binhex-official-gluetun
Aplicación Docker from Binhex's Repository
Visión general
Install binhex-official-gluetun on Unraid in a few clicks.
Find binhex-official-gluetun in Community Apps on your Unraid server, review the template, and click Install. Unraid handles the Docker app or plugin setup from the published template.
Categorías
Descargar estadísticas
Descargas totales a lo largo del tiempo
Detalles
qmcgaw/gluetunArgumentos en tiempo de ejecución
- Interfaz web
http://[IP]:[PORT:8000]- Red
bridge- Concha
sh- Privilegiado
- false
- Parámetros adicionales
--cap-add=NET_ADMIN --device /dev/net/tun:/dev/net/tun
Configuración de plantillas
This is the container path to store gluetun related configuration.
- Objetivo
- /gluetun
- Por defecto
- /mnt/cache/appdata/gluetun
HTTP Control Server port
- Objetivo
- 8000
- Por defecto
- 8000
HTTP Proxy port (when HTTPPROXY=on)
- Objetivo
- 8888
- Por defecto
- 8888
Shadowsocks port TCP (when SHADOWSOCKS=on)
- Objetivo
- 8388
- Por defecto
- 8388
Shadowsocks port UDP (when SHADOWSOCKS=on)
- Objetivo
- 8388
- Por defecto
- 8388
Specify a supported VPN provider to use
- Objetivo
- VPN_SERVICE_PROVIDER
- Por defecto
- private internet access|airvpn|cyberghost|expressvpn|fastestvpn|hidemyass|ipvanish|ivpn|mullvad|nordvpn|perfect privacy|privado|privatevpn|protonvpn|purevpn|slickvpn|surfshark|torguard|vpnsecure|vpn unlimited|vyprvpn|wevpn|windscribe|custom
VPN protocol to use. Not all providers support Wireguard.
- Objetivo
- VPN_TYPE
- Por defecto
- openvpn|wireguard
Specify a custom network interface name to use
- Objetivo
- VPN_INTERFACE
- Por defecto
- tun0|en0
Encryption preset, 'none' disables the cipher and auth OpenVPN options (not recommended).
- Objetivo
- PRIVATE_INTERNET_ACCESS_OPENVPN_ENCRYPTION_PRESET
- Por defecto
- normal|strong|none
OpenVPN username (required for OpenVPN)
- Objetivo
- OPENVPN_USER
OpenVPN password (required for OpenVPN)
- Objetivo
- OPENVPN_PASSWORD
Network protocol to use for OpenVPN
- Objetivo
- OPENVPN_PROTOCOL
- Por defecto
- udp|tcp
Set the OpenVPN version to run
- Objetivo
- OPENVPN_VERSION
- Por defecto
- 2.6|2.5
Specify a target VPN server IP address to use
- Objetivo
- OPENVPN_ENDPOINT_IP
Specify a target VPN server port number to use
- Objetivo
- OPENVPN_ENDPOINT_PORT
OpenVPN verbosity level (1-6)
- Objetivo
- OPENVPN_VERBOSITY
- Por defecto
- 1|2|3|4|5|6
Space delimited OpenVPN flags to pass to openvpn
- Objetivo
- OPENVPN_FLAGS
Run OpenVPN as root
- Objetivo
- OPENVPN_ROOT
- Por defecto
- no|yes
Specify a custom cipher to use (e.g. aes-256-gcm)
- Objetivo
- OPENVPN_CIPHERS
Specify a custom auth algorithm to use (e.g. sha256)
- Objetivo
- OPENVPN_AUTH
Set the MSS fix parameter (0-9999, 0 to use defaults)
- Objetivo
- OPENVPN_MSSFIX
- Por defecto
- 0
Path to custom OpenVPN configuration file for custom provider
- Objetivo
- OPENVPN_CUSTOM_CONFIG
Wireguard client private key (required for Wireguard)
- Objetivo
- WIREGUARD_PRIVATE_KEY
Wireguard IP network interface address (xx.xx.xx.xx/xx)
- Objetivo
- WIREGUARD_ADDRESSES
Wireguard server public key
- Objetivo
- WIREGUARD_PUBLIC_KEY
Wireguard server endpoint IP address
- Objetivo
- WIREGUARD_ENDPOINT_IP
Wireguard server endpoint port number
- Objetivo
- WIREGUARD_ENDPOINT_PORT
Wireguard pre-shared key
- Objetivo
- WIREGUARD_PRESHARED_KEY
Wireguard peer allowed IPs (CSV format)
- Objetivo
- WIREGUARD_ALLOWED_IPS
- Por defecto
- 0.0.0.0/0,::/0
Wireguard implementation to use
- Objetivo
- WIREGUARD_IMPLEMENTATION
- Por defecto
- auto|kernelspace|userspace
Wireguard MTU (1-65535)
- Objetivo
- WIREGUARD_MTU
- Por defecto
- 1400
Wireguard persistent keepalive interval (e.g. 25s)
- Objetivo
- WIREGUARD_PERSISTENT_KEEPALIVE_INTERVAL
Comma separated list of countries
- Objetivo
- SERVER_COUNTRIES
Comma separated list of regions
- Objetivo
- SERVER_REGIONS
Comma separated list of cities
- Objetivo
- SERVER_CITIES
Comma separated list of server hostnames
- Objetivo
- SERVER_HOSTNAMES
Comma separated list of server names
- Objetivo
- SERVER_NAMES
Comma separated list of server categories (NordVPN)
- Objetivo
- SERVER_CATEGORIES
Enable custom port forwarding code for supported providers
- Objetivo
- VPN_PORT_FORWARDING
- Por defecto
- off|on
Choose the custom port forwarding code to use
- Objetivo
- VPN_PORT_FORWARDING_PROVIDER
File path to use for writing the forwarded port obtained
- Objetivo
- VPN_PORT_FORWARDING_STATUS_FILE
- Por defecto
- /gluetun/forwarded_port
Port redirection for the VPN server side port forwarded
- Objetivo
- VPN_PORT_FORWARDING_LISTENING_PORT
Comma separated list of ports to allow from the VPN server side
- Objetivo
- FIREWALL_VPN_INPUT_PORTS
Comma separated list of ports to allow through the default interface
- Objetivo
- FIREWALL_INPUT_PORTS
Prints every firewall related command (debugging only)
- Objetivo
- FIREWALL_DEBUG
- Por defecto
- off|on
Comma separated subnets that Gluetun is allowed to access
- Objetivo
- FIREWALL_OUTBOUND_SUBNETS
Activate DNS over TLS with Unbound
- Objetivo
- DNS_SERVER
- Por defecto
- on
How to connect to upstream DNS servers: dot (DNS over TLS), doh (DNS over HTTPS), plain (UDP DNS)
- Objetivo
- DNS_UPSTREAM_RESOLVER_TYPE
- Por defecto
- dot|doh|plain
Comma delimited list of DNS over TLS providers, valid values are: 'google', 'quad9', 'quadrant', 'cleanbrowsing', 'libredns', 'opendns'
- Objetivo
- DNS_UPSTREAM_RESOLVERS
- Por defecto
Comma separated list of domain names to leave unblocked from the filtering
- Objetivo
- DNS_UNBLOCK_HOSTNAMES
Unbound caching
- Objetivo
- DNS_CACHING
- Por defecto
- on|off
All private CIDRs ranges. Comma separated list of CIDRs or single IP addresses Unbound won't resolve to. Note that the default setting prevents DNS rebinding
- Objetivo
- DNS_BLOCK_IP_PREFIXES
- Por defecto
- 127.0.0.1/8,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,169.254.0.0/16,::1/128,fc00::/7,fe80::/10,::ffff:7f00:1/104,::ffff:a00:0/104,::ffff:a9fe:0/112,::ffff:ac10:0/108,::ffff:c0a8:0/112
DNS IPv6 resolution
- Objetivo
- DNS_UPSTREAM_IPV6
- Por defecto
- off|on
Comma separated list of IP addresses to not resolve public domains to
- Objetivo
- DNS_BLOCK_IPS
Comma separated list of public domain names to exclude from DNS rebinding protection
- Objetivo
- DNS_REBINDING_PROTECTION_EXEMPT_HOSTNAMES
Period to update block lists and restart Unbound (e.g. 24h, 0 to disable)
- Objetivo
- DNS_UPDATE_PERIOD
- Por defecto
- 24h
IP address to use as DNS resolver
- Objetivo
- DNS_ADDRESS
- Por defecto
- 127.0.0.1
Keep /etc/resolv.conf untouched
- Objetivo
- DNS_KEEP_NAMESERVER
- Por defecto
- off|on
Block malicious hostnames and IPs with Unbound
- Objetivo
- BLOCK_MALICIOUS
- Por defecto
- on|off
Block surveillance hostnames and IPs with Unbound
- Objetivo
- BLOCK_SURVEILLANCE
- Por defecto
- off|on
Block ads hostnames and IPs with Unbound
- Objetivo
- BLOCK_ADS
- Por defecto
- off|on
Enable the internal HTTP proxy
- Objetivo
- HTTPPROXY
- Por defecto
- off|on
Logs every tunnel requests
- Objetivo
- HTTPPROXY_LOG
- Por defecto
- off|on
Internal listening address for the HTTP proxy
- Objetivo
- HTTPPROXY_LISTENING_ADDRESS
- Por defecto
- :8888
Username to use to connect to the HTTP proxy
- Objetivo
- HTTPPROXY_USER
Password to use to connect to the HTTP proxy
- Objetivo
- HTTPPROXY_PASSWORD
Stealth mode means HTTP proxy headers are not added
- Objetivo
- HTTPPROXY_STEALTH
- Por defecto
- off|on
Enable the internal Shadowsocks proxy
- Objetivo
- SHADOWSOCKS
- Por defecto
- off|on
Enable Shadowsocks logging
- Objetivo
- SHADOWSOCKS_LOG
- Por defecto
- off|on
Internal listening address for Shadowsocks
- Objetivo
- SHADOWSOCKS_LISTENING_ADDRESS
- Por defecto
- :8388
Password to use to connect to Shadowsocks
- Objetivo
- SHADOWSOCKS_PASSWORD
AEAD Cipher to use for Shadowsocks
- Objetivo
- SHADOWSOCKS_CIPHER
- Por defecto
- chacha20-ietf-poly1305|aes-128-gcm|aes-256-gcm
Authentication configuration for the HTTP Control Server
- Objetivo
- HTTP_CONTROL_SERVER_AUTH_DEFAULT_ROLE
- Por defecto
- {"auth":"basic","username":"controlserver","password":"controlserver"}
Listening address for the HTTP Control Server
- Objetivo
- HTTP_CONTROL_SERVER_ADDRESS
- Por defecto
- :8000
Enable logging of requests for the HTTP Control Server
- Objetivo
- HTTP_CONTROL_SERVER_LOG
- Por defecto
- on|off
Path to a TOML file containing authentication configuration for the HTTP Control Server
- Objetivo
- HTTP_CONTROL_SERVER_AUTH_CONFIG_FILEPATH
Comma-separated addresses to ping on every internal health check (replaces HEALTH_TARGET_ADDRESS)
- Objetivo
- HEALTH_TARGET_ADDRESSES
- Por defecto
- google.com:443
Initial duration to wait for the VPN to be ready
- Objetivo
- HEALTH_VPN_DURATION_INITIAL
- Por defecto
- 6s
Additional duration to add for each consecutive VPN failure
- Objetivo
- HEALTH_VPN_DURATION_ADDITION
- Por defecto
- 5s
Duration to wait after a success check
- Objetivo
- HEALTH_SUCCESS_WAIT_DURATION
- Por defecto
- 5s
Internal health check server listening address
- Objetivo
- HEALTH_SERVER_ADDRESS
- Por defecto
- 127.0.0.1:9999
Period to update VPN servers data e.g. '24h' (0 to disable)
- Objetivo
- UPDATER_PERIOD
- Por defecto
- 0
Ratio of servers to be found for update to succeed
- Objetivo
- UPDATER_MIN_RATIO
- Por defecto
- 0.8
List of providers to update servers data for
- Objetivo
- UPDATER_VPN_SERVICE_PROVIDERS
Path of servers.json file (empty to disable caching)
- Objetivo
- STORAGE_FILEPATH
- Por defecto
- /gluetun/servers.json
Specify a timezone to use to have correct log times. i.e. Europe/London
- Objetivo
- TZ
User ID to run as non root
- Objetivo
- PUID
- Por defecto
- 99
Group ID to run as non root
- Objetivo
- PGID
- Por defecto
- 100
Check for public IP address information on VPN connection
- Objetivo
- PUBLICIP_ENABLED
- Por defecto
- true
Public IP echo service API to use
- Objetivo
- PUBLICIP_API
- Por defecto
- ipinfo
Optional API token for the public IP echo service
- Objetivo
- PUBLICIP_API_TOKEN
Filepath to store the public IP address assigned
- Objetivo
- PUBLICIP_FILE
- Por defecto
- /gluetun/ip
Logs a message indicating if a newer version is available
- Objetivo
- VERSION_INFORMATION
- Por defecto
- on