Skip to content

Docker

Terminal window
docker volume create zunder-guard
# 1. Create the config with your rules (paper mode).
docker run --rm -it -v zunder-guard:/var/lib/zunder-guard \
ghcr.io/zunderlabs/zunder-guard:1 init --network paper \
--rules zr1_eyJ2IjoxLCJtYXhMZXZlcmFnZSI6NSwibWF4TG9zc0F0U3RvcFBjdCI6Miwic3RvcFBvbGljeSI6ImF0dGFjaCIsImRlZmF1bHRTdG9wRGlzdGFuY2VQY3QiOjIsIm1pbkxpcURpc3RhbmNlUGN0IjoxMCwibWF4UG9zaXRpb25QY3QiOjIwMCwibWF4T3BlblJpc2tQY3QiOjYsImRhaWx5TG9zc1N0b3BQY3QiOjYsImRyYXdkb3duSGFsdFBjdCI6MjUsIm1hcmtldHMiOlsiKiJdfQ
# 2. Start it, reachable from this machine only.
docker run -d --name zunder-guard --restart unless-stopped \
-p 127.0.0.1:8547:8547 \
-v zunder-guard:/var/lib/zunder-guard \
ghcr.io/zunderlabs/zunder-guard:1 start
  • -p 127.0.0.1:8547:8547, not -p 8547:8547. The short form publishes the port on every interface of the host.
  • The volume holds the journal. Deleting it deletes the risk state, and a new journal starts with a new peak and no halt. Back it up; do not share it between two containers. The journal is locked against a second process.
  • Pin the image by digest once you have verified it: ghcr.io/zunderlabs/zunder-guard@sha256:…. A tag can move; a digest cannot.
  • A bot in another container reaches Guard on a shared Docker network (for example http://zunder-guard:8547), not through the published port.
services:
zunder-guard:
image: ghcr.io/zunderlabs/zunder-guard:1
command: start
restart: unless-stopped
ports: ["127.0.0.1:8547:8547"]
volumes: ["zunder-guard:/var/lib/zunder-guard"]
bot:
image: your-bot
environment:
HYPERLIQUID_API_URL: http://zunder-guard:8547
volumes:
zunder-guard: {}

HYPERLIQUID_API_URL is an example name; use whatever setting your bot reads (Integrations).