3 ms·
I recently set this up, but with Podman since I was experimenting with CentOS. It turned out to be quite simple to use network namespaces. I created a new names
by resfirestar 6y ago
I recently set this up, but with Podman since I was experimenting with CentOS. It turned out to be quite simple to use network namespaces. I created a new namespace for wireguard and moved wg0 into the namespace, then had the container use that namespace:
ip netns add vpn
ip link add wg0 type wireguard
ip link set wg0 netns vpn
# configure wireguard as usual, prefix commands with ip netns exec vpn
podman run --network=ns:/var/run/netns/vpn ...
When I tried this was not yet possible with rootless containers, but in newer Podman versions you can tell slirp4netns to use a specific network interface with --network=slirp4netns:outbound_addr=INTERFACE.