mirror of
https://github.com/fphammerle/docker-tor-proxy.git
synced 2025-10-27 02:43:35 +01:00
Compare commits
18 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| c44166f264 | |||
| b0d0e8da22 | |||
| ef97bc410f | |||
| a4f7946ced | |||
| dcb78b66c5 | |||
| 7bce89fedf | |||
| 22dcf7e9f4 | |||
| 95b977d216 | |||
| db4522974f | |||
| cf5401be4e | |||
| d2d2f4aaf7 | |||
| 60bad462e4 | |||
| 140ebf8e2e | |||
| e49b89c9d7 | |||
| d6f5c7c769 | |||
| fbe6e32e39 | |||
| d76b221102 | |||
| d75d6c74a5 |
+28
-1
@@ -4,9 +4,36 @@ All notable changes to this project will be documented in this file.
|
||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
|
||||
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [2.1.0] - 2020-09-27
|
||||
### Added
|
||||
- Enable [Tor control](https://gitweb.torproject.org/torspec.git/tree/control-spec.txt)
|
||||
listener on port `9051`
|
||||
(listening on loopback device only)
|
||||
|
||||
## [2.0.0] - 2020-03-24
|
||||
### Changed
|
||||
- Changed DNS port from 53 to 9053
|
||||
|
||||
### Fixed
|
||||
- Run as unprivileged user
|
||||
|
||||
## [1.1.1] - 2020-03-21
|
||||
### Fixed
|
||||
- Fix invalid torrc path
|
||||
|
||||
## [1.1.0] - 2020-03-21
|
||||
### Added
|
||||
- Change `SocksTimeout` option by setting `$SOCKS_TIMEOUT_SECONDS`
|
||||
|
||||
## [1.0.0] - 2019-10-12
|
||||
### Added
|
||||
- Tor Socks5 & DNS proxy
|
||||
|
||||
[Unreleased]: https://github.com/fphammerle/docker-tor-proxy/compare/1.0.0...HEAD
|
||||
[Unreleased]: https://github.com/fphammerle/docker-tor-proxy/compare/v2.1.0...HEAD
|
||||
[2.1.0]: https://github.com/fphammerle/docker-tor-proxy/compare/v2.0.0...v2.1.0
|
||||
[2.0.0]: https://github.com/fphammerle/docker-tor-proxy/compare/v1.1.1...v2.0.0
|
||||
[1.1.1]: https://github.com/fphammerle/docker-tor-proxy/compare/v1.1.0...v1.1.1
|
||||
[1.1.0]: https://github.com/fphammerle/docker-tor-proxy/compare/1.0.0...v1.1.0
|
||||
[1.0.0]: https://github.com/fphammerle/docker-tor-proxy/releases/tag/1.0.0
|
||||
|
||||
+17
-14
@@ -1,28 +1,31 @@
|
||||
FROM alpine:3.10
|
||||
FROM alpine:3.12
|
||||
|
||||
ARG CURL_PACKAGE_VERSION=7.66.0-r0
|
||||
ARG BIND_TOOLS_PACKAGE_VERSION=9.14.3-r0
|
||||
ARG TOR_PACKAGE_VERSION=0.4.1.6-r0
|
||||
ARG TOR_PACKAGE_REPOSITORY=http://dl-cdn.alpinelinux.org/alpine/edge/community
|
||||
ARG CURL_PACKAGE_VERSION=7.69.1-r0
|
||||
ARG BIND_TOOLS_PACKAGE_VERSION=9.16.6-r0
|
||||
ARG TOR_PACKAGE_VERSION=0.4.3.5-r0
|
||||
RUN adduser -S onion \
|
||||
&& apk add --no-cache \
|
||||
curl=$CURL_PACKAGE_VERSION \
|
||||
bind-tools=$BIND_TOOLS_PACKAGE_VERSION `# dig` \
|
||||
&& apk add --no-cache --repository $TOR_PACKAGE_REPOSITORY \
|
||||
tor=$TOR_PACKAGE_VERSION
|
||||
|
||||
# RUN apk add --no-cache man less \
|
||||
# && apk add --no-cache tor-doc=$TOR_PACKAGE_VERSION \
|
||||
# --repository $TOR_PACKAGE_REPOSITORY
|
||||
# ENV PAGER=less
|
||||
#RUN apk add --no-cache \
|
||||
# less \
|
||||
# man-db \
|
||||
# tor-doc=$TOR_PACKAGE_VERSION
|
||||
#ENV PAGER=less
|
||||
|
||||
EXPOSE 9050/tcp
|
||||
EXPOSE 53/udp
|
||||
COPY torrc /etc/tor/torrc
|
||||
EXPOSE 9053/udp
|
||||
COPY torrc.template entrypoint.sh /
|
||||
ENV SOCKS_TIMEOUT_SECONDS=
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
RUN chmod -c a+rX /torrc.template /entrypoint.sh
|
||||
|
||||
CMD ["tor"]
|
||||
USER onion
|
||||
CMD ["tor", "-f", "/tmp/torrc"]
|
||||
|
||||
HEALTHCHECK CMD \
|
||||
curl --silent --socks5 localhost:9050 https://google.com > /dev/null \
|
||||
&& [ ! -z "$(dig +notcp +short one.one.one.one @localhost)" ] \
|
||||
&& [ ! -z "$(dig -p 9053 +notcp +short one.one.one.one @localhost)" ] \
|
||||
|| exit 1
|
||||
|
||||
@@ -2,23 +2,23 @@
|
||||
|
||||
docker hub: https://hub.docker.com/r/fphammerle/tor-proxy
|
||||
|
||||
signed tags: https://github.com/fphammerle/tor-proxy/tags
|
||||
signed tags: https://github.com/fphammerle/docker-tor-proxy/tags
|
||||
|
||||
```sh
|
||||
$ docker run --rm --name tor-proxy \
|
||||
$ sudo docker run --rm --name tor_proxy \
|
||||
-p 127.0.0.1:9050:9050/tcp \
|
||||
-p 127.0.0.1:53:53/udp \
|
||||
-p 127.0.0.1:53:9053/udp \
|
||||
fphammerle/tor-proxy
|
||||
```
|
||||
|
||||
or after cloning the repository 🐙
|
||||
```sh
|
||||
$ docker-compose up
|
||||
$ sudo docker-compose up
|
||||
```
|
||||
|
||||
test proxies:
|
||||
```sh
|
||||
$ curl --socks5 localhost:9050 ipinfo.io
|
||||
$ curl --proxy socks5h://localhost:9050 ipinfo.io
|
||||
$ torsocks wget -O - ipinfo.io
|
||||
$ torsocks lynx -dump https://check.torproject.org/
|
||||
$ dig @localhost fabian.hammerle.me
|
||||
@@ -26,3 +26,18 @@ $ ssh -o 'ProxyCommand nc -x localhost:9050 -v %h %p' abcdefghi.onion
|
||||
# no anonymity!
|
||||
$ chromium-browser --proxy-server=socks5://localhost:9050 ipinfo.io
|
||||
```
|
||||
|
||||
isolate:
|
||||
```sh
|
||||
sudo iptables -A OUTPUT ! -o lo -j REJECT --reject-with icmp-admin-prohibited
|
||||
```
|
||||
|
||||
change `SocksTimeout` option:
|
||||
```sh
|
||||
$ sudo docker run -e SOCKS_TIMEOUT_SECONDS=60 …
|
||||
```
|
||||
|
||||
show circuits:
|
||||
```sh
|
||||
$ sudo docker exec tor_proxy sh -c 'printf "AUTHENTICATE\nGETINFO circuit-status\n" | nc localhost 9051'
|
||||
```
|
||||
|
||||
@@ -14,7 +14,7 @@
|
||||
purge_networks: yes
|
||||
ports:
|
||||
- '127.0.0.1:9050:9050/tcp'
|
||||
- '127.0.0.1:53:53/udp'
|
||||
- '127.0.0.1:53:9053/udp'
|
||||
restart_policy: unless-stopped
|
||||
memory: 128M
|
||||
- iptables:
|
||||
|
||||
+7
-3
@@ -6,10 +6,14 @@ services:
|
||||
image: fphammerle/tor-proxy
|
||||
ports:
|
||||
- '127.0.0.1:9050:9050/tcp'
|
||||
- '127.0.0.1:53:53/udp'
|
||||
security_opt: ['no-new-privileges']
|
||||
restart: unless-stopped
|
||||
- '127.0.0.1:53:9053/udp'
|
||||
environment:
|
||||
SOCKS_TIMEOUT_SECONDS: 240
|
||||
cap_drop: [ALL]
|
||||
#cap_add: [SYS_PTRACE]
|
||||
security_opt: [no-new-privileges]
|
||||
cpus: 0.5
|
||||
mem_limit: 128m
|
||||
restart: unless-stopped
|
||||
|
||||
# https://docs.docker.com/compose/compose-file/compose-file-v2/
|
||||
|
||||
Executable
+13
@@ -0,0 +1,13 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -e
|
||||
|
||||
# default: 120 sec
|
||||
# https://github.com/torproject/tor/blob/tor-0.4.1.7/src/core/or/connection_edge.c#L1099
|
||||
if [ -z "$SOCKS_TIMEOUT_SECONDS" ]; then
|
||||
sed -e '/{socks_timeout_seconds}/d' /torrc.template > /tmp/torrc
|
||||
else
|
||||
sed -e "s/{socks_timeout_seconds}/$SOCKS_TIMEOUT_SECONDS/" /torrc.template > /tmp/torrc
|
||||
fi
|
||||
|
||||
exec "$@"
|
||||
@@ -1,7 +0,0 @@
|
||||
Log notice stdout
|
||||
|
||||
SocksPort 0.0.0.0:9050
|
||||
DNSPort 0.0.0.0:53
|
||||
|
||||
# try to
|
||||
HardwareAccel 1
|
||||
@@ -0,0 +1,12 @@
|
||||
Log notice stdout
|
||||
|
||||
# https://gitweb.torproject.org/torspec.git/tree/control-spec.txt
|
||||
ControlPort localhost:9051
|
||||
|
||||
DNSPort 0.0.0.0:9053
|
||||
|
||||
SocksPort 0.0.0.0:9050
|
||||
SocksTimeout {socks_timeout_seconds}
|
||||
|
||||
# try to
|
||||
HardwareAccel 1
|
||||
Reference in New Issue
Block a user