Files
luci-app-zt-gateway/Dockerfile.router
Malar Invention eb04a2597d feat: implement ZeroTier exit gateway switcher
Adds the luci-app-zt-gateway package: a LuCI app + rpcd/ucode backend +
shell switch script that reconfigures which remote ZeroTier node acts as
the internet exit gateway for WIBLAN clients (10.11.13.0/24).

  - Makefile (luci.mk, arch-independent)
  - UCI config skeleton with three sample gateways
  - rpcd ACL + menu entry
  - zt-gateway.uc rpcd backend exposing status / switch / health /
    drain_status / cancel_drain ubus methods
  - zt-gateway-switch shell script implementing force + graceful modes:
      * force: pre-flight ping, atomic route replace, conntrack flush,
        UCI/hotplug/rc.local persistence
      * graceful: dual-table drain using CONNMARK fwmark 0x100 at
        priority 99, background drain monitor with two-consecutive-zero
        completion and timeout-forced fallback to force
  - LuCI overview.js: gateway radio list, mode select, drain progress
    panel, cancel-drain button, health polling
  - Docker test harness (docker-compose + Dockerfile.router +
    router/gw entrypoints) exercising the switch script against real
    iproute2/iptables/conntrack on two simulated exit nodes

Verified against the harness: force switch, graceful drain to natural
completion, pre-flight blocking of unreachable gateways (force + graceful),
and drain-timeout forced fallback.
2026-06-19 02:51:21 +05:30

17 lines
740 B
Docker

FROM archlinux:latest
# archlinux:latest ships iproute2, iptables, awk, sed, ip6tables, busybox
# tools. Install conntrack-tools for the drain monitor + conntrack -D path.
# Tolerate offline builds: the script falls back to /proc/net/nf_conntrack
# when conntrack CLI is unavailable.
RUN pacman --noconfirm -Sy conntrack-tools 2>/dev/null || \
echo "[build] conntrack-tools unavailable; script will degrade gracefully"
# Harness + switch script
COPY docker/router-entrypoint.sh /usr/local/bin/router-entrypoint.sh
COPY root/usr/sbin/zt-gateway-switch /usr/sbin/zt-gateway-switch
RUN chmod +x /usr/local/bin/router-entrypoint.sh /usr/sbin/zt-gateway-switch
ENTRYPOINT ["/usr/local/bin/router-entrypoint.sh"]
CMD ["sleep", "infinity"]