Skip to content

Containerized tunnel unusable again #118

Description

@asardaes

Describe the Bug

I think it's basically the same issue from fosrl/olm#72. I don't want to use host network for the CLI's container, I want only the containers in the docker compose network to connect to the tunnel, but now the CLI keeps trying to use a local connection and loops forever.

INFO: 2026/07/26 19:49:02 WireGuard connection to site 3 is CONNECTED (RTT: 28.018564ms)
INFO: 2026/07/26 19:49:03 Local endpoint 172.16.15.133:57686 for site 3 is reachable (RTT: 14.817936ms), switching to local connection
INFO: 2026/07/26 19:49:03 Switched peer 3 to local connection at 172.16.15.133:57686
INFO: 2026/07/26 19:49:03 Sent local-connection message for site 3 (172.16.15.133:57686, chain 04ca81b2b1971dbb)
INFO: 2026/07/26 19:49:03 Cancelled local-connection sender for chain 04ca81b2b1971dbb
WARN: 2026/07/26 19:49:05 WireGuard connection to site 3 is DISCONNECTED
WARN: 2026/07/26 19:49:13 Local endpoint 172.16.15.133:57686 for site 3 failed 3 times, falling back to public/relay logic
INFO: 2026/07/26 19:49:13 Switched peer 3 back to direct connection at 193.122.62.82:57686
INFO: 2026/07/26 19:49:13 Sent unlocal-connection message for site 3 (chain e6b8673e0ab28a53)
INFO: 2026/07/26 19:49:13 Starting rapid holepunch test for site 3 at 193.122.62.82:57686 (max 5 attempts, 400ms timeout each)
INFO: 2026/07/26 19:49:13 Cancelled local-connection sender for chain e6b8673e0ab28a53
WARN: 2026/07/26 19:49:16 Rapid test: site 3 holepunch FAILED after 5 attempts, will relay
WARN: 2026/07/26 19:49:16 Rapid fallback test: site 3 unreachable on public endpoint after local fallback, requesting relay
INFO: 2026/07/26 19:49:16 Sent relay message for site 3 (chain f2dacb4e459192de)
INFO: 2026/07/26 19:49:16 Cancelled relay sender for chain f2dacb4e459192de
INFO: 2026/07/26 19:49:16 Adjusted peer 3 to point to relay!
INFO: 2026/07/26 19:49:17 Local endpoint 172.16.15.133:57686 for site 3 is reachable (RTT: 15.368761ms), switching to local connection
INFO: 2026/07/26 19:49:17 Switched peer 3 to local connection at 172.16.15.133:57686
INFO: 2026/07/26 19:49:17 Sent local-connection message for site 3 (172.16.15.133:57686, chain 273e6ce534d50008)
INFO: 2026/07/26 19:49:17 Cancelled local-connection sender for chain 273e6ce534d50008
WARN: 2026/07/26 19:49:27 Local endpoint 172.16.15.133:57686 for site 3 failed 3 times, falling back to public/relay logic
INFO: 2026/07/26 19:49:27 Switched peer 3 back to direct connection at 193.122.62.82:57686
INFO: 2026/07/26 19:49:27 Sent unlocal-connection message for site 3 (chain d364ef47f6465dfc)
INFO: 2026/07/26 19:49:27 Starting rapid holepunch test for site 3 at 193.122.62.82:57686 (max 5 attempts, 400ms timeout each)
INFO: 2026/07/26 19:49:27 Cancelled local-connection sender for chain d364ef47f6465dfc
WARN: 2026/07/26 19:49:30 Rapid test: site 3 holepunch FAILED after 5 attempts, will relay
WARN: 2026/07/26 19:49:30 Rapid fallback test: site 3 unreachable on public endpoint after local fallback, requesting relay
INFO: 2026/07/26 19:49:30 Sent relay message for site 3 (chain 726a520033f85721)
INFO: 2026/07/26 19:49:30 Cancelled relay sender for chain 726a520033f85721
INFO: 2026/07/26 19:49:30 Adjusted peer 3 to point to relay!
INFO: 2026/07/26 19:49:31 Tunnel process context cancelled, cleaning up
Received shutdown signal, stopping tunnel
INFO: 2026/07/26 19:49:31 Hole punch manager stopped
INFO: 2026/07/26 19:49:31 Stopped holepunch connection monitor
INFO: 2026/07/26 19:49:31 UDP hole punch goroutine ended for all exit nodes
INFO: 2026/07/26 19:49:31 DNS proxy stopped
INFO: 2026/07/26 19:49:31 Released shared UDP bind
INFO: 2026/07/26 19:49:31 Olm service stopped

Environment

  • OS Type & Version: TrueNAS Linux - Docker
  • Pangolin Version: 1.21.0
  • Gerbil Version: 1.4.3
  • Traefik Version: 3.7.9
  • Newt Version: 1.15.0
  • Client Version: CLI 0.15.0

To Reproduce

Here's my docker compose's relevant section:

services:
  olm:
    image: fosrl/pangolin-cli
    restart: unless-stopped
    command:
      - up
      - --attach
      - --endpoint=$ENDPOINT
      - --id=$CLIENT_ID
      - --secret=$CLIENT_SECRET
      - --netstack-dns=9.9.9.9
      - --holepunch=false
      - --override-dns=false
      - --prefer-local-routes=false
    cap_add:
      - NET_ADMIN
    devices:
      - /dev/net/tun:/dev/net/tun

Expected Behavior

Flags --holepunch=false and --prefer-local-routes=false should be respected.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions