Skip to content

Containerized tunnel unusable again #118

Description

@asardaes

Describe the Bug

I think it's basically the same issue from fosrl/olm#72. I don't want to use host network for the CLI's container, I want only the containers in the docker compose network to connect to the tunnel, but now the CLI keeps trying to use a local connection and loops forever.

INFO: 2026/07/26 19:49:02 WireGuard connection to site 3 is CONNECTED (RTT: 28.018564ms)
INFO: 2026/07/26 19:49:03 Local endpoint 172.16.15.133:57686 for site 3 is reachable (RTT: 14.817936ms), switching to local connection
INFO: 2026/07/26 19:49:03 Switched peer 3 to local connection at 172.16.15.133:57686
INFO: 2026/07/26 19:49:03 Sent local-connection message for site 3 (172.16.15.133:57686, chain 04ca81b2b1971dbb)
INFO: 2026/07/26 19:49:03 Cancelled local-connection sender for chain 04ca81b2b1971dbb
WARN: 2026/07/26 19:49:05 WireGuard connection to site 3 is DISCONNECTED
WARN: 2026/07/26 19:49:13 Local endpoint 172.16.15.133:57686 for site 3 failed 3 times, falling back to public/relay logic
INFO: 2026/07/26 19:49:13 Switched peer 3 back to direct connection at 193.122.62.82:57686
INFO: 2026/07/26 19:49:13 Sent unlocal-connection message for site 3 (chain e6b8673e0ab28a53)
INFO: 2026/07/26 19:49:13 Starting rapid holepunch test for site 3 at 193.122.62.82:57686 (max 5 attempts, 400ms timeout each)
INFO: 2026/07/26 19:49:13 Cancelled local-connection sender for chain e6b8673e0ab28a53
WARN: 2026/07/26 19:49:16 Rapid test: site 3 holepunch FAILED after 5 attempts, will relay
WARN: 2026/07/26 19:49:16 Rapid fallback test: site 3 unreachable on public endpoint after local fallback, requesting relay
INFO: 2026/07/26 19:49:16 Sent relay message for site 3 (chain f2dacb4e459192de)
INFO: 2026/07/26 19:49:16 Cancelled relay sender for chain f2dacb4e459192de
INFO: 2026/07/26 19:49:16 Adjusted peer 3 to point to relay!
INFO: 2026/07/26 19:49:17 Local endpoint 172.16.15.133:57686 for site 3 is reachable (RTT: 15.368761ms), switching to local connection
INFO: 2026/07/26 19:49:17 Switched peer 3 to local connection at 172.16.15.133:57686
INFO: 2026/07/26 19:49:17 Sent local-connection message for site 3 (172.16.15.133:57686, chain 273e6ce534d50008)
INFO: 2026/07/26 19:49:17 Cancelled local-connection sender for chain 273e6ce534d50008
WARN: 2026/07/26 19:49:27 Local endpoint 172.16.15.133:57686 for site 3 failed 3 times, falling back to public/relay logic
INFO: 2026/07/26 19:49:27 Switched peer 3 back to direct connection at 193.122.62.82:57686
INFO: 2026/07/26 19:49:27 Sent unlocal-connection message for site 3 (chain d364ef47f6465dfc)
INFO: 2026/07/26 19:49:27 Starting rapid holepunch test for site 3 at 193.122.62.82:57686 (max 5 attempts, 400ms timeout each)
INFO: 2026/07/26 19:49:27 Cancelled local-connection sender for chain d364ef47f6465dfc
WARN: 2026/07/26 19:49:30 Rapid test: site 3 holepunch FAILED after 5 attempts, will relay
WARN: 2026/07/26 19:49:30 Rapid fallback test: site 3 unreachable on public endpoint after local fallback, requesting relay
INFO: 2026/07/26 19:49:30 Sent relay message for site 3 (chain 726a520033f85721)
INFO: 2026/07/26 19:49:30 Cancelled relay sender for chain 726a520033f85721
INFO: 2026/07/26 19:49:30 Adjusted peer 3 to point to relay!
INFO: 2026/07/26 19:49:31 Tunnel process context cancelled, cleaning up
Received shutdown signal, stopping tunnel
INFO: 2026/07/26 19:49:31 Hole punch manager stopped
INFO: 2026/07/26 19:49:31 Stopped holepunch connection monitor
INFO: 2026/07/26 19:49:31 UDP hole punch goroutine ended for all exit nodes
INFO: 2026/07/26 19:49:31 DNS proxy stopped
INFO: 2026/07/26 19:49:31 Released shared UDP bind
INFO: 2026/07/26 19:49:31 Olm service stopped

Environment

  • OS Type & Version: TrueNAS Linux - Docker
  • Pangolin Version: 1.21.0
  • Gerbil Version: 1.4.3
  • Traefik Version: 3.7.9
  • Newt Version: 1.15.0
  • Client Version: CLI 0.15.0

To Reproduce

Here's my docker compose's relevant section:

services:
  olm:
    image: fosrl/pangolin-cli
    restart: unless-stopped
    command:
      - up
      - --attach
      - --endpoint=$ENDPOINT
      - --id=$CLIENT_ID
      - --secret=$CLIENT_SECRET
      - --netstack-dns=9.9.9.9
      - --holepunch=false
      - --override-dns=false
      - --prefer-local-routes=false
    cap_add:
      - NET_ADMIN
    devices:
      - /dev/net/tun:/dev/net/tun

Expected Behavior

Flags --holepunch=false and --prefer-local-routes=false should be respected.

Metadata

Metadata

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions