diff --git a/.devcontainer/Containerfile b/.devcontainer/Containerfile new file mode 100644 index 000000000..dbe6b4bb2 --- /dev/null +++ b/.devcontainer/Containerfile @@ -0,0 +1,45 @@ +# Containerfile +# podman image build -q -t debian:podman-trixie -f Containerfile . +# podman run -q -it --rm --device /dev/fuse debian:podman-trixie + # in development container e.g. +FROM debian:trixie + +ENV DEBIAN_FRONTEND="noninteractive" + +RUN apt-get update && \ + apt-get install -y --no-install-recommends podman podman-compose \ + fuse-overlayfs slirp4netns uidmap iptables aardvark-dns nftables ca-certificates sudo \ + git ssh && \ + apt-get upgrade -y + +RUN useradd webgui -s /bin/bash && \ + echo "webgui:1001:64535" > /etc/subuid && \ + echo "webgui:1001:64535" > /etc/subgid + +ARG _REPO_URL="https://raw.githubusercontent.com/containers/image_build/refs/heads/main/podman" +ADD $_REPO_URL/containers.conf /etc/containers/containers.conf +ADD $_REPO_URL/podman-containers.conf /home/webgui/.config/containers/containers.conf + +RUN mkdir -p /home/webgui/.local/share/containers && \ + chown webgui:webgui -R /home/webgui && \ + chmod 0644 /etc/containers/containers.conf + +VOLUME /home/webgui/.local/share/containers + +# Replace setuid bits by proper file capabilities for uidmap binaries. +# See . +RUN apt-get install -y libcap2-bin && \ + chmod 0755 /usr/bin/newuidmap /usr/bin/newgidmap && \ + setcap cap_setuid=ep /usr/bin/newuidmap && \ + setcap cap_setgid=ep /usr/bin/newgidmap && \ + apt-get autoremove --purge -y libcap2-bin + +ENV _CONTAINERS_USERNS_CONFIGURED="" + +RUN SNIPPET="export PROMPT_COMMAND='history -a' && \ + export HISTFILE=/commandhistory/.bash_history" && \ + echo "$SNIPPET" >> "/root/.bashrc" + +#USER webgui +#WORKDIR /home/webgui + diff --git a/.devcontainer/compose.yml b/.devcontainer/compose.yml new file mode 100644 index 000000000..88d121223 --- /dev/null +++ b/.devcontainer/compose.yml @@ -0,0 +1,23 @@ +# compose.yml +version: '3.8' +volumes: + projectname-bashhistory: # Define named volume for bash history + +# Note: The 'bashhistory' service is used to persist bash history data across different containers. +services: +# bashhistory: +# volumes: +# - projectname-bashhistory:/commandhistory:z # Mount the named volume to /commandhistory in bashhistory service + + devcontainer: + container_name: devcontainer + privileged: true + hostname: devcontainer + build: + context: . + dockerfile: Containerfile + volumes: + - ..:/workspace:cached # Mount parent directory to workspace + - projectname-bashhistory:/commandhistory:z # Mount the named volume to /commandhistory in devcontainer service + command: sleep infinity + diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json new file mode 100644 index 000000000..32ceba81b --- /dev/null +++ b/.devcontainer/devcontainer.json @@ -0,0 +1,35 @@ +// devcontainer.json +// For format details, see https://aka.ms/devcontainer.json. For config options, see the +// README at: https://github.com/devcontainers/templates/tree/main/src/debian +{ + "name": "devcontainer", + // Or use a Dockerfile or Docker Compose file. More info: https://containers.dev/guide/dockerfile +// "image": "mcr.microsoft.com/devcontainers/base:trixie" +// "build": { +// "dockerfile": "Dockerfile" +// } + "dockerComposeFile": "compose.yml", + "service": "devcontainer", + + // default workspace path in container to open + "workspaceFolder": "/workspace", //${localWorkspaceFolder}" + +// "mounts": [ +// "source=projectname-bashhistory,target=/commandhistory,type=volume" +// ], + "postCreateCommand": { + "Fix Volume Permissions": "chown -R $(whoami): /commandhistory" + } + + // Features to add to the dev container. More info: https://containers.dev/features. + // "features": {}, + + // Use 'forwardPorts' to make a list of ports inside the container available locally. + // "forwardPorts": [], + + // Configure tool-specific properties. + // "customizations": {}, + + // Uncomment to connect as root instead. More info: https://aka.ms/dev-containers-non-root. + // "remoteUser": "root" +} diff --git a/.devcontainer/memory/MEMORY.md b/.devcontainer/memory/MEMORY.md new file mode 100644 index 000000000..dcfb49d98 --- /dev/null +++ b/.devcontainer/memory/MEMORY.md @@ -0,0 +1 @@ +- [Uses podman not docker](user_podman.md) — uses podman and podman-compose instead of Docker diff --git a/.devcontainer/memory/user_podman.md b/.devcontainer/memory/user_podman.md new file mode 100644 index 000000000..9c61c1eba --- /dev/null +++ b/.devcontainer/memory/user_podman.md @@ -0,0 +1,8 @@ +--- +name: user_podman +description: User uses podman and podman-compose, not Docker +metadata: + type: user +--- + +Uses **podman** and **podman-compose** for containerization, not Docker/Docker Compose. Compose file format is identical but the runtime and tooling is different. diff --git a/Dockerfile b/Dockerfile index bee1e043b..33d07a262 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,11 +1,16 @@ +# Podman Containerfile +# build via compose.yml or: +# podman image build -q -t debian:podman-trixie -f Containerfile . FROM debian:trixie -ENV DEBIAN_FRONTEND=noninteractive +ENV DEBIAN_FRONTEND="noninteractive" RUN apt update && apt -y install perl cpanminus libaspell-dev make libdbd-mysql-perl libdigest-perl-md5-perl libxml-simple-perl \ libmodule-install-perl gcc libperl-dev default-libmysqlclient-dev libpng-dev build-essential libgd-dev mariadb-client imagemagick \ libpng-dev libjpeg-dev libtiff-dev libapache2-mod-perl2 libapache2-mod-perl2-dev libapache2-request-perl libimage-magick-perl vim \ - apache2 apache2-utils mailutils + apache2 apache2-utils mailutils \ +# could be removed for production: + curl procps RUN cpanm --notest --no-cache --force \ @@ -168,6 +173,11 @@ RUN useradd --home=/data/WebGUI webgui; chown -R webgui: /data/WebGUI; chmod 755 #USER webgui +# zorgt voor een andere shell prompt in de container gestart in de development container +# ook wanneer die in dezelfde UTC namespace zit - always /after/ USER command +ENV CONTAINER_CONTEXT=inner +RUN printf '%s\n' 'export PS1="\u@${CONTAINER_CONTEXT}:\w\\$ "' >> ~/.bashrc + WORKDIR /data/WebGUI CMD [ "/entrypoint" ] diff --git a/distribution/docker-compose.yml b/distribution/docker-compose.yml index af39eaf88..2d64ab285 100644 --- a/distribution/docker-compose.yml +++ b/distribution/docker-compose.yml @@ -29,7 +29,7 @@ services: - "80" nginx-proxy: - image: nginx:latest + image: docker.io/nginx:latest container_name: nginx_proxy depends_on: - webgui