# ihasvpn on the host network: the fastest way to run it. # # With `network_mode: host` the WireGuard socket sits directly on the host's # interfaces. There is no port mapping, no conntrack entry per client packet # and no second NAT hop, which is worth a few percent of throughput and a # little latency on a busy server. The trade-offs: wg0 is created in the # host's namespace (you will see it in `ip link` and it is removed on # shutdown), the NAT rules land in the host's nftables as a table named # `ihasvpn`, and the admin UI listens on the host directly -- so it is bound to # localhost below. Put a reverse proxy in front of it or set # IHASVPN_TLS_SELF_SIGNED to reach it from elsewhere. services: ihasvpn: image: ghcr.io/coffey-labs/ihasvpn:latest container_name: ihasvpn restart: unless-stopped network_mode: host cap_add: - NET_ADMIN environment: IHASVPN_ENDPOINT: vpn.example.com IHASVPN_PORT: "51820" IHASVPN_SUBNET: 10.8.0.0/24 IHASVPN_DNS: 1.1.1.1, 1.0.0.1 IHASVPN_HTTP_LISTEN: "127.0.0.1:51821" # In host mode the forwarding sysctls are the host's own; ihasvpn sets # them itself since it has NET_ADMIN, but if you prefer to own them # add `net.ipv4.ip_forward = 1` to /etc/sysctl.d/ and turn this off. # IHASVPN_MANAGE_SYSCTL: "false" # Pick the interface to masquerade on if auto-detection picks the # wrong one (it uses the default route). # IHASVPN_EGRESS_INTERFACE: eth0 volumes: - ihasvpn-data:/data volumes: ihasvpn-data: