels net.ipv4.ip forward=1 Route traffic between VPN clients and the network Enable IP forwarding on the host (required for host mode; in bridge mode it is set automatically via --sysctl ): Optional — improve TCP performance with BBR: --- Configuration ocserv.conf This project does not ship a default config. Create your own based on the upstream example: - ocserv sample.config - ocserv manual - Configuration recipes Required settings for this container: TLS Certificates Use any method you prefer: certtool , openssl , ACME (certbot, acme.sh), etc. Mount the resulting cert and key into config/ . Environment Variables Variable Required Default Description --- --- --- --- VPN NETWORK yes — NAT MASQUERADE CIDR, must matc","default_branch":null,"files":null,"tree":[],"storefront":"/r/gifi71","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/gifi71/ocserv-docker/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}