Skip to content

Examples

air-gapped

Two machines on a network with no internet and nothing published: on Docker, an internal network; on VMs, outbound connections blocked once the machines are provisioned. VMs use 192.168.62.0/24 as written; Docker uses the block the network names for it.

Tested: Runs in CI on Docker with its checks.

version: 1
name: air-gapped

networks:
  lab:
    cidr: 192.168.62.0/24
    internet: false
    docker:
      cidr: 10.62.0.0/24   # Docker keeps out of 192.168.0.0/16

machines:
  store:
    networks: { lab: 20 }
    services: [{ port: 6379, name: redis }]
    docker:
      image: "redis:7-alpine"
    vm:
      os: debian-12
      provision: [provision/store.sh]

  app:
    networks: { lab: 10 }
    services: [{ port: 80, http: true }]
    depends_on: [store]
    docker:
      image: "nginx:1.27-alpine"
    vm:
      os: debian-12
      provision: [provision/app.sh]

checks:
  - checks/app-answers.sh
  - checks/no-internet.sh

Targets

docker, hosted, cloud-docker, vagrant, proxmox, cloud-vm. See Targets for what each means.

Checks

  • checks/app-answers.sh
  • checks/no-internet.sh

See Checks.