Docker
docker volume create zunder-guard
# 1. Create the config with your rules (paper mode).docker run --rm -it -v zunder-guard:/var/lib/zunder-guard \ ghcr.io/zunderlabs/zunder-guard:1 init --network paper \ --rules zr1_eyJ2IjoxLCJtYXhMZXZlcmFnZSI6NSwibWF4TG9zc0F0U3RvcFBjdCI6Miwic3RvcFBvbGljeSI6ImF0dGFjaCIsImRlZmF1bHRTdG9wRGlzdGFuY2VQY3QiOjIsIm1pbkxpcURpc3RhbmNlUGN0IjoxMCwibWF4UG9zaXRpb25QY3QiOjIwMCwibWF4T3BlblJpc2tQY3QiOjYsImRhaWx5TG9zc1N0b3BQY3QiOjYsImRyYXdkb3duSGFsdFBjdCI6MjUsIm1hcmtldHMiOlsiKiJdfQ
# 2. Start it, reachable from this machine only.docker run -d --name zunder-guard --restart unless-stopped \ -p 127.0.0.1:8547:8547 \ -v zunder-guard:/var/lib/zunder-guard \ ghcr.io/zunderlabs/zunder-guard:1 startfilled in from your settings ·
Things to get right
Section titled “Things to get right”-p 127.0.0.1:8547:8547, not-p 8547:8547. The short form publishes the port on every interface of the host.- The volume holds the journal. Deleting it deletes the risk state, and a new journal starts with a new peak and no halt. Back it up; do not share it between two containers. The journal is locked against a second process.
- Pin the image by digest once you have verified it:
ghcr.io/zunderlabs/zunder-guard@sha256:…. A tag can move; a digest cannot. - A bot in another container reaches Guard on a shared Docker network (for example
http://zunder-guard:8547), not through the published port.
Docker Compose
Section titled “Docker Compose”services: zunder-guard: image: ghcr.io/zunderlabs/zunder-guard:1 command: start restart: unless-stopped ports: ["127.0.0.1:8547:8547"] volumes: ["zunder-guard:/var/lib/zunder-guard"] bot: image: your-bot environment: HYPERLIQUID_API_URL: http://zunder-guard:8547volumes: zunder-guard: {}HYPERLIQUID_API_URL is an example name; use whatever setting your bot reads (Integrations).