WireGuard Archive on lore.kernel.org
 help / Atom feed
* Docker Swarm over WireGuard
@ 2018-11-18  3:45 Kirill K
  0 siblings, 0 replies; 1+ messages in thread
From: Kirill K @ 2018-11-18  3:45 UTC (permalink / raw)
  To: wireguard

[-- Attachment #1.1: Type: text/plain, Size: 1281 bytes --]

Hello there!

I'm using WireGuard about a year and really happy with it. It's
easy-to-use, fast and stable. Great thanks for this precious software.

Sometimes I use servers from providers which do not have any internal
network. So I tried to setup Docker Swarm and route it's ingress network
over WireGuard. For some reason it's not working: internal load balancer
fails to access containers from other nodes. So it's impossible to reach
containers from other nodes, load balancing/routing mesh becomes completely
broken.

Setup is pretty basic and everything works like a charm but this particular
feature. I also found few related questions, so there are number of people
interested in fixing this:
https://stackoverflow.com/questions/52409012/docker-swarm-mode-routing-mesh-not-working-with-wireguard-vpn
https://github.com/moby/moby/issues/37985
https://github.com/moby/moby/issues/36689 (that's my issue, more details
here)

Of course, I do understand that this could be Docker-specific issue, so I'm
just asking here for some directions:

- Does someone succeeded at enchancing Docker Swarm with WireGuard?
- My it be netns-related thing? Should we place Docker ingress network and
wg0 interface into same namespace?

Any help appreciated.

-- 
Best regards,
Kirill Kovalev

[-- Attachment #1.2: Type: text/html, Size: 1876 bytes --]

<div dir="ltr"><div dir="ltr"><div>Hello there!</div><div><br></div><div>I&#39;m using WireGuard about a year and really happy with it. It&#39;s easy-to-use, fast and stable. Great thanks for this precious software.</div><div><br></div><div>Sometimes I use servers from providers which do not have any internal network. So I tried to setup Docker Swarm and route it&#39;s ingress network over WireGuard. For some reason it&#39;s not working: internal load balancer fails to access containers from other nodes. So it&#39;s impossible to reach containers from other nodes, load balancing/routing mesh becomes completely broken.</div><div><br></div><div>Setup is pretty basic and everything works like a charm but this particular feature. I also found few related questions, so there are number of people interested in fixing this:</div><div><a href="https://stackoverflow.com/questions/52409012/docker-swarm-mode-routing-mesh-not-working-with-wireguard-vpn">https://stackoverflow.com/questions/52409012/docker-swarm-mode-routing-mesh-not-working-with-wireguard-vpn</a></div><div><a href="https://github.com/moby/moby/issues/37985">https://github.com/moby/moby/issues/37985</a></div><div><a href="https://github.com/moby/moby/issues/36689">https://github.com/moby/moby/issues/36689</a> (that&#39;s my issue, more details here)</div><div><br></div><div>Of course, I do understand that this could be Docker-specific issue, so I&#39;m just asking here for some directions:</div><div><br></div><div>- Does someone succeeded at enchancing Docker Swarm with WireGuard?</div><div>- My it be netns-related thing? Should we place Docker ingress network and wg0 interface into same namespace?</div><div><br></div><div>Any help appreciated.</div><div><br></div>-- <br><div dir="ltr" class="gmail_signature"><div dir="ltr"><div>Best regards,<br>Kirill Kovalev</div></div></div></div></div>

[-- Attachment #2: Type: text/plain, Size: 148 bytes --]

_______________________________________________
WireGuard mailing list
WireGuard@lists.zx2c4.com
https://lists.zx2c4.com/mailman/listinfo/wireguard

^ permalink raw reply	[flat|nested] 1+ messages in thread

only message in thread, back to index

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-11-18  3:45 Docker Swarm over WireGuard Kirill K

WireGuard Archive on lore.kernel.org

Archives are clonable:
	git clone --mirror https://lore.kernel.org/wireguard/0 wireguard/git/0.git

	# If you have public-inbox 1.1+ installed, you may
	# initialize and index your mirror using the following commands:
	public-inbox-init -V2 wireguard wireguard/ https://lore.kernel.org/wireguard \
		wireguard@lists.zx2c4.com zx2c4-wireguard@archiver.kernel.org
	public-inbox-index wireguard


Newsgroup available over NNTP:
	nntp://nntp.lore.kernel.org/com.zx2c4.lists.wireguard


AGPL code for this site: git clone https://public-inbox.org/ public-inbox