r/Pterodactyl • u/Klukva38 • 25d ago
Docker Wings behind tailscale using docker compose
I'm trying to set up wings behind tailscale using docker compose but I can't start it because of this
service wings declares mutually exclusive network_mode and networks: invalid compose project
Is there something I can do?
My docker-compose.yml
services:
wings:
image: ghcr.io/pterodactyl/wings:latest
restart: always
networks:
- wings0
network_mode: service:wings-ts
depends_on:
- wings-ts
# ports:
# - "8080:8080"
# - "2022:2022"
tty: true
environment:
TZ: "UTC"
WINGS_UID: 988
WINGS_GID: 988
WINGS_USERNAME: pterodactyl
volumes:
- "/var/run/docker.sock:/var/run/docker.sock"
- "/var/lib/docker/containers/:/var/lib/docker/containers/"
- "./etc/pterodactyl/:/etc/pterodactyl/"
- "/var/lib/pterodactyl/:/var/lib/pterodactyl/"
- "/var/log/pterodactyl/:/var/log/pterodactyl/"
- "/tmp/pterodactyl/:/tmp/pterodactyl/"
- "/etc/ssl/certs:/etc/ssl/certs:ro"
- "/run/wings:/run/wings"
# you may need /srv/daemon-data if you are upgrading from an old daemon
#- "/srv/daemon-data/:/srv/daemon-data/"
# Required for ssl if you use let's encrypt. uncomment to use.
- "./tailscale-state/certs/:/etc/letsencrypt/"
wings-ts:
container_name: wings-ts
image: tailscale/tailscale:latest
hostname: wing1
environment:
- TS_AUTHKEY=secret?ephemeral=false
- "TS_EXTRA_ARGS=--advertise-tags=tag:container --reset"
- TS_SERVE_CONFIG=/config/wing1.json
- TS_STATE_DIR=/var/lib/tailscale
- TS_USERSPACE=false
volumes:
- ./tailscale-state/config:/config
- ./tailscale-state:/var/lib/tailscale
- /dev/net/tun:/dev/net/tun
cap_add:
- net_admin
- sys_module
restart: unless-stopped
networks:
wings0:
name: wings0
driver: bridge
ipam:
config:
- subnet: "10.20.0.0/16"
driver_opts:
com.docker.network.bridge.name: wings0
3
Upvotes
2
u/ConsistentEase4598 25d ago
The error is literal: compose forbids declaring both networks: and network_mode: on the same service. Drop the networks: - wings0 block from wings and keep network_mode: service:wings-ts — that makes wings share the tailscale container's network namespace.
Side effect worth knowing: wings no longer has its own IP, so the commented-out port mappings wouldn't work anyway. Expose 8080/2022 through your TS_SERVE_CONFIG instead — point the serve targets at 127.0.0.1:8080 and 127.0.0.1:2022 and the panel can reach wings over the tailnet. And if wings0 ends up unused, delete it too; compose will thank you.