[BUG] PEERDNS env variable unexpected behavior
还没有人认领这个 Issue。
评估
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 新手友好度
- 55/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- docker
- 领域
- devops, networking
调研方向
首先复现两种 Podman Quadlet 配置,并比较 PEERDNS 和 CoreDNS 的容器启动日志。跟踪容器启动时对未设置的 PEERDNS 值与 PEERDNS=auto 的处理;当两种配置都初始化 CoreDNS,并为 WireGuard 客户端提供相同的 DNS 行为时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
Is there an existing issue for this?
- I have searched the existing issues
Current Behavior
Documentation here reports that PEERDNS defaults to auto, which should make use of CoreDNS.
However, currently there is a difference between these two cases:
- Not setting any value for
PEERDNSwhen deploying the container. In this case, the DNS service is not initialized, as evidenced by container logs below. - Setting
PEERDNS=auto. In this case, the DNS service works as expected.
Expected Behavior
Since PEERDNS defaults to auto, there should be no difference between the two situations. Thus, the DNS server should work in both cases.
Steps To Reproduce
- Deploy both versions of the Podman Quadlet below (i.e. with and without the
Environment=PEERDNS=autoline. - Check logs, or attempt to use the DNS server from a WireGuard client.
Environment
- OS: Debian
- How podman service was installed: `apt`
- How the container was deployed: Podman Quadlet
CPU architecture
x86-64
Docker creation
[Unit]
Description="WireGuard VPN server"
Wants=network-online.target
After=network-online.target
After=local-fs.target
[Container]
ContainerName="wireguard-server"
Image=lscr.io/linuxserver/wireguard
Volume=wireguard-server:/config
Network=host
AddCapability=NET_ADMIN
AddCapability=NET_RAW
PublishPort=51820:51820/udp
Environment=SERVERPORT=51820
Environment=SERVERURL=auto
Environment=PEERS=<redacted>
Environment=TZ=<redacted>
Environment=PEERDNS=auto # this line is the only difference between the two configurations
Environment=INTERFACE=enp1s0
AutoUpdate=registry
[Service]
Restart=on-failure
TimeoutStartSec=900
[Install]
WantedBy=default.target
Container logs
Without setting any value for PEERDNS:
───────────────────────────────────────
██╗ ███████╗██╗ ██████╗
██║ ██╔════╝██║██╔═══██╗
██║ ███████╗██║██║ ██║
██║ ╚════██║██║██║ ██║
███████╗███████║██║╚██████╔╝
╚══════╝╚══════╝╚═╝ ╚═════╝
Brought to you by linuxserver.io
───────────────────────────────────────
To support the app dev(s) visit:
WireGuard: https://www.wireguard.com/donations/
To support LSIO projects visit:
https://www.linuxserver.io/donate/
───────────────────────────────────────
GID/UID
───────────────────────────────────────
User UID: 911
User GID: 911
───────────────────────────────────────
Linuxserver.io version: 1.0.20260223-r0-ls120
Build-date: 2026-08-06T13:03:25+00:00
───────────────────────────────────────
Uname info: Linux SERVER-1 6.12.107+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.107-1 (2026-08-29) x86_64 GNU/Linux
**** Server mode is selected ****
**** SERVERURL var is either not set or is set to "auto", setting external IP to auto detected value of <redacted> ****
**** External server port is set to 51820. Make sure that port is properly forwarded to port 51820 inside this container ****
**** Internal subnet is set to 10.13.13.0 ****
**** AllowedIPs for peers 0.0.0.0/0, ::/0 ****
**** PEERDNS var is either not set or is set to "auto", setting peer DNS to 10.13.13.1 to use wireguard docker host's DNS. ****
**** Server mode is selected ****
**** No changes to parameters. Existing configs are used. ****
[custom-init] No custom files found, skipping...
**** Disabling CoreDNS ****
**** Found WG conf /config/wg_confs/wg0.conf, adding to list ****
**** Activating tunnel /config/wg_confs/wg0.conf ****
[#] ip link add dev wg0 type wireguard
[#] wg addconf wg0 /dev/fd/63
[#] ip -4 address add 10.13.13.1 dev wg0
[#] ip link set mtu 1420 up dev wg0
[#] ip -4 route add 10.13.13.6/32 dev wg0
[#] ip -4 route add 10.13.13.5/32 dev wg0
[#] ip -4 route add 10.13.13.4/32 dev wg0
[#] ip -4 route add 10.13.13.3/32 dev wg0
[#] ip -4 route add 10.13.13.2/32 dev wg0
[#] iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o enp1s0 -j MASQUERADE
**** All tunnels are now active ****
[ls.io-init] done.
=========================
Setting `PEERDNS=auto`:
───────────────────────────────────────
██╗ ███████╗██╗ ██████╗
██║ ██╔════╝██║██╔═══██╗
██║ ███████╗██║██║ ██║
██║ ╚════██║██║██║ ██║
███████╗███████║██║╚██████╔╝
╚══════╝╚══════╝╚═╝ ╚═════╝
Brought to you by linuxserver.io
───────────────────────────────────────
To support the app dev(s) visit:
WireGuard: https://www.wireguard.com/donations/
To support LSIO projects visit:
https://www.linuxserver.io/donate/
───────────────────────────────────────
GID/UID
───────────────────────────────────────
User UID: 911
User GID: 911
───────────────────────────────────────
Linuxserver.io version: 1.0.20260223-r0-ls120
Build-date: 2026-08-06T13:03:25+00:00
───────────────────────────────────────
Uname info: Linux SERVER-1 6.12.107+deb13-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.12.107-1 (2026-08-29) x86_64 GNU/Linux
**** Server mode is selected ****
**** SERVERURL var is either not set or is set to "auto", setting external IP to auto detected value of <redacted> ****
**** External server port is set to 51820. Make sure that port is properly forwarded to port 51820 inside this container ****
**** Internal subnet is set to 10.13.13.0 ****
**** AllowedIPs for peers 0.0.0.0/0, ::/0 ****
**** PEERDNS var is either not set or is set to "auto", setting peer DNS to 10.13.13.1 to use wireguard docker host's DNS. ****
**** Server mode is selected ****
**** No changes to parameters. Existing configs are used. ****
[custom-init] No custom files found, skipping...
maxprocs: Leaving GOMAXPROCS=4: CPU quota undefined
.:53
CoreDNS-1.13.2
linux/amd64, go1.26.3,
**** Found WG conf /config/wg_confs/wg0.conf, adding to list ****
**** Activating tunnel /config/wg_confs/wg0.conf ****
[#] ip link add dev wg0 type wireguard
[#] wg addconf wg0 /dev/fd/63
[#] ip -4 address add 10.13.13.1 dev wg0
[#] ip link set mtu 1420 up dev wg0
[#] ip -4 route add 10.13.13.6/32 dev wg0
[#] ip -4 route add 10.13.13.5/32 dev wg0
[#] ip -4 route add 10.13.13.4/32 dev wg0
[#] ip -4 route add 10.13.13.3/32 dev wg0
[#] ip -4 route add 10.13.13.2/32 dev wg0
[#] iptables -A FORWARD -i wg0 -j ACCEPT; iptables -A FORWARD -o wg0 -j ACCEPT; iptables -t nat -A POSTROUTING -o enp1s0 -j MASQUERADE
**** All tunnels are now active ****
[ls.io-init] done.
- 主要语言
- Dockerfile
- 星标
- 3.6k
- 派生
- 437
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
linuxserver/docker-wireguard 的其他 Issue
-
no-issue-activity
难度 1/5 1 小时以内 新手友好度 78/100
linuxserver/docker-wireguard#416 · 5 条评论 ·
-
[BUG] Server mode + host networking + read only = stale wg0 iface, deletes host route on failure未关闭no-issue-activity
难度 4/5 3-5 天 新手友好度 48/100
linuxserver/docker-wireguard#414 · 2 条评论 ·
查看 linuxserver/docker-wireguard 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 60/100
EchoTools/nevr-runtime#450 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 62/100
NuSkooler/enigma-bbs#907 ·
维护者通常 1 天内回复
-
enhancement good first issue
难度 2/5 1-3 小时 新手友好度 80/100
-
python-version
难度 1/5 1 小时以内 新手友好度 88/100
-
initramfs: -type f (#18686) skips the libcurl.so.4 symlink, libcurl no longer copied into initramfs未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 2 天内回复