mirror of
https://github.com/linuxserver/docker-swag.git
synced 2026-03-11 20:55:16 +09:00
Compare commits
419 Commits
2.6.0-ls23
...
5.1.0-ls42
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
012b4ac68f | ||
|
|
8961b7e923 | ||
|
|
1e3524f927 | ||
|
|
a2f969a62e | ||
|
|
caaaccb0b3 | ||
|
|
ae11ca79a0 | ||
|
|
9d7c0d6239 | ||
|
|
eb151ebd19 | ||
|
|
4076c6b012 | ||
|
|
8437debed5 | ||
|
|
0f177af593 | ||
|
|
23dd0531f1 | ||
|
|
56d0503cb3 | ||
|
|
9397e9c70f | ||
|
|
e87649ffcd | ||
|
|
e11a8ded00 | ||
|
|
576de0400c | ||
|
|
ad2d99029a | ||
|
|
b8d0c422ab | ||
|
|
07c7399089 | ||
|
|
2d9590691c | ||
|
|
72e5347c3b | ||
|
|
be7016bcc1 | ||
|
|
ccd2464a26 | ||
|
|
fb4ba0deb0 | ||
|
|
7d8332e624 | ||
|
|
0e19ad9d0f | ||
|
|
d9dbcd0756 | ||
|
|
8381b03a05 | ||
|
|
a1efcf3cd4 | ||
|
|
834de14952 | ||
|
|
8353859972 | ||
|
|
f491b59335 | ||
|
|
ca399a7fa2 | ||
|
|
d602e9bccf | ||
|
|
284a8c66f9 | ||
|
|
1905b3c920 | ||
|
|
c9efb531b0 | ||
|
|
26d05580ef | ||
|
|
a2a7292e39 | ||
|
|
5316c58910 | ||
|
|
fa860e1349 | ||
|
|
72f60b132b | ||
|
|
24cf84fd61 | ||
|
|
d4ceeb2f67 | ||
|
|
1282274a1a | ||
|
|
b05df6cf2a | ||
|
|
b96738cdf2 | ||
|
|
2d6a54a526 | ||
|
|
bb78c0f50e | ||
|
|
56ff1d5e19 | ||
|
|
7f9835b43f | ||
|
|
f3ac0dd394 | ||
|
|
0168126729 | ||
|
|
0e55f7b67e | ||
|
|
b52e35e494 | ||
|
|
ef2a5f2077 | ||
|
|
0c910b9a7b | ||
|
|
9ab0f727d0 | ||
|
|
adcdf5d748 | ||
|
|
7a38630c0b | ||
|
|
6b6e7b74b5 | ||
|
|
3b6d0484b9 | ||
|
|
0d952bcee1 | ||
|
|
35deb8f654 | ||
|
|
2ec9bacf0c | ||
|
|
bcbad63147 | ||
|
|
962c2322eb | ||
|
|
dd8fd8ad05 | ||
|
|
b818ae1f58 | ||
|
|
43466fe490 | ||
|
|
3781360d72 | ||
|
|
a01e4aca17 | ||
|
|
b87c9d2886 | ||
|
|
08aa9cc07b | ||
|
|
23e05f1f7a | ||
|
|
f80d14bf8c | ||
|
|
a5f1da0bcf | ||
|
|
7e7e22753c | ||
|
|
9f76c031fe | ||
|
|
2b2ccf9e9a | ||
|
|
54ed99d81a | ||
|
|
a3f72898ff | ||
|
|
8b8d33a81a | ||
|
|
82ba5dd791 | ||
|
|
e7c815c27f | ||
|
|
563ae7e9c5 | ||
|
|
8caf2a1841 | ||
|
|
15a3bc9d2c | ||
|
|
1567416bfb | ||
|
|
f909c85857 | ||
|
|
2992a09e32 | ||
|
|
5a8b8010ee | ||
|
|
586eaa3b4c | ||
|
|
2528e2f027 | ||
|
|
4632ecb91a | ||
|
|
615ccbc589 | ||
|
|
199d0a6707 | ||
|
|
f8171d73ce | ||
|
|
503578a870 | ||
|
|
b4978e40c5 | ||
|
|
ed765dbdc1 | ||
|
|
6fcd946c0a | ||
|
|
c1d1a87a0c | ||
|
|
990c95b7d9 | ||
|
|
d83dc89c84 | ||
|
|
7046e938e0 | ||
|
|
27e2e83f03 | ||
|
|
f11dbcea78 | ||
|
|
07e9ada724 | ||
|
|
ae72916deb | ||
|
|
06b385d25c | ||
|
|
8753119d54 | ||
|
|
1f2cc4ade5 | ||
|
|
fc0986b0be | ||
|
|
564fbd271a | ||
|
|
bffc4c9236 | ||
|
|
14cab18c36 | ||
|
|
c0adf4fd0a | ||
|
|
2160126f96 | ||
|
|
d81e33b63b | ||
|
|
21b5a79e06 | ||
|
|
02ed03a455 | ||
|
|
515fdf45d8 | ||
|
|
5a5d0ebaec | ||
|
|
37deacf13a | ||
|
|
16d5763dcc | ||
|
|
e12d7e642c | ||
|
|
0cddb6d6b7 | ||
|
|
ff8cf3bfa5 | ||
|
|
db05a6b72b | ||
|
|
410fa0515e | ||
|
|
e1ece8ac1c | ||
|
|
d33df2224b | ||
|
|
3b98b3ae65 | ||
|
|
af6a3a2163 | ||
|
|
7a8a360746 | ||
|
|
f467b9539b | ||
|
|
3aae7b50d9 | ||
|
|
98e22cb66d | ||
|
|
0a9c7ff821 | ||
|
|
6dd89c8232 | ||
|
|
d376c95088 | ||
|
|
9a63c22e77 | ||
|
|
29bd5fe1b7 | ||
|
|
2e005369f1 | ||
|
|
d9a92bd940 | ||
|
|
892cf960a9 | ||
|
|
aaa6ae77b5 | ||
|
|
c489e2c07f | ||
|
|
7f4aabeef7 | ||
|
|
03f8285212 | ||
|
|
589b80e492 | ||
|
|
2dc24f90c7 | ||
|
|
e56ade75fb | ||
|
|
584ca6732c | ||
|
|
4e109fb858 | ||
|
|
4788f2b855 | ||
|
|
397106ec30 | ||
|
|
ab9d0b8037 | ||
|
|
19e9b1158d | ||
|
|
0a87bdaba8 | ||
|
|
2f2d7033b1 | ||
|
|
cbc7b3de09 | ||
|
|
73806b2032 | ||
|
|
f3c87c3935 | ||
|
|
20a134924f | ||
|
|
9971d2f50b | ||
|
|
4e1f959980 | ||
|
|
f94e685a65 | ||
|
|
bfeeaaaa73 | ||
|
|
4437f6f8ba | ||
|
|
ed7c58a4c3 | ||
|
|
ca3830de35 | ||
|
|
e932493428 | ||
|
|
cd77a9cd2a | ||
|
|
7e9db0db80 | ||
|
|
ffecc6ee8b | ||
|
|
2b18659591 | ||
|
|
54e3eeb6e8 | ||
|
|
7066b4c1ea | ||
|
|
66ea2cbad6 | ||
|
|
139a27f1bf | ||
|
|
d107e3cbef | ||
|
|
08e91b3dc3 | ||
|
|
8decebad67 | ||
|
|
7b828b92e8 | ||
|
|
db6fbc2731 | ||
|
|
aaee5b4737 | ||
|
|
30165272ef | ||
|
|
1c052fdd0d | ||
|
|
b569c84976 | ||
|
|
c14b42f85d | ||
|
|
60b6827133 | ||
|
|
cef4d471e1 | ||
|
|
eaafc4393b | ||
|
|
94c72584a7 | ||
|
|
59d1c8a724 | ||
|
|
ed0c949267 | ||
|
|
5027f6f7b3 | ||
|
|
502d10303c | ||
|
|
05bccb95ab | ||
|
|
00afe35e21 | ||
|
|
e1340c6c9e | ||
|
|
96998a1002 | ||
|
|
4fb557dcda | ||
|
|
ea13c5a885 | ||
|
|
ee0f1247d9 | ||
|
|
a8cf2c5c40 | ||
|
|
62faebf642 | ||
|
|
81e65837ca | ||
|
|
a08edc14d2 | ||
|
|
edf1abd83a | ||
|
|
0357efea87 | ||
|
|
aa103ce997 | ||
|
|
20bbf040e0 | ||
|
|
e4a6e31b6f | ||
|
|
5b096a8a66 | ||
|
|
eb6dba6cbe | ||
|
|
afd6c9d827 | ||
|
|
daa84f28b4 | ||
|
|
cd931076e4 | ||
|
|
f5ce44887f | ||
|
|
875a17dfc7 | ||
|
|
210134745d | ||
|
|
9d469c2957 | ||
|
|
37e64ebdac | ||
|
|
47fc525094 | ||
|
|
625b11d21c | ||
|
|
77accb3762 | ||
|
|
7dcce8b346 | ||
|
|
03286fc238 | ||
|
|
7391dc1bcf | ||
|
|
a7ea6a955b | ||
|
|
e149638808 | ||
|
|
41cb7cb104 | ||
|
|
1499cbe7de | ||
|
|
5a7d49ec43 | ||
|
|
05b586d6df | ||
|
|
d6d1432ff8 | ||
|
|
efc2f55f48 | ||
|
|
95c13d0082 | ||
|
|
e05fc4b1e3 | ||
|
|
099e0e75a4 | ||
|
|
fc1675f3a1 | ||
|
|
dc1bc6d5b3 | ||
|
|
db6f61bd27 | ||
|
|
67f864c7b9 | ||
|
|
3f885d0415 | ||
|
|
280c4bde4b | ||
|
|
59e7865464 | ||
|
|
5c58fa9383 | ||
|
|
ae19b93cc7 | ||
|
|
5dee340726 | ||
|
|
3109ff8d9c | ||
|
|
4239dc22d4 | ||
|
|
44c6bd721b | ||
|
|
d4a6be8fad | ||
|
|
a66b478d1d | ||
|
|
9efac76e25 | ||
|
|
23c6384f2c | ||
|
|
13ede8ea87 | ||
|
|
a9391d07ee | ||
|
|
a00d272297 | ||
|
|
0207bd8f30 | ||
|
|
3fd209d686 | ||
|
|
87ced3fd3e | ||
|
|
3e342b0529 | ||
|
|
c9504bb55f | ||
|
|
2573149089 | ||
|
|
9b3f418afd | ||
|
|
c63b437e1f | ||
|
|
f14c6a7a3a | ||
|
|
4b4c103df4 | ||
|
|
26203c8c40 | ||
|
|
259850fcc5 | ||
|
|
c6474f07ea | ||
|
|
b6a196b93a | ||
|
|
3967276f06 | ||
|
|
4853736c4e | ||
|
|
a8d03c5280 | ||
|
|
907dfc8c03 | ||
|
|
bf21a51e10 | ||
|
|
32f72ac0b4 | ||
|
|
970fa75e87 | ||
|
|
137ad9f52e | ||
|
|
5d0ec79ac5 | ||
|
|
3145477f72 | ||
|
|
58b9470c52 | ||
|
|
68f5cf8d9e | ||
|
|
e8d452f4ce | ||
|
|
4abd6c9890 | ||
|
|
c335faabdc | ||
|
|
204dd90f9d | ||
|
|
92bfbc19cd | ||
|
|
cb3c74a6ee | ||
|
|
b7f40863fe | ||
|
|
ec6fca9418 | ||
|
|
25a2832056 | ||
|
|
3eabd75388 | ||
|
|
6ed17c1d52 | ||
|
|
e568785908 | ||
|
|
bcee5182e6 | ||
|
|
514cf42606 | ||
|
|
270a0d57c9 | ||
|
|
6f51d8be26 | ||
|
|
d915d516cd | ||
|
|
ffb03a03f5 | ||
|
|
9693b5884f | ||
|
|
87ca95c8c2 | ||
|
|
1a376a6975 | ||
|
|
8e74593f2c | ||
|
|
00d1bce24d | ||
|
|
be853fcb4b | ||
|
|
2fb6c1f51f | ||
|
|
9339d287d2 | ||
|
|
6b62a27bf0 | ||
|
|
c50ca83ef9 | ||
|
|
bd94a67024 | ||
|
|
11e060174b | ||
|
|
5f8a531a93 | ||
|
|
d2f843c4d1 | ||
|
|
ad6bb30bfc | ||
|
|
11991aa0b3 | ||
|
|
c76e664965 | ||
|
|
ccbd19fe62 | ||
|
|
2573b79bad | ||
|
|
0e5ba91588 | ||
|
|
4f92460b29 | ||
|
|
ad1884e5b4 | ||
|
|
70bea0a816 | ||
|
|
85e44eb399 | ||
|
|
4d3f30b67c | ||
|
|
9da97969f8 | ||
|
|
2cd84ad12b | ||
|
|
757ef31216 | ||
|
|
767aad2286 | ||
|
|
4cb18bc106 | ||
|
|
b1cf98d214 | ||
|
|
48dfde26c7 | ||
|
|
320404d358 | ||
|
|
52ae487bea | ||
|
|
65f62d14a6 | ||
|
|
accd20cc7a | ||
|
|
24b3540da5 | ||
|
|
bc31b51afb | ||
|
|
bf6ab14281 | ||
|
|
7c5d1d886c | ||
|
|
5b77a54620 | ||
|
|
3b1478667b | ||
|
|
0ddf8a270b | ||
|
|
dabbaa3b14 | ||
|
|
bdd5e047ee | ||
|
|
78689b02e2 | ||
|
|
6c1c4cd00a | ||
|
|
31cef5050f | ||
|
|
52e8f7223e | ||
|
|
1abab5cb6d | ||
|
|
0061faef15 | ||
|
|
6e64bcbd7e | ||
|
|
b9dd1b7c5a | ||
|
|
e9bceab763 | ||
|
|
eba3c341fa | ||
|
|
5fc5825afd | ||
|
|
de18e4ef24 | ||
|
|
fbe212b67c | ||
|
|
2ca6807b64 | ||
|
|
e3560414dc | ||
|
|
2f4162578f | ||
|
|
2697b74a8c | ||
|
|
bd685533a2 | ||
|
|
287b952aea | ||
|
|
576b81ab91 | ||
|
|
8b0df1fcbb | ||
|
|
efdfa45f37 | ||
|
|
278b57fb47 | ||
|
|
82e85d22c1 | ||
|
|
8b49f2b0d4 | ||
|
|
10d0877547 | ||
|
|
8fdb472564 | ||
|
|
f6d0e3089a | ||
|
|
5ceac2e2ec | ||
|
|
5b6498b1a9 | ||
|
|
118a76530e | ||
|
|
0499547b96 | ||
|
|
9cf01a0085 | ||
|
|
2b5a2785d6 | ||
|
|
202db184b3 | ||
|
|
3ed39caf43 | ||
|
|
9353e4e8a5 | ||
|
|
39e3159f39 | ||
|
|
9ba44dccee | ||
|
|
49f6fb2b6e | ||
|
|
693c24173b | ||
|
|
8a90cf85d8 | ||
|
|
fd958fe6b3 | ||
|
|
eb8f12b5de | ||
|
|
dae223ca0f | ||
|
|
14226ce700 | ||
|
|
b64bb62303 | ||
|
|
f478a200e8 | ||
|
|
40200982d1 | ||
|
|
3476f8b6f6 | ||
|
|
3e9dc80ed4 | ||
|
|
4486d528d1 | ||
|
|
e0032ecfd4 | ||
|
|
b1c1262a2c | ||
|
|
3b49643c78 | ||
|
|
23728cba0b | ||
|
|
7e1db9c562 | ||
|
|
919b8ac152 | ||
|
|
0f9d247ba4 | ||
|
|
cab0b86b65 | ||
|
|
4d3875d37e | ||
|
|
badea52047 | ||
|
|
97baf76a10 | ||
|
|
0b738d9ee0 | ||
|
|
269e9cdd3f | ||
|
|
17387674b8 |
0
.editorconfig
Executable file → Normal file
0
.editorconfig
Executable file → Normal file
6
.github/CONTRIBUTING.md
vendored
6
.github/CONTRIBUTING.md
vendored
@@ -6,7 +6,7 @@
|
|||||||
* Read, and fill the Pull Request template
|
* Read, and fill the Pull Request template
|
||||||
* If this is a fix for a typo (in code, documentation, or the README) please file an issue and let us sort it out. We do not need a PR
|
* If this is a fix for a typo (in code, documentation, or the README) please file an issue and let us sort it out. We do not need a PR
|
||||||
* If the PR is addressing an existing issue include, closes #\<issue number>, in the body of the PR commit message
|
* If the PR is addressing an existing issue include, closes #\<issue number>, in the body of the PR commit message
|
||||||
* If you want to discuss changes, you can also bring it up in [#dev-talk](https://discordapp.com/channels/354974912613449730/757585807061155840) in our [Discord server](https://discord.gg/YWrKVTn)
|
* If you want to discuss changes, you can also bring it up in [#dev-talk](https://discordapp.com/channels/354974912613449730/757585807061155840) in our [Discord server](https://linuxserver.io/discord)
|
||||||
|
|
||||||
## Common files
|
## Common files
|
||||||
|
|
||||||
@@ -105,10 +105,10 @@ docker build \
|
|||||||
-t linuxserver/swag:latest .
|
-t linuxserver/swag:latest .
|
||||||
```
|
```
|
||||||
|
|
||||||
The ARM variants can be built on x86_64 hardware using `multiarch/qemu-user-static`
|
The ARM variants can be built on x86_64 hardware and vice versa using `lscr.io/linuxserver/qemu-static`
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker run --rm --privileged multiarch/qemu-user-static:register --reset
|
docker run --rm --privileged lscr.io/linuxserver/qemu-static --reset
|
||||||
```
|
```
|
||||||
|
|
||||||
Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64`.
|
Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64`.
|
||||||
|
|||||||
0
.github/FUNDING.yml
vendored
Executable file → Normal file
0
.github/FUNDING.yml
vendored
Executable file → Normal file
2
.github/ISSUE_TEMPLATE/config.yml
vendored
Executable file → Normal file
2
.github/ISSUE_TEMPLATE/config.yml
vendored
Executable file → Normal file
@@ -1,7 +1,7 @@
|
|||||||
blank_issues_enabled: false
|
blank_issues_enabled: false
|
||||||
contact_links:
|
contact_links:
|
||||||
- name: Discord chat support
|
- name: Discord chat support
|
||||||
url: https://discord.gg/YWrKVTn
|
url: https://linuxserver.io/discord
|
||||||
about: Realtime support / chat with the community and the team.
|
about: Realtime support / chat with the community and the team.
|
||||||
|
|
||||||
- name: Discourse discussion forum
|
- name: Discourse discussion forum
|
||||||
|
|||||||
4
.github/ISSUE_TEMPLATE/issue.bug.yml
vendored
Executable file → Normal file
4
.github/ISSUE_TEMPLATE/issue.bug.yml
vendored
Executable file → Normal file
@@ -67,10 +67,10 @@ body:
|
|||||||
- type: textarea
|
- type: textarea
|
||||||
attributes:
|
attributes:
|
||||||
description: |
|
description: |
|
||||||
Provide a full docker log, output of "docker logs linuxserver.io"
|
Provide a full docker log, output of "docker logs swag"
|
||||||
label: Container logs
|
label: Container logs
|
||||||
placeholder: |
|
placeholder: |
|
||||||
Output of `docker logs linuxserver.io`
|
Output of `docker logs swag`
|
||||||
render: bash
|
render: bash
|
||||||
validations:
|
validations:
|
||||||
required: true
|
required: true
|
||||||
|
|||||||
0
.github/ISSUE_TEMPLATE/issue.feature.yml
vendored
Executable file → Normal file
0
.github/ISSUE_TEMPLATE/issue.feature.yml
vendored
Executable file → Normal file
3
.github/workflows/call_issue_pr_tracker.yml
vendored
Executable file → Normal file
3
.github/workflows/call_issue_pr_tracker.yml
vendored
Executable file → Normal file
@@ -8,6 +8,9 @@ on:
|
|||||||
pull_request_review:
|
pull_request_review:
|
||||||
types: [submitted,edited,dismissed]
|
types: [submitted,edited,dismissed]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
manage-project:
|
manage-project:
|
||||||
permissions:
|
permissions:
|
||||||
|
|||||||
3
.github/workflows/call_issues_cron.yml
vendored
Executable file → Normal file
3
.github/workflows/call_issues_cron.yml
vendored
Executable file → Normal file
@@ -4,6 +4,9 @@ on:
|
|||||||
- cron: '35 15 * * *'
|
- cron: '35 15 * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
stale:
|
stale:
|
||||||
permissions:
|
permissions:
|
||||||
|
|||||||
145
.github/workflows/external_trigger.yml
vendored
145
.github/workflows/external_trigger.yml
vendored
@@ -3,26 +3,42 @@ name: External Trigger Main
|
|||||||
on:
|
on:
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
external-trigger-master:
|
external-trigger-master:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v3.1.0
|
- uses: actions/checkout@v4.1.1
|
||||||
|
|
||||||
- name: External Trigger
|
- name: External Trigger
|
||||||
if: github.ref == 'refs/heads/master'
|
if: github.ref == 'refs/heads/master'
|
||||||
|
env:
|
||||||
|
SKIP_EXTERNAL_TRIGGER: ${{ vars.SKIP_EXTERNAL_TRIGGER }}
|
||||||
run: |
|
run: |
|
||||||
if [ -n "${{ secrets.PAUSE_EXTERNAL_TRIGGER_SWAG_MASTER }}" ]; then
|
printf "# External trigger for docker-swag\n\n" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Github secret PAUSE_EXTERNAL_TRIGGER_SWAG_MASTER is set; skipping trigger. ****"
|
if grep -q "^swag_master_" <<< "${SKIP_EXTERNAL_TRIGGER}"; then
|
||||||
echo "Github secret \`PAUSE_EXTERNAL_TRIGGER_SWAG_MASTER\` is set; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
echo "> [!NOTE]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Github organizational variable \`SKIP_EXTERNAL_TRIGGER\` contains \`swag_master_\`; will skip trigger if version matches." >> $GITHUB_STEP_SUMMARY
|
||||||
|
elif grep -q "^swag_master" <<< "${SKIP_EXTERNAL_TRIGGER}"; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Github organizational variable \`SKIP_EXTERNAL_TRIGGER\` contains \`swag_master\`; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
||||||
exit 0
|
exit 0
|
||||||
fi
|
fi
|
||||||
echo "**** External trigger running off of master branch. To disable this trigger, set a Github secret named \"PAUSE_EXTERNAL_TRIGGER_SWAG_MASTER\". ****"
|
echo "> [!NOTE]" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "External trigger running off of master branch. To disable this trigger, set a Github secret named \`PAUSE_EXTERNAL_TRIGGER_SWAG_MASTER\`" >> $GITHUB_STEP_SUMMARY
|
echo "> External trigger running off of master branch. To disable this trigger, add \`swag_master\` into the Github organizational variable \`SKIP_EXTERNAL_TRIGGER\`." >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Retrieving external version ****"
|
printf "\n## Retrieving external version\n\n" >> $GITHUB_STEP_SUMMARY
|
||||||
EXT_RELEASE=$(curl -sL "https://pypi.python.org/pypi/certbot/json" |jq -r '. | .info.version')
|
EXT_RELEASE=$(curl -sL "https://pypi.python.org/pypi/certbot/json" |jq -r '. | .info.version')
|
||||||
|
echo "Type is \`pip_version\`" >> $GITHUB_STEP_SUMMARY
|
||||||
|
if grep -q "^swag_master_${EXT_RELEASE}" <<< "${SKIP_EXTERNAL_TRIGGER}"; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Github organizational variable \`SKIP_EXTERNAL_TRIGGER\` matches current external release; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
||||||
|
exit 0
|
||||||
|
fi
|
||||||
if [ -z "${EXT_RELEASE}" ] || [ "${EXT_RELEASE}" == "null" ]; then
|
if [ -z "${EXT_RELEASE}" ] || [ "${EXT_RELEASE}" == "null" ]; then
|
||||||
echo "**** Can't retrieve external version, exiting ****"
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Can't retrieve external version, exiting" >> $GITHUB_STEP_SUMMARY
|
||||||
FAILURE_REASON="Can't retrieve external version for swag branch master"
|
FAILURE_REASON="Can't retrieve external version for swag branch master"
|
||||||
GHA_TRIGGER_URL="https://github.com/linuxserver/docker-swag/actions/runs/${{ github.run_id }}"
|
GHA_TRIGGER_URL="https://github.com/linuxserver/docker-swag/actions/runs/${{ github.run_id }}"
|
||||||
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 16711680,
|
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 16711680,
|
||||||
@@ -30,25 +46,43 @@ jobs:
|
|||||||
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
EXT_RELEASE=$(echo ${EXT_RELEASE} | sed 's/[~,%@+;:/]//g')
|
EXT_RELEASE_SANITIZED=$(echo ${EXT_RELEASE} | sed 's/[~,%@+;:/]//g')
|
||||||
echo "**** External version: ${EXT_RELEASE} ****"
|
echo "Sanitized external version: \`${EXT_RELEASE_SANITIZED}\`" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "External version: ${EXT_RELEASE}" >> $GITHUB_STEP_SUMMARY
|
echo "Retrieving last pushed version" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Retrieving last pushed version ****"
|
|
||||||
image="linuxserver/swag"
|
image="linuxserver/swag"
|
||||||
tag="latest"
|
tag="latest"
|
||||||
token=$(curl -sX GET \
|
token=$(curl -sX GET \
|
||||||
"https://ghcr.io/token?scope=repository%3Alinuxserver%2Fswag%3Apull" \
|
"https://ghcr.io/token?scope=repository%3Alinuxserver%2Fswag%3Apull" \
|
||||||
| jq -r '.token')
|
| jq -r '.token')
|
||||||
multidigest=$(curl -s \
|
multidigest=$(curl -s \
|
||||||
|
--header "Accept: application/vnd.docker.distribution.manifest.v2+json" \
|
||||||
|
--header "Accept: application/vnd.oci.image.index.v1+json" \
|
||||||
|
--header "Authorization: Bearer ${token}" \
|
||||||
|
"https://ghcr.io/v2/${image}/manifests/${tag}")
|
||||||
|
if jq -e '.layers // empty' <<< "${multidigest}" >/dev/null 2>&1; then
|
||||||
|
# If there's a layer element it's a single-arch manifest so just get that digest
|
||||||
|
digest=$(jq -r '.config.digest' <<< "${multidigest}")
|
||||||
|
else
|
||||||
|
# Otherwise it's multi-arch or has manifest annotations
|
||||||
|
if jq -e '.manifests[]?.annotations // empty' <<< "${multidigest}" >/dev/null 2>&1; then
|
||||||
|
# Check for manifest annotations and delete if found
|
||||||
|
multidigest=$(jq 'del(.manifests[] | select(.annotations))' <<< "${multidigest}")
|
||||||
|
fi
|
||||||
|
if [[ $(jq '.manifests | length' <<< "${multidigest}") -gt 1 ]]; then
|
||||||
|
# If there's still more than one digest, it's multi-arch
|
||||||
|
multidigest=$(jq -r ".manifests[] | select(.platform.architecture == \"amd64\").digest?" <<< "${multidigest}")
|
||||||
|
else
|
||||||
|
# Otherwise it's single arch
|
||||||
|
multidigest=$(jq -r ".manifests[].digest?" <<< "${multidigest}")
|
||||||
|
fi
|
||||||
|
if digest=$(curl -s \
|
||||||
--header "Accept: application/vnd.docker.distribution.manifest.v2+json" \
|
--header "Accept: application/vnd.docker.distribution.manifest.v2+json" \
|
||||||
|
--header "Accept: application/vnd.oci.image.manifest.v1+json" \
|
||||||
--header "Authorization: Bearer ${token}" \
|
--header "Authorization: Bearer ${token}" \
|
||||||
"https://ghcr.io/v2/${image}/manifests/${tag}" \
|
"https://ghcr.io/v2/${image}/manifests/${multidigest}"); then
|
||||||
| jq -r 'first(.manifests[].digest)')
|
digest=$(jq -r '.config.digest' <<< "${digest}");
|
||||||
digest=$(curl -s \
|
fi
|
||||||
--header "Accept: application/vnd.docker.distribution.manifest.v2+json" \
|
fi
|
||||||
--header "Authorization: Bearer ${token}" \
|
|
||||||
"https://ghcr.io/v2/${image}/manifests/${multidigest}" \
|
|
||||||
| jq -r '.config.digest')
|
|
||||||
image_info=$(curl -sL \
|
image_info=$(curl -sL \
|
||||||
--header "Authorization: Bearer ${token}" \
|
--header "Authorization: Bearer ${token}" \
|
||||||
"https://ghcr.io/v2/${image}/blobs/${digest}")
|
"https://ghcr.io/v2/${image}/blobs/${digest}")
|
||||||
@@ -60,45 +94,54 @@ jobs:
|
|||||||
IMAGE_RELEASE=$(echo ${image_info} | jq -r '.Labels.build_version' | awk '{print $3}')
|
IMAGE_RELEASE=$(echo ${image_info} | jq -r '.Labels.build_version' | awk '{print $3}')
|
||||||
IMAGE_VERSION=$(echo ${IMAGE_RELEASE} | awk -F'-ls' '{print $1}')
|
IMAGE_VERSION=$(echo ${IMAGE_RELEASE} | awk -F'-ls' '{print $1}')
|
||||||
if [ -z "${IMAGE_VERSION}" ]; then
|
if [ -z "${IMAGE_VERSION}" ]; then
|
||||||
echo "**** Can't retrieve last pushed version, exiting ****"
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "Can't retrieve last pushed version, exiting" >> $GITHUB_STEP_SUMMARY
|
||||||
FAILURE_REASON="Can't retrieve last pushed version for swag tag latest"
|
FAILURE_REASON="Can't retrieve last pushed version for swag tag latest"
|
||||||
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 16711680,
|
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 16711680,
|
||||||
"description": "**Trigger Failed** \n**Reason:** '"${FAILURE_REASON}"' \n"}],
|
"description": "**Trigger Failed** \n**Reason:** '"${FAILURE_REASON}"' \n"}],
|
||||||
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
echo "**** Last pushed version: ${IMAGE_VERSION} ****"
|
echo "Last pushed version: \`${IMAGE_VERSION}\`" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "Last pushed version: ${IMAGE_VERSION}" >> $GITHUB_STEP_SUMMARY
|
if [ "${EXT_RELEASE_SANITIZED}" == "${IMAGE_VERSION}" ]; then
|
||||||
if [ "${EXT_RELEASE}" == "${IMAGE_VERSION}" ]; then
|
echo "Sanitized version \`${EXT_RELEASE_SANITIZED}\` already pushed, exiting" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Version ${EXT_RELEASE} already pushed, exiting ****"
|
|
||||||
echo "Version ${EXT_RELEASE} already pushed, exiting" >> $GITHUB_STEP_SUMMARY
|
|
||||||
exit 0
|
exit 0
|
||||||
elif [ $(curl -s https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/lastBuild/api/json | jq -r '.building') == "true" ]; then
|
elif [ $(curl -s https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/lastBuild/api/json | jq -r '.building') == "true" ]; then
|
||||||
echo "**** New version ${EXT_RELEASE} found; but there already seems to be an active build on Jenkins; exiting ****"
|
echo "New version \`${EXT_RELEASE}\` found; but there already seems to be an active build on Jenkins; exiting" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "New version ${EXT_RELEASE} found; but there already seems to be an active build on Jenkins; exiting" >> $GITHUB_STEP_SUMMARY
|
|
||||||
exit 0
|
exit 0
|
||||||
else
|
else
|
||||||
echo "**** New version ${EXT_RELEASE} found; old version was ${IMAGE_VERSION}. Triggering new build ****"
|
if [[ "${artifacts_found}" == "false" ]]; then
|
||||||
echo "New version ${EXT_RELEASE} found; old version was ${IMAGE_VERSION}. Triggering new build" >> $GITHUB_STEP_SUMMARY
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
response=$(curl -iX POST \
|
echo "> New version detected, but not all artifacts are published yet; skipping trigger" >> $GITHUB_STEP_SUMMARY
|
||||||
https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/buildWithParameters?PACKAGE_CHECK=false \
|
FAILURE_REASON="New version ${EXT_RELEASE} for swag tag latest is detected, however not all artifacts are uploaded to upstream release yet. Will try again later."
|
||||||
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} | grep -i location | sed "s|^[L|l]ocation: \(.*\)|\1|")
|
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 9802903,
|
||||||
echo "**** Jenkins job queue url: ${response%$'\r'} ****"
|
"description": "**Trigger Failed** \n**Reason:** '"${FAILURE_REASON}"' \n"}],
|
||||||
echo "**** Sleeping 10 seconds until job starts ****"
|
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
||||||
sleep 10
|
else
|
||||||
buildurl=$(curl -s "${response%$'\r'}api/json" | jq -r '.executable.url')
|
printf "\n## Trigger new build\n\n" >> $GITHUB_STEP_SUMMARY
|
||||||
buildurl="${buildurl%$'\r'}"
|
echo "New sanitized version \`${EXT_RELEASE_SANITIZED}\` found; old version was \`${IMAGE_VERSION}\`. Triggering new build" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Jenkins job build url: ${buildurl} ****"
|
if [[ "${artifacts_found}" == "true" ]]; then
|
||||||
echo "Jenkins job build url: ${buildurl}" >> $GITHUB_STEP_SUMMARY
|
echo "All artifacts seem to be uploaded." >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Attempting to change the Jenkins job description ****"
|
fi
|
||||||
curl -iX POST \
|
response=$(curl -iX POST \
|
||||||
"${buildurl}submitDescription" \
|
https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/buildWithParameters?PACKAGE_CHECK=false \
|
||||||
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} \
|
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} | grep -i location | sed "s|^[L|l]ocation: \(.*\)|\1|")
|
||||||
--data-urlencode "description=GHA external trigger https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
|
echo "Jenkins [job queue url](${response%$'\r'})" >> $GITHUB_STEP_SUMMARY
|
||||||
--data-urlencode "Submit=Submit"
|
echo "Sleeping 10 seconds until job starts" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "**** Notifying Discord ****"
|
sleep 10
|
||||||
TRIGGER_REASON="A version change was detected for swag tag latest. Old version:${IMAGE_VERSION} New version:${EXT_RELEASE}"
|
buildurl=$(curl -s "${response%$'\r'}api/json" | jq -r '.executable.url')
|
||||||
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 9802903,
|
buildurl="${buildurl%$'\r'}"
|
||||||
"description": "**Build Triggered** \n**Reason:** '"${TRIGGER_REASON}"' \n**Build URL:** '"${buildurl}display/redirect"' \n"}],
|
echo "Jenkins job [build url](${buildurl})" >> $GITHUB_STEP_SUMMARY
|
||||||
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
echo "Attempting to change the Jenkins job description" >> $GITHUB_STEP_SUMMARY
|
||||||
|
curl -iX POST \
|
||||||
|
"${buildurl}submitDescription" \
|
||||||
|
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} \
|
||||||
|
--data-urlencode "description=GHA external trigger https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
|
||||||
|
--data-urlencode "Submit=Submit"
|
||||||
|
echo "**** Notifying Discord ****"
|
||||||
|
TRIGGER_REASON="A version change was detected for swag tag latest. Old version:${IMAGE_VERSION} New version:${EXT_RELEASE_SANITIZED}"
|
||||||
|
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 9802903,
|
||||||
|
"description": "**Build Triggered** \n**Reason:** '"${TRIGGER_REASON}"' \n**Build URL:** '"${buildurl}display/redirect"' \n"}],
|
||||||
|
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|||||||
29
.github/workflows/external_trigger_scheduler.yml
vendored
29
.github/workflows/external_trigger_scheduler.yml
vendored
@@ -5,41 +5,44 @@ on:
|
|||||||
- cron: '2 * * * *'
|
- cron: '2 * * * *'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
external-trigger-scheduler:
|
external-trigger-scheduler:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v3.1.0
|
- uses: actions/checkout@v4.1.1
|
||||||
with:
|
with:
|
||||||
fetch-depth: '0'
|
fetch-depth: '0'
|
||||||
|
|
||||||
- name: External Trigger Scheduler
|
- name: External Trigger Scheduler
|
||||||
run: |
|
run: |
|
||||||
echo "**** Branches found: ****"
|
printf "# External trigger scheduler for docker-swag\n\n" >> $GITHUB_STEP_SUMMARY
|
||||||
git for-each-ref --format='%(refname:short)' refs/remotes
|
printf "Found the branches:\n\n%s\n" "$(git for-each-ref --format='- %(refname:lstrip=3)' refs/remotes)" >> $GITHUB_STEP_SUMMARY
|
||||||
for br in $(git for-each-ref --format='%(refname:short)' refs/remotes)
|
for br in $(git for-each-ref --format='%(refname:lstrip=3)' refs/remotes)
|
||||||
do
|
do
|
||||||
br=$(echo "$br" | sed 's|origin/||g')
|
if [[ "${br}" == "HEAD" ]]; then
|
||||||
echo "**** Evaluating branch ${br} ****"
|
printf "\nSkipping %s.\n" ${br} >> $GITHUB_STEP_SUMMARY
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
printf "\n## Evaluating \`%s\`\n\n" ${br} >> $GITHUB_STEP_SUMMARY
|
||||||
ls_jenkins_vars=$(curl -sX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/jenkins-vars.yml)
|
ls_jenkins_vars=$(curl -sX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/jenkins-vars.yml)
|
||||||
ls_branch=$(echo "${ls_jenkins_vars}" | yq -r '.ls_branch')
|
ls_branch=$(echo "${ls_jenkins_vars}" | yq -r '.ls_branch')
|
||||||
ls_trigger=$(echo "${ls_jenkins_vars}" | yq -r '.external_type')
|
ls_trigger=$(echo "${ls_jenkins_vars}" | yq -r '.external_type')
|
||||||
if [[ "${br}" == "${ls_branch}" ]] && [[ "${ls_trigger}" != "os" ]]; then
|
if [[ "${br}" == "${ls_branch}" ]] && [[ "${ls_trigger}" != "os" ]]; then
|
||||||
echo "**** Branch ${br} appears to be live and trigger is not os; checking workflow. ****"
|
echo "Branch appears to be live and trigger is not os; checking workflow." >> $GITHUB_STEP_SUMMARY
|
||||||
if curl -sfX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/.github/workflows/external_trigger.yml > /dev/null 2>&1; then
|
if curl -sfX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/.github/workflows/external_trigger.yml > /dev/null 2>&1; then
|
||||||
echo "**** Workflow exists. Triggering external trigger workflow for branch ${br} ****."
|
echo "Triggering external trigger workflow for branch." >> $GITHUB_STEP_SUMMARY
|
||||||
echo "Triggering external trigger workflow for branch ${br}" >> $GITHUB_STEP_SUMMARY
|
|
||||||
curl -iX POST \
|
curl -iX POST \
|
||||||
-H "Authorization: token ${{ secrets.CR_PAT }}" \
|
-H "Authorization: token ${{ secrets.CR_PAT }}" \
|
||||||
-H "Accept: application/vnd.github.v3+json" \
|
-H "Accept: application/vnd.github.v3+json" \
|
||||||
-d "{\"ref\":\"refs/heads/${br}\"}" \
|
-d "{\"ref\":\"refs/heads/${br}\"}" \
|
||||||
https://api.github.com/repos/linuxserver/docker-swag/actions/workflows/external_trigger.yml/dispatches
|
https://api.github.com/repos/linuxserver/docker-swag/actions/workflows/external_trigger.yml/dispatches
|
||||||
else
|
else
|
||||||
echo "**** Workflow doesn't exist; skipping trigger. ****"
|
echo "Skipping branch due to no external trigger workflow present." >> $GITHUB_STEP_SUMMARY
|
||||||
echo "Skipping branch ${br} due to no external trigger workflow present." >> $GITHUB_STEP_SUMMARY
|
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "**** ${br} is either a dev branch, or has no external version; skipping trigger. ****"
|
echo "Skipping branch due to being detected as dev branch or having no external version." >> $GITHUB_STEP_SUMMARY
|
||||||
echo "Skipping branch ${br} due to being detected as dev branch or having no external version." >> $GITHUB_STEP_SUMMARY
|
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
|
|||||||
6
.github/workflows/greetings.yml
vendored
6
.github/workflows/greetings.yml
vendored
@@ -2,8 +2,14 @@ name: Greetings
|
|||||||
|
|
||||||
on: [pull_request_target, issues]
|
on: [pull_request_target, issues]
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
greeting:
|
greeting:
|
||||||
|
permissions:
|
||||||
|
issues: write
|
||||||
|
pull-requests: write
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/first-interaction@v1
|
- uses: actions/first-interaction@v1
|
||||||
|
|||||||
42
.github/workflows/package_trigger.yml
vendored
42
.github/workflows/package_trigger.yml
vendored
@@ -1,42 +0,0 @@
|
|||||||
name: Package Trigger Main
|
|
||||||
|
|
||||||
on:
|
|
||||||
workflow_dispatch:
|
|
||||||
|
|
||||||
jobs:
|
|
||||||
package-trigger-master:
|
|
||||||
runs-on: ubuntu-latest
|
|
||||||
steps:
|
|
||||||
- uses: actions/checkout@v3.1.0
|
|
||||||
|
|
||||||
- name: Package Trigger
|
|
||||||
if: github.ref == 'refs/heads/master'
|
|
||||||
run: |
|
|
||||||
if [ -n "${{ secrets.PAUSE_PACKAGE_TRIGGER_SWAG_MASTER }}" ]; then
|
|
||||||
echo "**** Github secret PAUSE_PACKAGE_TRIGGER_SWAG_MASTER is set; skipping trigger. ****"
|
|
||||||
echo "Github secret \`PAUSE_PACKAGE_TRIGGER_SWAG_MASTER\` is set; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
if [ $(curl -s https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/lastBuild/api/json | jq -r '.building') == "true" ]; then
|
|
||||||
echo "**** There already seems to be an active build on Jenkins; skipping package trigger ****"
|
|
||||||
echo "There already seems to be an active build on Jenkins; skipping package trigger" >> $GITHUB_STEP_SUMMARY
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
echo "**** Package trigger running off of master branch. To disable, set a Github secret named \"PAUSE_PACKAGE_TRIGGER_SWAG_MASTER\". ****"
|
|
||||||
echo "Package trigger running off of master branch. To disable, set a Github secret named \`PAUSE_PACKAGE_TRIGGER_SWAG_MASTER\`" >> $GITHUB_STEP_SUMMARY
|
|
||||||
response=$(curl -iX POST \
|
|
||||||
https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/buildWithParameters?PACKAGE_CHECK=true \
|
|
||||||
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} | grep -i location | sed "s|^[L|l]ocation: \(.*\)|\1|")
|
|
||||||
echo "**** Jenkins job queue url: ${response%$'\r'} ****"
|
|
||||||
echo "**** Sleeping 10 seconds until job starts ****"
|
|
||||||
sleep 10
|
|
||||||
buildurl=$(curl -s "${response%$'\r'}api/json" | jq -r '.executable.url')
|
|
||||||
buildurl="${buildurl%$'\r'}"
|
|
||||||
echo "**** Jenkins job build url: ${buildurl} ****"
|
|
||||||
echo "Jenkins job build url: ${buildurl}" >> $GITHUB_STEP_SUMMARY
|
|
||||||
echo "**** Attempting to change the Jenkins job description ****"
|
|
||||||
curl -iX POST \
|
|
||||||
"${buildurl}submitDescription" \
|
|
||||||
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} \
|
|
||||||
--data-urlencode "description=GHA package trigger https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
|
|
||||||
--data-urlencode "Submit=Submit"
|
|
||||||
107
.github/workflows/package_trigger_scheduler.yml
vendored
107
.github/workflows/package_trigger_scheduler.yml
vendored
@@ -5,46 +5,99 @@ on:
|
|||||||
- cron: '1 3 * * 6'
|
- cron: '1 3 * * 6'
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
package-trigger-scheduler:
|
package-trigger-scheduler:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v3.1.0
|
- uses: actions/checkout@v4.1.1
|
||||||
with:
|
with:
|
||||||
fetch-depth: '0'
|
fetch-depth: '0'
|
||||||
|
|
||||||
- name: Package Trigger Scheduler
|
- name: Package Trigger Scheduler
|
||||||
|
env:
|
||||||
|
SKIP_PACKAGE_TRIGGER: ${{ vars.SKIP_PACKAGE_TRIGGER }}
|
||||||
run: |
|
run: |
|
||||||
echo "**** Branches found: ****"
|
printf "# Package trigger scheduler for docker-swag\n\n" >> $GITHUB_STEP_SUMMARY
|
||||||
git for-each-ref --format='%(refname:short)' refs/remotes
|
printf "Found the branches:\n\n%s\n" "$(git for-each-ref --format='- %(refname:lstrip=3)' refs/remotes)" >> $GITHUB_STEP_SUMMARY
|
||||||
for br in $(git for-each-ref --format='%(refname:short)' refs/remotes)
|
for br in $(git for-each-ref --format='%(refname:lstrip=3)' refs/remotes)
|
||||||
do
|
do
|
||||||
br=$(echo "$br" | sed 's|origin/||g')
|
if [[ "${br}" == "HEAD" ]]; then
|
||||||
echo "**** Evaluating branch ${br} ****"
|
printf "\nSkipping %s.\n" ${br} >> $GITHUB_STEP_SUMMARY
|
||||||
ls_branch=$(curl -sX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/jenkins-vars.yml | yq -r '.ls_branch')
|
continue
|
||||||
if [ "${br}" == "${ls_branch}" ]; then
|
fi
|
||||||
echo "**** Branch ${br} appears to be live; checking workflow. ****"
|
printf "\n## Evaluating \`%s\`\n\n" ${br} >> $GITHUB_STEP_SUMMARY
|
||||||
if curl -sfX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/.github/workflows/package_trigger.yml > /dev/null 2>&1; then
|
JENKINS_VARS=$(curl -sX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/jenkins-vars.yml)
|
||||||
echo "**** Workflow exists. Triggering package trigger workflow for branch ${br}. ****"
|
if ! curl -sfX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/Jenkinsfile >/dev/null 2>&1; then
|
||||||
echo "Triggering package trigger workflow for branch ${br}" >> $GITHUB_STEP_SUMMARY
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
triggered_branches="${triggered_branches}${br} "
|
echo "> No Jenkinsfile found. Branch is either deprecated or is an early dev branch." >> $GITHUB_STEP_SUMMARY
|
||||||
curl -iX POST \
|
skipped_branches="${skipped_branches}${br} "
|
||||||
-H "Authorization: token ${{ secrets.CR_PAT }}" \
|
elif [[ "${br}" == $(yq -r '.ls_branch' <<< "${JENKINS_VARS}") ]]; then
|
||||||
-H "Accept: application/vnd.github.v3+json" \
|
echo "Branch appears to be live; checking workflow." >> $GITHUB_STEP_SUMMARY
|
||||||
-d "{\"ref\":\"refs/heads/${br}\"}" \
|
README_VARS=$(curl -sX GET https://raw.githubusercontent.com/linuxserver/docker-swag/${br}/readme-vars.yml)
|
||||||
https://api.github.com/repos/linuxserver/docker-swag/actions/workflows/package_trigger.yml/dispatches
|
if [[ $(yq -r '.project_deprecation_status' <<< "${README_VARS}") == "true" ]]; then
|
||||||
sleep 30
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Branch appears to be deprecated; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
||||||
|
skipped_branches="${skipped_branches}${br} "
|
||||||
|
elif [[ $(yq -r '.skip_package_check' <<< "${JENKINS_VARS}") == "true" ]]; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Skipping branch ${br} due to \`skip_package_check\` being set in \`jenkins-vars.yml\`." >> $GITHUB_STEP_SUMMARY
|
||||||
|
skipped_branches="${skipped_branches}${br} "
|
||||||
|
elif grep -q "^swag_${br}" <<< "${SKIP_PACKAGE_TRIGGER}"; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Github organizational variable \`SKIP_PACKAGE_TRIGGER\` contains \`swag_${br}\`; skipping trigger." >> $GITHUB_STEP_SUMMARY
|
||||||
|
skipped_branches="${skipped_branches}${br} "
|
||||||
|
elif [ $(curl -s https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/${br}/lastBuild/api/json | jq -r '.building' 2>/dev/null) == "true" ]; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> There already seems to be an active build on Jenkins; skipping package trigger for ${br}" >> $GITHUB_STEP_SUMMARY
|
||||||
|
skipped_branches="${skipped_branches}${br} "
|
||||||
else
|
else
|
||||||
echo "**** Workflow doesn't exist; skipping trigger. ****"
|
echo "> [!NOTE]" >> $GITHUB_STEP_SUMMARY
|
||||||
echo "Skipping branch ${br} due to no package trigger workflow present." >> $GITHUB_STEP_SUMMARY
|
echo "> Triggering package trigger for branch ${br}" >> $GITHUB_STEP_SUMMARY
|
||||||
|
printf "> To disable, add \`swag_%s\` into the Github organizational variable \`SKIP_PACKAGE_TRIGGER\`.\n\n" "${br}" >> $GITHUB_STEP_SUMMARY
|
||||||
|
triggered_branches="${triggered_branches}${br} "
|
||||||
|
response=$(curl -iX POST \
|
||||||
|
https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/${br}/buildWithParameters?PACKAGE_CHECK=true \
|
||||||
|
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} | grep -i location | sed "s|^[L|l]ocation: \(.*\)|\1|")
|
||||||
|
if [[ -z "${response}" ]]; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Jenkins build could not be triggered. Skipping branch."
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
echo "Jenkins [job queue url](${response%$'\r'})" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "Sleeping 10 seconds until job starts" >> $GITHUB_STEP_SUMMARY
|
||||||
|
sleep 10
|
||||||
|
buildurl=$(curl -s "${response%$'\r'}api/json" | jq -r '.executable.url')
|
||||||
|
buildurl="${buildurl%$'\r'}"
|
||||||
|
echo "Jenkins job [build url](${buildurl})" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "Attempting to change the Jenkins job description" >> $GITHUB_STEP_SUMMARY
|
||||||
|
if ! curl -ifX POST \
|
||||||
|
"${buildurl}submitDescription" \
|
||||||
|
--user ${{ secrets.JENKINS_USER }}:${{ secrets.JENKINS_TOKEN }} \
|
||||||
|
--data-urlencode "description=GHA package trigger https://github.com/${{ github.repository }}/actions/runs/${{ github.run_id }}" \
|
||||||
|
--data-urlencode "Submit=Submit"; then
|
||||||
|
echo "> [!WARNING]" >> $GITHUB_STEP_SUMMARY
|
||||||
|
echo "> Unable to change the Jenkins job description."
|
||||||
|
fi
|
||||||
|
sleep 20
|
||||||
fi
|
fi
|
||||||
else
|
else
|
||||||
echo "**** ${br} appears to be a dev branch; skipping trigger. ****"
|
|
||||||
echo "Skipping branch ${br} due to being detected as dev branch." >> $GITHUB_STEP_SUMMARY
|
echo "Skipping branch ${br} due to being detected as dev branch." >> $GITHUB_STEP_SUMMARY
|
||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
echo "**** Package check build(s) triggered for branch(es): ${triggered_branches} ****"
|
if [[ -n "${triggered_branches}" ]] || [[ -n "${skipped_branches}" ]]; then
|
||||||
echo "**** Notifying Discord ****"
|
if [[ -n "${triggered_branches}" ]]; then
|
||||||
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 9802903,
|
NOTIFY_BRANCHES="**Triggered:** ${triggered_branches} \n"
|
||||||
"description": "**Package Check Build(s) Triggered for swag** \n**Branch(es):** '"${triggered_branches}"' \n**Build URL:** '"https://ci.linuxserver.io/blue/organizations/jenkins/Docker-Pipeline-Builders%2Fdocker-swag/activity/"' \n"}],
|
NOTIFY_BUILD_URL="**Build URL:** https://ci.linuxserver.io/blue/organizations/jenkins/Docker-Pipeline-Builders%2Fdocker-swag/activity/ \n"
|
||||||
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
echo "**** Package check build(s) triggered for branch(es): ${triggered_branches} ****"
|
||||||
|
fi
|
||||||
|
if [[ -n "${skipped_branches}" ]]; then
|
||||||
|
NOTIFY_BRANCHES="${NOTIFY_BRANCHES}**Skipped:** ${skipped_branches} \n"
|
||||||
|
fi
|
||||||
|
echo "**** Notifying Discord ****"
|
||||||
|
curl -X POST -H "Content-Type: application/json" --data '{"avatar_url": "https://cdn.discordapp.com/avatars/354986384542662657/df91181b3f1cf0ef1592fbe18e0962d7.png","embeds": [{"color": 9802903,
|
||||||
|
"description": "**Package Check Build(s) for swag** \n'"${NOTIFY_BRANCHES}"''"${NOTIFY_BUILD_URL}"'"}],
|
||||||
|
"username": "Github Actions"}' ${{ secrets.DISCORD_WEBHOOK }}
|
||||||
|
fi
|
||||||
|
|||||||
2
.github/workflows/permissions.yml
vendored
Executable file → Normal file
2
.github/workflows/permissions.yml
vendored
Executable file → Normal file
@@ -5,6 +5,8 @@ on:
|
|||||||
- '**/run'
|
- '**/run'
|
||||||
- '**/finish'
|
- '**/finish'
|
||||||
- '**/check'
|
- '**/check'
|
||||||
|
- 'root/migrations/*'
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
permission_check:
|
permission_check:
|
||||||
uses: linuxserver/github-workflows/.github/workflows/init-svc-executable-permissions.yml@v1
|
uses: linuxserver/github-workflows/.github/workflows/init-svc-executable-permissions.yml@v1
|
||||||
|
|||||||
1
.gitignore
vendored
1
.gitignore
vendored
@@ -1 +1,2 @@
|
|||||||
|
.idea
|
||||||
.jenkins-external
|
.jenkins-external
|
||||||
|
|||||||
87
Dockerfile
87
Dockerfile
@@ -1,6 +1,6 @@
|
|||||||
# syntax=docker/dockerfile:1
|
# syntax=docker/dockerfile:1
|
||||||
|
|
||||||
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:3.18
|
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:3.22
|
||||||
|
|
||||||
# set version label
|
# set version label
|
||||||
ARG BUILD_DATE
|
ARG BUILD_DATE
|
||||||
@@ -10,8 +10,10 @@ LABEL build_version="Linuxserver.io version:- ${VERSION} Build-date:- ${BUILD_DA
|
|||||||
LABEL maintainer="nemchik"
|
LABEL maintainer="nemchik"
|
||||||
|
|
||||||
# environment settings
|
# environment settings
|
||||||
ENV DHLEVEL=2048 ONLY_SUBDOMAINS=false AWS_CONFIG_FILE=/config/dns-conf/route53.ini
|
ENV DHLEVEL=2048 \
|
||||||
ENV S6_BEHAVIOUR_IF_STAGE2_FAILS=2
|
ONLY_SUBDOMAINS=false \
|
||||||
|
AWS_CONFIG_FILE=/config/dns-conf/route53.ini \
|
||||||
|
S6_BEHAVIOUR_IF_STAGE2_FAILS=2
|
||||||
|
|
||||||
RUN \
|
RUN \
|
||||||
echo "**** install build packages ****" && \
|
echo "**** install build packages ****" && \
|
||||||
@@ -27,6 +29,8 @@ RUN \
|
|||||||
apk add --no-cache \
|
apk add --no-cache \
|
||||||
fail2ban \
|
fail2ban \
|
||||||
gnupg \
|
gnupg \
|
||||||
|
inotify-tools \
|
||||||
|
iptables-legacy \
|
||||||
memcached \
|
memcached \
|
||||||
nginx-mod-http-brotli \
|
nginx-mod-http-brotli \
|
||||||
nginx-mod-http-dav-ext \
|
nginx-mod-http-dav-ext \
|
||||||
@@ -45,39 +49,37 @@ RUN \
|
|||||||
nginx-mod-stream \
|
nginx-mod-stream \
|
||||||
nginx-mod-stream-geoip2 \
|
nginx-mod-stream-geoip2 \
|
||||||
nginx-vim \
|
nginx-vim \
|
||||||
php82-bcmath \
|
php84-bcmath \
|
||||||
php82-bz2 \
|
php84-bz2 \
|
||||||
php82-dom \
|
php84-dom \
|
||||||
php82-exif \
|
php84-exif \
|
||||||
php82-ftp \
|
php84-ftp \
|
||||||
php82-gd \
|
php84-gd \
|
||||||
php82-gmp \
|
php84-gmp \
|
||||||
php82-imap \
|
php84-imap \
|
||||||
php82-intl \
|
php84-intl \
|
||||||
php82-ldap \
|
php84-ldap \
|
||||||
php82-mysqli \
|
php84-mysqli \
|
||||||
php82-mysqlnd \
|
php84-mysqlnd \
|
||||||
php82-opcache \
|
php84-opcache \
|
||||||
php82-pdo_mysql \
|
php84-pdo_mysql \
|
||||||
php82-pdo_odbc \
|
php84-pdo_odbc \
|
||||||
php82-pdo_pgsql \
|
php84-pdo_pgsql \
|
||||||
php82-pdo_sqlite \
|
php84-pdo_sqlite \
|
||||||
php82-pear \
|
php84-pear \
|
||||||
php82-pecl-apcu \
|
php84-pecl-apcu \
|
||||||
php82-pecl-memcached \
|
php84-pecl-memcached \
|
||||||
php82-pecl-redis \
|
php84-pecl-redis \
|
||||||
php82-pgsql \
|
php84-pgsql \
|
||||||
php82-posix \
|
php84-posix \
|
||||||
php82-soap \
|
php84-soap \
|
||||||
php82-sockets \
|
php84-sockets \
|
||||||
php82-sodium \
|
php84-sodium \
|
||||||
php82-sqlite3 \
|
php84-sqlite3 \
|
||||||
php82-tokenizer \
|
php84-tokenizer \
|
||||||
php82-xmlreader \
|
php84-xmlreader \
|
||||||
php82-xsl \
|
php84-xsl \
|
||||||
whois && \
|
whois && \
|
||||||
apk add --no-cache --repository=http://dl-cdn.alpinelinux.org/alpine/edge/testing \
|
|
||||||
php82-pecl-mcrypt && \
|
|
||||||
echo "**** install certbot plugins ****" && \
|
echo "**** install certbot plugins ****" && \
|
||||||
if [ -z ${CERTBOT_VERSION+x} ]; then \
|
if [ -z ${CERTBOT_VERSION+x} ]; then \
|
||||||
CERTBOT_VERSION=$(curl -sL https://pypi.python.org/pypi/certbot/json |jq -r '. | .info.version'); \
|
CERTBOT_VERSION=$(curl -sL https://pypi.python.org/pypi/certbot/json |jq -r '. | .info.version'); \
|
||||||
@@ -86,7 +88,7 @@ RUN \
|
|||||||
pip install -U --no-cache-dir \
|
pip install -U --no-cache-dir \
|
||||||
pip \
|
pip \
|
||||||
wheel && \
|
wheel && \
|
||||||
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.18/ \
|
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.22/ \
|
||||||
certbot==${CERTBOT_VERSION} \
|
certbot==${CERTBOT_VERSION} \
|
||||||
certbot-dns-acmedns \
|
certbot-dns-acmedns \
|
||||||
certbot-dns-aliyun \
|
certbot-dns-aliyun \
|
||||||
@@ -104,11 +106,12 @@ RUN \
|
|||||||
certbot-dns-domeneshop \
|
certbot-dns-domeneshop \
|
||||||
certbot-dns-dreamhost \
|
certbot-dns-dreamhost \
|
||||||
certbot-dns-duckdns \
|
certbot-dns-duckdns \
|
||||||
certbot-dns-dynu \
|
certbot-dns-dynudns \
|
||||||
|
certbot-dns-freedns \
|
||||||
certbot-dns-gehirn \
|
certbot-dns-gehirn \
|
||||||
|
certbot-dns-glesys \
|
||||||
certbot-dns-godaddy \
|
certbot-dns-godaddy \
|
||||||
certbot-dns-google \
|
certbot-dns-google \
|
||||||
certbot-dns-google-domains \
|
|
||||||
certbot-dns-he \
|
certbot-dns-he \
|
||||||
certbot-dns-hetzner \
|
certbot-dns-hetzner \
|
||||||
certbot-dns-infomaniak \
|
certbot-dns-infomaniak \
|
||||||
@@ -117,6 +120,7 @@ RUN \
|
|||||||
certbot-dns-linode \
|
certbot-dns-linode \
|
||||||
certbot-dns-loopia \
|
certbot-dns-loopia \
|
||||||
certbot-dns-luadns \
|
certbot-dns-luadns \
|
||||||
|
certbot-dns-namecheap \
|
||||||
certbot-dns-netcup \
|
certbot-dns-netcup \
|
||||||
certbot-dns-njalla \
|
certbot-dns-njalla \
|
||||||
certbot-dns-nsone \
|
certbot-dns-nsone \
|
||||||
@@ -142,11 +146,13 @@ RUN \
|
|||||||
sed -i \
|
sed -i \
|
||||||
's|#ssl_trusted_certificate /config/keys/cert.crt;|ssl_trusted_certificate /config/keys/cert.crt;|' \
|
's|#ssl_trusted_certificate /config/keys/cert.crt;|ssl_trusted_certificate /config/keys/cert.crt;|' \
|
||||||
/defaults/nginx/ssl.conf.sample && \
|
/defaults/nginx/ssl.conf.sample && \
|
||||||
|
echo "**** remove stream.conf ****" && \
|
||||||
|
rm -f /etc/nginx/conf.d/stream.conf && \
|
||||||
echo "**** correct ip6tables legacy issue ****" && \
|
echo "**** correct ip6tables legacy issue ****" && \
|
||||||
rm \
|
rm \
|
||||||
/sbin/ip6tables && \
|
/usr/sbin/ip6tables && \
|
||||||
ln -s \
|
ln -s \
|
||||||
/sbin/ip6tables-nft /sbin/ip6tables && \
|
/usr/sbin/ip6tables-nft /usr/sbin/ip6tables && \
|
||||||
echo "**** remove unnecessary fail2ban filters ****" && \
|
echo "**** remove unnecessary fail2ban filters ****" && \
|
||||||
rm \
|
rm \
|
||||||
/etc/fail2ban/jail.d/alpine-ssh.conf && \
|
/etc/fail2ban/jail.d/alpine-ssh.conf && \
|
||||||
@@ -165,6 +171,7 @@ RUN \
|
|||||||
tar xf \
|
tar xf \
|
||||||
/tmp/proxy-confs.tar.gz -C \
|
/tmp/proxy-confs.tar.gz -C \
|
||||||
/defaults/nginx/proxy-confs --strip-components=1 --exclude=linux*/.editorconfig --exclude=linux*/.gitattributes --exclude=linux*/.github --exclude=linux*/.gitignore --exclude=linux*/LICENSE && \
|
/defaults/nginx/proxy-confs --strip-components=1 --exclude=linux*/.editorconfig --exclude=linux*/.gitattributes --exclude=linux*/.github --exclude=linux*/.gitignore --exclude=linux*/LICENSE && \
|
||||||
|
printf "Linuxserver.io version: ${VERSION}\nBuild-date: ${BUILD_DATE}" > /build_version && \
|
||||||
echo "**** cleanup ****" && \
|
echo "**** cleanup ****" && \
|
||||||
apk del --purge \
|
apk del --purge \
|
||||||
build-dependencies && \
|
build-dependencies && \
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
# syntax=docker/dockerfile:1
|
# syntax=docker/dockerfile:1
|
||||||
|
|
||||||
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:arm64v8-3.18
|
FROM ghcr.io/linuxserver/baseimage-alpine-nginx:arm64v8-3.22
|
||||||
|
|
||||||
# set version label
|
# set version label
|
||||||
ARG BUILD_DATE
|
ARG BUILD_DATE
|
||||||
@@ -10,8 +10,10 @@ LABEL build_version="Linuxserver.io version:- ${VERSION} Build-date:- ${BUILD_DA
|
|||||||
LABEL maintainer="nemchik"
|
LABEL maintainer="nemchik"
|
||||||
|
|
||||||
# environment settings
|
# environment settings
|
||||||
ENV DHLEVEL=2048 ONLY_SUBDOMAINS=false AWS_CONFIG_FILE=/config/dns-conf/route53.ini
|
ENV DHLEVEL=2048 \
|
||||||
ENV S6_BEHAVIOUR_IF_STAGE2_FAILS=2
|
ONLY_SUBDOMAINS=false \
|
||||||
|
AWS_CONFIG_FILE=/config/dns-conf/route53.ini \
|
||||||
|
S6_BEHAVIOUR_IF_STAGE2_FAILS=2
|
||||||
|
|
||||||
RUN \
|
RUN \
|
||||||
echo "**** install build packages ****" && \
|
echo "**** install build packages ****" && \
|
||||||
@@ -27,6 +29,8 @@ RUN \
|
|||||||
apk add --no-cache \
|
apk add --no-cache \
|
||||||
fail2ban \
|
fail2ban \
|
||||||
gnupg \
|
gnupg \
|
||||||
|
inotify-tools \
|
||||||
|
iptables-legacy \
|
||||||
memcached \
|
memcached \
|
||||||
nginx-mod-http-brotli \
|
nginx-mod-http-brotli \
|
||||||
nginx-mod-http-dav-ext \
|
nginx-mod-http-dav-ext \
|
||||||
@@ -45,39 +49,37 @@ RUN \
|
|||||||
nginx-mod-stream \
|
nginx-mod-stream \
|
||||||
nginx-mod-stream-geoip2 \
|
nginx-mod-stream-geoip2 \
|
||||||
nginx-vim \
|
nginx-vim \
|
||||||
php82-bcmath \
|
php84-bcmath \
|
||||||
php82-bz2 \
|
php84-bz2 \
|
||||||
php82-dom \
|
php84-dom \
|
||||||
php82-exif \
|
php84-exif \
|
||||||
php82-ftp \
|
php84-ftp \
|
||||||
php82-gd \
|
php84-gd \
|
||||||
php82-gmp \
|
php84-gmp \
|
||||||
php82-imap \
|
php84-imap \
|
||||||
php82-intl \
|
php84-intl \
|
||||||
php82-ldap \
|
php84-ldap \
|
||||||
php82-mysqli \
|
php84-mysqli \
|
||||||
php82-mysqlnd \
|
php84-mysqlnd \
|
||||||
php82-opcache \
|
php84-opcache \
|
||||||
php82-pdo_mysql \
|
php84-pdo_mysql \
|
||||||
php82-pdo_odbc \
|
php84-pdo_odbc \
|
||||||
php82-pdo_pgsql \
|
php84-pdo_pgsql \
|
||||||
php82-pdo_sqlite \
|
php84-pdo_sqlite \
|
||||||
php82-pear \
|
php84-pear \
|
||||||
php82-pecl-apcu \
|
php84-pecl-apcu \
|
||||||
php82-pecl-memcached \
|
php84-pecl-memcached \
|
||||||
php82-pecl-redis \
|
php84-pecl-redis \
|
||||||
php82-pgsql \
|
php84-pgsql \
|
||||||
php82-posix \
|
php84-posix \
|
||||||
php82-soap \
|
php84-soap \
|
||||||
php82-sockets \
|
php84-sockets \
|
||||||
php82-sodium \
|
php84-sodium \
|
||||||
php82-sqlite3 \
|
php84-sqlite3 \
|
||||||
php82-tokenizer \
|
php84-tokenizer \
|
||||||
php82-xmlreader \
|
php84-xmlreader \
|
||||||
php82-xsl \
|
php84-xsl \
|
||||||
whois && \
|
whois && \
|
||||||
apk add --no-cache --repository=http://dl-cdn.alpinelinux.org/alpine/edge/testing \
|
|
||||||
php82-pecl-mcrypt && \
|
|
||||||
echo "**** install certbot plugins ****" && \
|
echo "**** install certbot plugins ****" && \
|
||||||
if [ -z ${CERTBOT_VERSION+x} ]; then \
|
if [ -z ${CERTBOT_VERSION+x} ]; then \
|
||||||
CERTBOT_VERSION=$(curl -sL https://pypi.python.org/pypi/certbot/json |jq -r '. | .info.version'); \
|
CERTBOT_VERSION=$(curl -sL https://pypi.python.org/pypi/certbot/json |jq -r '. | .info.version'); \
|
||||||
@@ -86,7 +88,7 @@ RUN \
|
|||||||
pip install -U --no-cache-dir \
|
pip install -U --no-cache-dir \
|
||||||
pip \
|
pip \
|
||||||
wheel && \
|
wheel && \
|
||||||
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.18/ \
|
pip install -U --no-cache-dir --find-links https://wheel-index.linuxserver.io/alpine-3.22/ \
|
||||||
certbot==${CERTBOT_VERSION} \
|
certbot==${CERTBOT_VERSION} \
|
||||||
certbot-dns-acmedns \
|
certbot-dns-acmedns \
|
||||||
certbot-dns-aliyun \
|
certbot-dns-aliyun \
|
||||||
@@ -104,11 +106,12 @@ RUN \
|
|||||||
certbot-dns-domeneshop \
|
certbot-dns-domeneshop \
|
||||||
certbot-dns-dreamhost \
|
certbot-dns-dreamhost \
|
||||||
certbot-dns-duckdns \
|
certbot-dns-duckdns \
|
||||||
certbot-dns-dynu \
|
certbot-dns-dynudns \
|
||||||
|
certbot-dns-freedns \
|
||||||
certbot-dns-gehirn \
|
certbot-dns-gehirn \
|
||||||
|
certbot-dns-glesys \
|
||||||
certbot-dns-godaddy \
|
certbot-dns-godaddy \
|
||||||
certbot-dns-google \
|
certbot-dns-google \
|
||||||
certbot-dns-google-domains \
|
|
||||||
certbot-dns-he \
|
certbot-dns-he \
|
||||||
certbot-dns-hetzner \
|
certbot-dns-hetzner \
|
||||||
certbot-dns-infomaniak \
|
certbot-dns-infomaniak \
|
||||||
@@ -117,6 +120,7 @@ RUN \
|
|||||||
certbot-dns-linode \
|
certbot-dns-linode \
|
||||||
certbot-dns-loopia \
|
certbot-dns-loopia \
|
||||||
certbot-dns-luadns \
|
certbot-dns-luadns \
|
||||||
|
certbot-dns-namecheap \
|
||||||
certbot-dns-netcup \
|
certbot-dns-netcup \
|
||||||
certbot-dns-njalla \
|
certbot-dns-njalla \
|
||||||
certbot-dns-nsone \
|
certbot-dns-nsone \
|
||||||
@@ -142,11 +146,13 @@ RUN \
|
|||||||
sed -i \
|
sed -i \
|
||||||
's|#ssl_trusted_certificate /config/keys/cert.crt;|ssl_trusted_certificate /config/keys/cert.crt;|' \
|
's|#ssl_trusted_certificate /config/keys/cert.crt;|ssl_trusted_certificate /config/keys/cert.crt;|' \
|
||||||
/defaults/nginx/ssl.conf.sample && \
|
/defaults/nginx/ssl.conf.sample && \
|
||||||
|
echo "**** remove stream.conf ****" && \
|
||||||
|
rm -f /etc/nginx/conf.d/stream.conf && \
|
||||||
echo "**** correct ip6tables legacy issue ****" && \
|
echo "**** correct ip6tables legacy issue ****" && \
|
||||||
rm \
|
rm \
|
||||||
/sbin/ip6tables && \
|
/usr/sbin/ip6tables && \
|
||||||
ln -s \
|
ln -s \
|
||||||
/sbin/ip6tables-nft /sbin/ip6tables && \
|
/usr/sbin/ip6tables-nft /usr/sbin/ip6tables && \
|
||||||
echo "**** remove unnecessary fail2ban filters ****" && \
|
echo "**** remove unnecessary fail2ban filters ****" && \
|
||||||
rm \
|
rm \
|
||||||
/etc/fail2ban/jail.d/alpine-ssh.conf && \
|
/etc/fail2ban/jail.d/alpine-ssh.conf && \
|
||||||
@@ -165,6 +171,7 @@ RUN \
|
|||||||
tar xf \
|
tar xf \
|
||||||
/tmp/proxy-confs.tar.gz -C \
|
/tmp/proxy-confs.tar.gz -C \
|
||||||
/defaults/nginx/proxy-confs --strip-components=1 --exclude=linux*/.editorconfig --exclude=linux*/.gitattributes --exclude=linux*/.github --exclude=linux*/.gitignore --exclude=linux*/LICENSE && \
|
/defaults/nginx/proxy-confs --strip-components=1 --exclude=linux*/.editorconfig --exclude=linux*/.gitattributes --exclude=linux*/.github --exclude=linux*/.gitignore --exclude=linux*/LICENSE && \
|
||||||
|
printf "Linuxserver.io version: ${VERSION}\nBuild-date: ${BUILD_DATE}" > /build_version && \
|
||||||
echo "**** cleanup ****" && \
|
echo "**** cleanup ****" && \
|
||||||
apk del --purge \
|
apk del --purge \
|
||||||
build-dependencies && \
|
build-dependencies && \
|
||||||
|
|||||||
769
Jenkinsfile
vendored
769
Jenkinsfile
vendored
File diff suppressed because it is too large
Load Diff
251
README.md
251
README.md
@@ -1,12 +1,10 @@
|
|||||||
<!-- DO NOT EDIT THIS FILE MANUALLY -->
|
<!-- DO NOT EDIT THIS FILE MANUALLY -->
|
||||||
<!-- Please read the https://github.com/linuxserver/docker-swag/blob/master/.github/CONTRIBUTING.md -->
|
<!-- Please read https://github.com/linuxserver/docker-swag/blob/master/.github/CONTRIBUTING.md -->
|
||||||
|
|
||||||
[](https://linuxserver.io)
|
[](https://linuxserver.io)
|
||||||
|
|
||||||
[](https://blog.linuxserver.io "all the things you can do with our containers including How-To guides, opinions and much more!")
|
[](https://blog.linuxserver.io "all the things you can do with our containers including How-To guides, opinions and much more!")
|
||||||
[](https://discord.gg/YWrKVTn "realtime support / chat with the community and the team.")
|
[](https://linuxserver.io/discord "realtime support / chat with the community and the team.")
|
||||||
[](https://discourse.linuxserver.io "post on our community forum.")
|
[](https://discourse.linuxserver.io "post on our community forum.")
|
||||||
[](https://fleet.linuxserver.io "an online web interface which displays all of our maintained images.")
|
|
||||||
[](https://github.com/linuxserver "view the source for all of our repositories.")
|
[](https://github.com/linuxserver "view the source for all of our repositories.")
|
||||||
[](https://opencollective.com/linuxserver "please consider helping us by either donating or contributing to our budget")
|
[](https://opencollective.com/linuxserver "please consider helping us by either donating or contributing to our budget")
|
||||||
|
|
||||||
@@ -21,15 +19,14 @@ The [LinuxServer.io](https://linuxserver.io) team brings you another container r
|
|||||||
Find us at:
|
Find us at:
|
||||||
|
|
||||||
* [Blog](https://blog.linuxserver.io) - all the things you can do with our containers including How-To guides, opinions and much more!
|
* [Blog](https://blog.linuxserver.io) - all the things you can do with our containers including How-To guides, opinions and much more!
|
||||||
* [Discord](https://discord.gg/YWrKVTn) - realtime support / chat with the community and the team.
|
* [Discord](https://linuxserver.io/discord) - realtime support / chat with the community and the team.
|
||||||
* [Discourse](https://discourse.linuxserver.io) - post on our community forum.
|
* [Discourse](https://discourse.linuxserver.io) - post on our community forum.
|
||||||
* [Fleet](https://fleet.linuxserver.io) - an online web interface which displays all of our maintained images.
|
|
||||||
* [GitHub](https://github.com/linuxserver) - view the source for all of our repositories.
|
* [GitHub](https://github.com/linuxserver) - view the source for all of our repositories.
|
||||||
* [Open Collective](https://opencollective.com/linuxserver) - please consider helping us by either donating or contributing to our budget
|
* [Open Collective](https://opencollective.com/linuxserver) - please consider helping us by either donating or contributing to our budget
|
||||||
|
|
||||||
# [linuxserver/swag](https://github.com/linuxserver/docker-swag)
|
# [linuxserver/swag](https://github.com/linuxserver/docker-swag)
|
||||||
|
|
||||||
[](https://scarf.sh/gateway/linuxserver-ci/docker/linuxserver%2Fswag)
|
[](https://scarf.sh)
|
||||||
[](https://github.com/linuxserver/docker-swag)
|
[](https://github.com/linuxserver/docker-swag)
|
||||||
[](https://github.com/linuxserver/docker-swag/releases)
|
[](https://github.com/linuxserver/docker-swag/releases)
|
||||||
[](https://github.com/linuxserver/docker-swag/packages)
|
[](https://github.com/linuxserver/docker-swag/packages)
|
||||||
@@ -38,7 +35,6 @@ Find us at:
|
|||||||
[](https://hub.docker.com/r/linuxserver/swag)
|
[](https://hub.docker.com/r/linuxserver/swag)
|
||||||
[](https://hub.docker.com/r/linuxserver/swag)
|
[](https://hub.docker.com/r/linuxserver/swag)
|
||||||
[](https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/)
|
[](https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-swag/job/master/)
|
||||||
[](https://ci-tests.linuxserver.io/linuxserver/swag/latest/index.html)
|
|
||||||
|
|
||||||
SWAG - Secure Web Application Gateway (formerly known as letsencrypt, no relation to Let's Encrypt™) sets up an Nginx webserver and reverse proxy with php support and a built-in certbot client that automates free SSL server certificate generation and renewal processes (Let's Encrypt and ZeroSSL). It also contains fail2ban for intrusion prevention.
|
SWAG - Secure Web Application Gateway (formerly known as letsencrypt, no relation to Let's Encrypt™) sets up an Nginx webserver and reverse proxy with php support and a built-in certbot client that automates free SSL server certificate generation and renewal processes (Let's Encrypt and ZeroSSL). It also contains fail2ban for intrusion prevention.
|
||||||
|
|
||||||
@@ -46,7 +42,7 @@ SWAG - Secure Web Application Gateway (formerly known as letsencrypt, no relatio
|
|||||||
|
|
||||||
## Supported Architectures
|
## Supported Architectures
|
||||||
|
|
||||||
We utilise the docker manifest for multi-platform awareness. More information is available from docker [here](https://github.com/docker/distribution/blob/master/docs/spec/manifest-v2-2.md#manifest-list) and our announcement [here](https://blog.linuxserver.io/2019/02/21/the-lsio-pipeline-project/).
|
We utilise the docker manifest for multi-platform awareness. More information is available from docker [here](https://distribution.github.io/distribution/spec/manifest-v2-2/#manifest-list) and our announcement [here](https://blog.linuxserver.io/2019/02/21/the-lsio-pipeline-project/).
|
||||||
|
|
||||||
Simply pulling `lscr.io/linuxserver/swag:latest` should retrieve the correct image for your arch, but you can also pull specific arch images via tags.
|
Simply pulling `lscr.io/linuxserver/swag:latest` should retrieve the correct image for your arch, but you can also pull specific arch images via tags.
|
||||||
|
|
||||||
@@ -56,7 +52,6 @@ The architectures supported by this image are:
|
|||||||
| :----: | :----: | ---- |
|
| :----: | :----: | ---- |
|
||||||
| x86-64 | ✅ | amd64-\<version tag\> |
|
| x86-64 | ✅ | amd64-\<version tag\> |
|
||||||
| arm64 | ✅ | arm64v8-\<version tag\> |
|
| arm64 | ✅ | arm64v8-\<version tag\> |
|
||||||
| armhf | ❌ | |
|
|
||||||
|
|
||||||
## Application Setup
|
## Application Setup
|
||||||
|
|
||||||
@@ -72,9 +67,24 @@ The architectures supported by this image are:
|
|||||||
1. Certs that only cover your main subdomain (ie. `yoursubdomain.duckdns.org`, leave the `SUBDOMAINS` variable empty)
|
1. Certs that only cover your main subdomain (ie. `yoursubdomain.duckdns.org`, leave the `SUBDOMAINS` variable empty)
|
||||||
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
|
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
|
||||||
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
|
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
|
||||||
* After setup, navigate to `https://yourdomain.url` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
|
* After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
|
||||||
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances.
|
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances.
|
||||||
|
|
||||||
|
### Certbot Plugins
|
||||||
|
|
||||||
|
SWAG includes many Certbot plugins out of the box, but not all plugins can be included.
|
||||||
|
If you need a plugin that is not included, the quickest way to have the plugin available is to use our [Universal Package Install Docker Mod](https://github.com/linuxserver/docker-mods/tree/universal-package-install).
|
||||||
|
|
||||||
|
Set the following environment variables on your container:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
DOCKER_MODS=linuxserver/mods:universal-package-install
|
||||||
|
INSTALL_PIP_PACKAGES=certbot-dns-<plugin>
|
||||||
|
```
|
||||||
|
|
||||||
|
Set the required credentials (usually found in the plugin documentation) in `/config/dns-conf/<plugin>.ini`.
|
||||||
|
It is recommended to attempt obtaining a certificate with `STAGING=true` first to make sure the plugin is working as expected.
|
||||||
|
|
||||||
### Security and password protection
|
### Security and password protection
|
||||||
|
|
||||||
* The container detects changes to url and subdomains, revokes existing certs and generates new ones during start.
|
* The container detects changes to url and subdomains, revokes existing certs and generates new ones during start.
|
||||||
@@ -116,7 +126,7 @@ This will *ask* Google et al not to index and list your site. Be careful with th
|
|||||||
* You can check which jails are active via `docker exec -it swag fail2ban-client status`
|
* You can check which jails are active via `docker exec -it swag fail2ban-client status`
|
||||||
* You can check the status of a specific jail via `docker exec -it swag fail2ban-client status <jail name>`
|
* You can check the status of a specific jail via `docker exec -it swag fail2ban-client status <jail name>`
|
||||||
* You can unban an IP via `docker exec -it swag fail2ban-client set <jail name> unbanip <IP>`
|
* You can unban an IP via `docker exec -it swag fail2ban-client set <jail name> unbanip <IP>`
|
||||||
* A list of commands can be found here: <https://www.fail2ban.org/wiki/index.php/Commands>
|
* A list of commands for fail2ban-client can be found [here](https://manpages.ubuntu.com/manpages/noble/man1/fail2ban-client.1.html)
|
||||||
|
|
||||||
### Updating configs
|
### Updating configs
|
||||||
|
|
||||||
@@ -132,19 +142,40 @@ This will *ask* Google et al not to index and list your site. Be careful with th
|
|||||||
* Proxy sample files WILL be updated, however your renamed (enabled) proxy files will not.
|
* Proxy sample files WILL be updated, however your renamed (enabled) proxy files will not.
|
||||||
* You can check the new sample and adjust your active config as needed.
|
* You can check the new sample and adjust your active config as needed.
|
||||||
|
|
||||||
|
### QUIC support
|
||||||
|
|
||||||
|
This image supports QUIC (also known as HTTP/3) but it must be explicitly enabled in each proxy conf, and the default conf, because if the listener is enabled and you don't expose 443/UDP, it can break connections with some browsers.
|
||||||
|
|
||||||
|
To enable QUIC, expose 443/UDP to your clients, then uncomment both QUIC listeners in all of your active proxy confs, as well as the default conf, and restart the container.
|
||||||
|
|
||||||
|
You should also uncomment the `Alt-Svc` header in your `ssl.conf` so that browsers are aware that you offer QUIC connectivity.
|
||||||
|
|
||||||
|
It is [recommended](https://quic-go.net/docs/quic/optimizations/#udp-buffer-sizes) to increase the UDP send/recieve buffer **on the host** by setting the `net.core.rmem_max` and `net.core.wmem_max` sysctls. Suggested values are 4-16Mb (4194304-16777216 bytes). For persistence between reboots use `/etc/sysctl.d/`.
|
||||||
|
|
||||||
### Migration from the old `linuxserver/letsencrypt` image
|
### Migration from the old `linuxserver/letsencrypt` image
|
||||||
|
|
||||||
Please follow the instructions [on this blog post](https://www.linuxserver.io/blog/2020-08-21-introducing-swag#migrate).
|
Please follow the instructions [on this blog post](https://www.linuxserver.io/blog/2020-08-21-introducing-swag#migrate).
|
||||||
|
|
||||||
|
## Read-Only Operation
|
||||||
|
|
||||||
|
This image can be run with a read-only container filesystem. For details please [read the docs](https://docs.linuxserver.io/misc/read-only/).
|
||||||
|
|
||||||
|
### Caveats
|
||||||
|
|
||||||
|
* `/tmp` must be mounted to tmpfs
|
||||||
|
* fail2ban will not be available
|
||||||
|
|
||||||
## Usage
|
## Usage
|
||||||
|
|
||||||
Here are some example snippets to help you get started creating a container.
|
To help you get started creating a container from this image you can either use docker-compose or the docker cli.
|
||||||
|
|
||||||
|
>[!NOTE]
|
||||||
|
>Unless a parameter is flaged as 'optional', it is *mandatory* and a value must be provided.
|
||||||
|
|
||||||
### docker-compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose))
|
### docker-compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose))
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
---
|
---
|
||||||
version: "2.1"
|
|
||||||
services:
|
services:
|
||||||
swag:
|
swag:
|
||||||
image: lscr.io/linuxserver/swag:latest
|
image: lscr.io/linuxserver/swag:latest
|
||||||
@@ -155,7 +186,7 @@ services:
|
|||||||
- PUID=1000
|
- PUID=1000
|
||||||
- PGID=1000
|
- PGID=1000
|
||||||
- TZ=Etc/UTC
|
- TZ=Etc/UTC
|
||||||
- URL=yourdomain.url
|
- URL=example.com
|
||||||
- VALIDATION=http
|
- VALIDATION=http
|
||||||
- SUBDOMAINS=www, #optional
|
- SUBDOMAINS=www, #optional
|
||||||
- CERTPROVIDER= #optional
|
- CERTPROVIDER= #optional
|
||||||
@@ -165,11 +196,15 @@ services:
|
|||||||
- ONLY_SUBDOMAINS=false #optional
|
- ONLY_SUBDOMAINS=false #optional
|
||||||
- EXTRA_DOMAINS= #optional
|
- EXTRA_DOMAINS= #optional
|
||||||
- STAGING=false #optional
|
- STAGING=false #optional
|
||||||
|
- DISABLE_F2B= #optional
|
||||||
|
- SWAG_AUTORELOAD= #optional
|
||||||
|
- SWAG_AUTORELOAD_WATCHLIST= #optional
|
||||||
volumes:
|
volumes:
|
||||||
- /path/to/appdata/config:/config
|
- /path/to/swag/config:/config
|
||||||
ports:
|
ports:
|
||||||
- 443:443
|
- 443:443
|
||||||
- 80:80 #optional
|
- 80:80 #optional
|
||||||
|
- 443:443/udp #optional
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -182,7 +217,7 @@ docker run -d \
|
|||||||
-e PUID=1000 \
|
-e PUID=1000 \
|
||||||
-e PGID=1000 \
|
-e PGID=1000 \
|
||||||
-e TZ=Etc/UTC \
|
-e TZ=Etc/UTC \
|
||||||
-e URL=yourdomain.url \
|
-e URL=example.com \
|
||||||
-e VALIDATION=http \
|
-e VALIDATION=http \
|
||||||
-e SUBDOMAINS=www, `#optional` \
|
-e SUBDOMAINS=www, `#optional` \
|
||||||
-e CERTPROVIDER= `#optional` \
|
-e CERTPROVIDER= `#optional` \
|
||||||
@@ -192,36 +227,45 @@ docker run -d \
|
|||||||
-e ONLY_SUBDOMAINS=false `#optional` \
|
-e ONLY_SUBDOMAINS=false `#optional` \
|
||||||
-e EXTRA_DOMAINS= `#optional` \
|
-e EXTRA_DOMAINS= `#optional` \
|
||||||
-e STAGING=false `#optional` \
|
-e STAGING=false `#optional` \
|
||||||
|
-e DISABLE_F2B= `#optional` \
|
||||||
|
-e SWAG_AUTORELOAD= `#optional` \
|
||||||
|
-e SWAG_AUTORELOAD_WATCHLIST= `#optional` \
|
||||||
-p 443:443 \
|
-p 443:443 \
|
||||||
-p 80:80 `#optional` \
|
-p 80:80 `#optional` \
|
||||||
-v /path/to/appdata/config:/config \
|
-p 443:443/udp `#optional` \
|
||||||
|
-v /path/to/swag/config:/config \
|
||||||
--restart unless-stopped \
|
--restart unless-stopped \
|
||||||
lscr.io/linuxserver/swag:latest
|
lscr.io/linuxserver/swag:latest
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
||||||
## Parameters
|
## Parameters
|
||||||
|
|
||||||
Container images are configured using parameters passed at runtime (such as those above). These parameters are separated by a colon and indicate `<external>:<internal>` respectively. For example, `-p 8080:80` would expose port `80` from inside the container to be accessible from the host's IP on port `8080` outside the container.
|
Containers are configured using parameters passed at runtime (such as those above). These parameters are separated by a colon and indicate `<external>:<internal>` respectively. For example, `-p 8080:80` would expose port `80` from inside the container to be accessible from the host's IP on port `8080` outside the container.
|
||||||
|
|
||||||
| Parameter | Function |
|
| Parameter | Function |
|
||||||
| :----: | --- |
|
| :----: | --- |
|
||||||
| `-p 443` | Https port |
|
| `-p 443:443` | HTTPS port |
|
||||||
| `-p 80` | Http port (required for http validation and http -> https redirect) |
|
| `-p 80` | HTTP port (required for HTTP validation and HTTP -> HTTPS redirect) |
|
||||||
|
| `-p 443/udp` | QUIC (HTTP/3) port. Must be enabled in the default and proxy confs. |
|
||||||
| `-e PUID=1000` | for UserID - see below for explanation |
|
| `-e PUID=1000` | for UserID - see below for explanation |
|
||||||
| `-e PGID=1000` | for GroupID - see below for explanation |
|
| `-e PGID=1000` | for GroupID - see below for explanation |
|
||||||
| `-e TZ=Etc/UTC` | specify a timezone to use, see this [list](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List). |
|
| `-e TZ=Etc/UTC` | specify a timezone to use, see this [list](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List). |
|
||||||
| `-e URL=yourdomain.url` | Top url you have control over (`customdomain.com` if you own it, or `customsubdomain.ddnsprovider.com` if dynamic dns). |
|
| `-e URL=example.com` | Top url you have control over (e.g. `example.com` if you own it, or `customsubdomain.example.com` if dynamic dns). |
|
||||||
| `-e VALIDATION=http` | Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set). |
|
| `-e VALIDATION=http` | Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set). |
|
||||||
| `-e SUBDOMAINS=www,` | Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only) |
|
| `-e SUBDOMAINS=www,` | Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only) |
|
||||||
| `-e CERTPROVIDER=` | Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt. |
|
| `-e CERTPROVIDER=` | Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt. |
|
||||||
| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `gandi`, `gehirn`, `godaddy`, `google`, `google-domains`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. |
|
| `-e DNSPLUGIN=cloudflare` | Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`. |
|
||||||
| `-e PROPAGATION=` | Optionally override (in seconds) the default propagation time for the dns plugins. |
|
| `-e PROPAGATION=` | Optionally override (in seconds) the default propagation time for the dns plugins. |
|
||||||
| `-e EMAIL=` | Optional e-mail address used for cert expiration notifications (Required for ZeroSSL). |
|
| `-e EMAIL=` | Optional e-mail address used for cert expiration notifications (Required for ZeroSSL). |
|
||||||
| `-e ONLY_SUBDOMAINS=false` | If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true` |
|
| `-e ONLY_SUBDOMAINS=false` | If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true` |
|
||||||
| `-e EXTRA_DOMAINS=` | Additional fully qualified domain names (comma separated, no spaces) ie. `extradomain.com,subdomain.anotherdomain.org,*.anotherdomain.org` |
|
| `-e EXTRA_DOMAINS=` | Additional fully qualified domain names (comma separated, no spaces) ie. `example.net,subdomain.example.net,*.example.org` |
|
||||||
| `-e STAGING=false` | Set to `true` to retrieve certs in staging mode. Rate limits will be much higher, but the resulting cert will not pass the browser's security test. Only to be used for testing purposes. |
|
| `-e STAGING=false` | Set to `true` to retrieve certs in staging mode. Rate limits will be much higher, but the resulting cert will not pass the browser's security test. Only to be used for testing purposes. |
|
||||||
| `-v /config` | All the config files including the webroot reside here. |
|
| `-e DISABLE_F2B=` | Set to `true` to disable the Fail2ban service in the container, if you're already running it elsewhere or using a different IPS. |
|
||||||
|
| `-e SWAG_AUTORELOAD=` | Set to `true` to enable automatic reloading of confs on change without stopping/restarting nginx. Your filesystem must support inotify. This functionality was previously offered [via mod](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload). |
|
||||||
|
| `-e SWAG_AUTORELOAD_WATCHLIST=` | A [pipe](https://en.wikipedia.org/wiki/Vertical_bar)-separated list of additional folders for auto reload to watch in addition to `/config/nginx` |
|
||||||
|
| `-v /config` | Persistent config files |
|
||||||
|
| `--read-only=true` | Run container with a read-only filesystem. Please [read the docs](https://docs.linuxserver.io/misc/read-only/). |
|
||||||
|
| `--cap-add=NET_ADMIN` | Required for fail2Ban to be able to modify iptables rules. |
|
||||||
|
|
||||||
### Portainer notice
|
### Portainer notice
|
||||||
|
|
||||||
@@ -234,10 +278,10 @@ You can set any environment variable from a file by using a special prepend `FIL
|
|||||||
As an example:
|
As an example:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
-e FILE__PASSWORD=/run/secrets/mysecretpassword
|
-e FILE__MYVAR=/run/secrets/mysecretvariable
|
||||||
```
|
```
|
||||||
|
|
||||||
Will set the environment variable `PASSWORD` based on the contents of the `/run/secrets/mysecretpassword` file.
|
Will set the environment variable `MYVAR` based on the contents of the `/run/secrets/mysecretvariable` file.
|
||||||
|
|
||||||
## Umask for running applications
|
## Umask for running applications
|
||||||
|
|
||||||
@@ -246,15 +290,20 @@ Keep in mind umask is not chmod it subtracts from permissions based on it's valu
|
|||||||
|
|
||||||
## User / Group Identifiers
|
## User / Group Identifiers
|
||||||
|
|
||||||
When using volumes (`-v` flags) permissions issues can arise between the host OS and the container, we avoid this issue by allowing you to specify the user `PUID` and group `PGID`.
|
When using volumes (`-v` flags), permissions issues can arise between the host OS and the container, we avoid this issue by allowing you to specify the user `PUID` and group `PGID`.
|
||||||
|
|
||||||
Ensure any volume directories on the host are owned by the same user you specify and any permissions issues will vanish like magic.
|
Ensure any volume directories on the host are owned by the same user you specify and any permissions issues will vanish like magic.
|
||||||
|
|
||||||
In this instance `PUID=1000` and `PGID=1000`, to find yours use `id user` as below:
|
In this instance `PUID=1000` and `PGID=1000`, to find yours use `id your_user` as below:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
$ id username
|
id your_user
|
||||||
uid=1000(dockeruser) gid=1000(dockergroup) groups=1000(dockergroup)
|
```
|
||||||
|
|
||||||
|
Example output:
|
||||||
|
|
||||||
|
```text
|
||||||
|
uid=1000(your_user) gid=1000(your_user) groups=1000(your_user)
|
||||||
```
|
```
|
||||||
|
|
||||||
## Docker Mods
|
## Docker Mods
|
||||||
@@ -265,53 +314,101 @@ We publish various [Docker Mods](https://github.com/linuxserver/docker-mods) to
|
|||||||
|
|
||||||
## Support Info
|
## Support Info
|
||||||
|
|
||||||
* Shell access whilst the container is running: `docker exec -it swag /bin/bash`
|
* Shell access whilst the container is running:
|
||||||
* To monitor the logs of the container in realtime: `docker logs -f swag`
|
|
||||||
* container version number
|
```bash
|
||||||
* `docker inspect -f '{{ index .Config.Labels "build_version" }}' swag`
|
docker exec -it swag /bin/bash
|
||||||
* image version number
|
```
|
||||||
* `docker inspect -f '{{ index .Config.Labels "build_version" }}' lscr.io/linuxserver/swag:latest`
|
|
||||||
|
* To monitor the logs of the container in realtime:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker logs -f swag
|
||||||
|
```
|
||||||
|
|
||||||
|
* Container version number:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker inspect -f '{{ index .Config.Labels "build_version" }}' swag
|
||||||
|
```
|
||||||
|
|
||||||
|
* Image version number:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker inspect -f '{{ index .Config.Labels "build_version" }}' lscr.io/linuxserver/swag:latest
|
||||||
|
```
|
||||||
|
|
||||||
## Updating Info
|
## Updating Info
|
||||||
|
|
||||||
Most of our images are static, versioned, and require an image update and container recreation to update the app inside. With some exceptions (ie. nextcloud, plex), we do not recommend or support updating apps inside the container. Please consult the [Application Setup](#application-setup) section above to see if it is recommended for the image.
|
Most of our images are static, versioned, and require an image update and container recreation to update the app inside. With some exceptions (noted in the relevant readme.md), we do not recommend or support updating apps inside the container. Please consult the [Application Setup](#application-setup) section above to see if it is recommended for the image.
|
||||||
|
|
||||||
Below are the instructions for updating containers:
|
Below are the instructions for updating containers:
|
||||||
|
|
||||||
### Via Docker Compose
|
### Via Docker Compose
|
||||||
|
|
||||||
* Update all images: `docker-compose pull`
|
* Update images:
|
||||||
* or update a single image: `docker-compose pull swag`
|
* All images:
|
||||||
* Let compose update all containers as necessary: `docker-compose up -d`
|
|
||||||
* or update a single container: `docker-compose up -d swag`
|
```bash
|
||||||
* You can also remove the old dangling images: `docker image prune`
|
docker-compose pull
|
||||||
|
```
|
||||||
|
|
||||||
|
* Single image:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker-compose pull swag
|
||||||
|
```
|
||||||
|
|
||||||
|
* Update containers:
|
||||||
|
* All containers:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker-compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
* Single container:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker-compose up -d swag
|
||||||
|
```
|
||||||
|
|
||||||
|
* You can also remove the old dangling images:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker image prune
|
||||||
|
```
|
||||||
|
|
||||||
### Via Docker Run
|
### Via Docker Run
|
||||||
|
|
||||||
* Update the image: `docker pull lscr.io/linuxserver/swag:latest`
|
* Update the image:
|
||||||
* Stop the running container: `docker stop swag`
|
|
||||||
* Delete the container: `docker rm swag`
|
```bash
|
||||||
|
docker pull lscr.io/linuxserver/swag:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
* Stop the running container:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker stop swag
|
||||||
|
```
|
||||||
|
|
||||||
|
* Delete the container:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker rm swag
|
||||||
|
```
|
||||||
|
|
||||||
* Recreate a new container with the same docker run parameters as instructed above (if mapped correctly to a host folder, your `/config` folder and settings will be preserved)
|
* Recreate a new container with the same docker run parameters as instructed above (if mapped correctly to a host folder, your `/config` folder and settings will be preserved)
|
||||||
* You can also remove the old dangling images: `docker image prune`
|
* You can also remove the old dangling images:
|
||||||
|
|
||||||
### Via Watchtower auto-updater (only use if you don't remember the original parameters)
|
```bash
|
||||||
|
docker image prune
|
||||||
* Pull the latest image at its tag and replace it with the same env variables in one run:
|
```
|
||||||
|
|
||||||
```bash
|
|
||||||
docker run --rm \
|
|
||||||
-v /var/run/docker.sock:/var/run/docker.sock \
|
|
||||||
containrrr/watchtower \
|
|
||||||
--run-once swag
|
|
||||||
```
|
|
||||||
|
|
||||||
* You can also remove the old dangling images: `docker image prune`
|
|
||||||
|
|
||||||
**Note:** We do not endorse the use of Watchtower as a solution to automated updates of existing Docker containers. In fact we generally discourage automated updates. However, this is a useful tool for one-time manual updates of containers where you have forgotten the original parameters. In the long term, we highly recommend using [Docker Compose](https://docs.linuxserver.io/general/docker-compose).
|
|
||||||
|
|
||||||
### Image Update Notifications - Diun (Docker Image Update Notifier)
|
### Image Update Notifications - Diun (Docker Image Update Notifier)
|
||||||
|
|
||||||
* We recommend [Diun](https://crazymax.dev/diun/) for update notifications. Other tools that automatically update containers unattended are not recommended or supported.
|
>[!TIP]
|
||||||
|
>We recommend [Diun](https://crazymax.dev/diun/) for update notifications. Other tools that automatically update containers unattended are not recommended or supported.
|
||||||
|
|
||||||
## Building locally
|
## Building locally
|
||||||
|
|
||||||
@@ -326,16 +423,38 @@ docker build \
|
|||||||
-t lscr.io/linuxserver/swag:latest .
|
-t lscr.io/linuxserver/swag:latest .
|
||||||
```
|
```
|
||||||
|
|
||||||
The ARM variants can be built on x86_64 hardware using `multiarch/qemu-user-static`
|
The ARM variants can be built on x86_64 hardware and vice versa using `lscr.io/linuxserver/qemu-static`
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
docker run --rm --privileged multiarch/qemu-user-static:register --reset
|
docker run --rm --privileged lscr.io/linuxserver/qemu-static --reset
|
||||||
```
|
```
|
||||||
|
|
||||||
Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64`.
|
Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64`.
|
||||||
|
|
||||||
## Versions
|
## Versions
|
||||||
|
|
||||||
|
* **04.11.25:** - Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin.
|
||||||
|
* **18.07.25:** - Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained.
|
||||||
|
* **05.05.25:** - Disable Certbot's built in log rotation.
|
||||||
|
* **19.01.25:** - Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG.
|
||||||
|
* **17.12.24:** - Rebase to Alpine 3.21.
|
||||||
|
* **21.10.24:** - Fix naming issue with Dynu plugin. If you are using Dynu, please make sure your credentials are set in /config/dns-conf/dynu.ini and your DNSPLUGIN variable is set to dynu (not dynudns).
|
||||||
|
* **30.08.24:** - Fix zerossl cert revocation.
|
||||||
|
* **24.07.14:** - Rebase to Alpine 3.20. Remove deprecated Google Domains certbot plugin. Existing users should update their nginx confs to avoid http2 deprecation warnings.
|
||||||
|
* **01.07.24:** - Fall back to iptables-legacy if iptables doesn't work.
|
||||||
|
* **23.03.24:** - Fix perms on the generated `priv-fullchain-bundle.pem`.
|
||||||
|
* **14.03.24:** - [Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf - Update Authelia conf samples with support for 4.38.
|
||||||
|
* **11.03.24:** - Restore support for DynuDNS using `certbot-dns-dynudns`.
|
||||||
|
* **06.03.24:** - [Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Cleanup default site conf.
|
||||||
|
* **04.03.24:** - Remove `stream.conf` inside the container to allow users to include their own block in `nginx.conf`.
|
||||||
|
* **23.01.24:** - Rebase to Alpine 3.19 with php 8.3, add root periodic crontabs for logrotate.
|
||||||
|
* **01.01.24:** - Add GleSYS DNS plugin.
|
||||||
|
* **11.12.23:** - Deprecate certbot-dns-dynu to resolve dependency conflicts with other plugins.
|
||||||
|
* **30.11.23:** - [Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Fix index.php being downloaded on 404.
|
||||||
|
* **23.11.23:** - Run certbot as root to allow fix http validation.
|
||||||
|
* **01.10.23:** - Fix "unrecognized arguments" issue in DirectAdmin DNS plugin.
|
||||||
|
* **28.08.23:** - Add Namecheap DNS plugin.
|
||||||
|
* **12.08.23:** - Add FreeDNS plugin. Detect certbot DNS authenticators using CLI.
|
||||||
* **07.08.23:** - Add Bunny DNS Configuration.
|
* **07.08.23:** - Add Bunny DNS Configuration.
|
||||||
* **27.07.23:** - Added support for dreamhost validation.
|
* **27.07.23:** - Added support for dreamhost validation.
|
||||||
* **25.05.23:** - Rebase to Alpine 3.18, deprecate armhf.
|
* **25.05.23:** - Rebase to Alpine 3.18, deprecate armhf.
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ external_type: pip_version
|
|||||||
release_type: stable
|
release_type: stable
|
||||||
release_tag: latest
|
release_tag: latest
|
||||||
ls_branch: master
|
ls_branch: master
|
||||||
build_armhf: false
|
|
||||||
repo_vars:
|
repo_vars:
|
||||||
- EXT_PIP = 'certbot'
|
- EXT_PIP = 'certbot'
|
||||||
- BUILD_VERSION_ARG = 'CERTBOT_VERSION'
|
- BUILD_VERSION_ARG = 'CERTBOT_VERSION'
|
||||||
@@ -18,12 +17,12 @@ repo_vars:
|
|||||||
- PR_DOCKERHUB_IMAGE = 'lspipepr/swag'
|
- PR_DOCKERHUB_IMAGE = 'lspipepr/swag'
|
||||||
- DIST_IMAGE = 'alpine'
|
- DIST_IMAGE = 'alpine'
|
||||||
- MULTIARCH='true'
|
- MULTIARCH='true'
|
||||||
- CI='true'
|
- CI='false'
|
||||||
- CI_WEB='false'
|
- CI_WEB='false'
|
||||||
- CI_PORT='80'
|
- CI_PORT='80'
|
||||||
- CI_SSL='false'
|
- CI_SSL='false'
|
||||||
- CI_DELAY='30'
|
- CI_DELAY='30'
|
||||||
- CI_DOCKERENV='TEST_RUN=1'
|
- CI_DOCKERENV=''
|
||||||
- CI_AUTH=''
|
- CI_AUTH=''
|
||||||
- CI_WEBPATH=''
|
- CI_WEBPATH=''
|
||||||
sponsor_links:
|
sponsor_links:
|
||||||
|
|||||||
@@ -1,342 +1,372 @@
|
|||||||
NAME VERSION TYPE
|
NAME VERSION TYPE
|
||||||
ConfigArgParse 1.7 python
|
Simple Launcher 1.1.0.14 binary (+5 duplicates)
|
||||||
PyJWT 2.8.0 python
|
acl-libs 2.3.2-r1 apk
|
||||||
PyYAML 6.0.1 python
|
acme 5.1.0 python
|
||||||
Simple Launcher Executable 1.1.0.14 dotnet
|
alpine-baselayout 3.7.0-r0 apk
|
||||||
acme 2.6.0 python
|
alpine-baselayout-data 3.7.0-r0 apk
|
||||||
alpine-baselayout 3.4.3-r1 apk
|
alpine-keys 2.5-r0 apk
|
||||||
alpine-baselayout-data 3.4.3-r1 apk
|
alpine-release 3.22.2-r0 apk
|
||||||
alpine-keys 2.4-r1 apk
|
aom-libs 3.12.1-r0 apk
|
||||||
alpine-release 3.18.2-r0 apk
|
apache2-utils 2.4.65-r0 apk
|
||||||
aom-libs 3.6.1-r0 apk
|
apk-tools 2.14.9-r3 apk
|
||||||
apache2-utils 2.4.57-r3 apk
|
apr 1.7.5-r0 apk
|
||||||
apk-tools 2.14.0-r2 apk
|
apr-util 1.6.3-r1 apk
|
||||||
apr 1.7.4-r0 apk
|
argon2-libs 20190702-r5 apk
|
||||||
apr-util 1.6.3-r1 apk
|
attrs 25.4.0 python
|
||||||
argon2-libs 20190702-r4 apk
|
autocommand 2.2.2 python
|
||||||
attrs 23.1.0 python
|
azure-common 1.1.28 python
|
||||||
azure-common 1.1.28 python
|
azure-core 1.36.0 python
|
||||||
azure-core 1.29.1 python
|
azure-identity 1.25.1 python
|
||||||
azure-identity 1.14.0 python
|
azure-mgmt-core 1.6.0 python
|
||||||
azure-mgmt-core 1.4.0 python
|
azure-mgmt-dns 9.0.0 python
|
||||||
azure-mgmt-dns 8.1.0 python
|
backports-tarfile 1.2.0 python
|
||||||
bash 5.2.15-r5 apk
|
bash 5.2.37-r0 apk
|
||||||
beautifulsoup4 4.12.2 python
|
beautifulsoup4 4.14.2 python
|
||||||
boto3 1.28.25 python
|
boto3 1.41.5 python
|
||||||
botocore 1.31.25 python
|
botocore 1.41.5 python
|
||||||
brotli-libs 1.0.9-r14 apk
|
brotli-libs 1.1.0-r2 apk
|
||||||
bs4 0.0.1 python
|
bs4 0.0.2 python
|
||||||
busybox 1.36.1 binary
|
busybox 1.37.0-r20 apk
|
||||||
busybox 1.36.1-r2 apk
|
busybox-binsh 1.37.0-r20 apk
|
||||||
busybox-binsh 1.36.1-r2 apk
|
c-ares 1.34.5-r0 apk
|
||||||
c-client 2007f-r15 apk
|
c-client 2007f-r15 apk
|
||||||
ca-certificates 20230506-r0 apk
|
ca-certificates 20250911-r0 apk
|
||||||
ca-certificates-bundle 20230506-r0 apk
|
ca-certificates-bundle 20250911-r0 apk
|
||||||
cachetools 5.3.1 python
|
cachetools 6.2.2 python
|
||||||
certbot 2.6.0 python
|
catatonit 0.2.1-r0 apk
|
||||||
certbot-dns-acmedns 0.1.0 python
|
certbot 5.1.0 python
|
||||||
certbot-dns-aliyun 2.0.0 python
|
certbot-dns-acmedns 0.1.0 python
|
||||||
certbot-dns-azure 2.3.0 python
|
certbot-dns-aliyun 2.0.0 python
|
||||||
certbot-dns-bunny 0.0.9 python
|
certbot-dns-azure 1.5.0 python
|
||||||
certbot-dns-cloudflare 2.6.0 python
|
certbot-dns-bunny 3.0.0 python
|
||||||
certbot-dns-cpanel 0.4.0 python
|
certbot-dns-cloudflare 5.1.0 python
|
||||||
certbot-dns-desec 1.2.1 python
|
certbot-dns-cpanel 0.4.0 python
|
||||||
certbot-dns-digitalocean 2.6.0 python
|
certbot-dns-desec 1.3.2 python
|
||||||
certbot-dns-directadmin 1.0.3 python
|
certbot-dns-digitalocean 5.1.0 python
|
||||||
certbot-dns-dnsimple 2.6.0 python
|
certbot-dns-directadmin 1.0.15 python
|
||||||
certbot-dns-dnsmadeeasy 2.6.0 python
|
certbot-dns-dnsimple 5.1.0 python
|
||||||
certbot-dns-dnspod 0.1.0 python
|
certbot-dns-dnsmadeeasy 5.1.0 python
|
||||||
certbot-dns-do 0.31.0 python
|
certbot-dns-dnspod 0.1.0 python
|
||||||
certbot-dns-domeneshop 0.2.9 python
|
certbot-dns-do 0.31.0 python
|
||||||
certbot-dns-dreamhost 1.0 python
|
certbot-dns-domeneshop 0.2.9 python
|
||||||
certbot-dns-duckdns 1.3 python
|
certbot-dns-dreamhost 1.0 python
|
||||||
certbot-dns-dynu 0.0.4 python
|
certbot-dns-duckdns 1.7.0 python
|
||||||
certbot-dns-gehirn 2.6.0 python
|
certbot-dns-dynudns 0.0.6 python
|
||||||
certbot-dns-godaddy 2.6.0 python
|
certbot-dns-freedns 0.2.0 python
|
||||||
certbot-dns-google 2.6.0 python
|
certbot-dns-gehirn 5.1.0 python
|
||||||
certbot-dns-google-domains 0.1.11 python
|
certbot-dns-glesys 2.1.0 python
|
||||||
certbot-dns-he 1.0.0 python
|
certbot-dns-godaddy 2.8.0 python
|
||||||
certbot-dns-hetzner 2.0.0 python
|
certbot-dns-google 5.1.0 python
|
||||||
certbot-dns-infomaniak 0.2.1 python
|
certbot-dns-he 1.0.0 python
|
||||||
certbot-dns-inwx 2.2.0 python
|
certbot-dns-hetzner 2.0.1 python
|
||||||
certbot-dns-ionos 2022.11.24 python
|
certbot-dns-infomaniak 0.2.4 python
|
||||||
certbot-dns-linode 2.6.0 python
|
certbot-dns-inwx 3.0.3 python
|
||||||
certbot-dns-loopia 1.0.1 python
|
certbot-dns-ionos 2024.11.9 python
|
||||||
certbot-dns-luadns 2.6.0 python
|
certbot-dns-linode 5.1.0 python
|
||||||
certbot-dns-netcup 1.3.0 python
|
certbot-dns-loopia 1.0.1 python
|
||||||
certbot-dns-njalla 1.0.0 python
|
certbot-dns-luadns 5.1.0 python
|
||||||
certbot-dns-nsone 2.6.0 python
|
certbot-dns-namecheap 1.0.0 python
|
||||||
certbot-dns-ovh 2.6.0 python
|
certbot-dns-netcup 2.0.0 python
|
||||||
certbot-dns-porkbun 0.8 python
|
certbot-dns-njalla 2.0.2 python
|
||||||
certbot-dns-rfc2136 2.6.0 python
|
certbot-dns-nsone 5.1.0 python
|
||||||
certbot-dns-route53 2.6.0 python
|
certbot-dns-ovh 5.1.0 python
|
||||||
certbot-dns-sakuracloud 2.6.0 python
|
certbot-dns-porkbun 0.11.0 python
|
||||||
certbot-dns-standalone 1.1 python
|
certbot-dns-rfc2136 5.1.0 python
|
||||||
certbot-dns-transip 0.5.2 python
|
certbot-dns-route53 5.1.0 python
|
||||||
certbot-dns-vultr 1.1.0 python
|
certbot-dns-sakuracloud 5.1.0 python
|
||||||
certbot-plugin-gandi 1.4.3 python
|
certbot-dns-standalone 1.2.1 python
|
||||||
certifi 2023.7.22 python
|
certbot-dns-transip 0.5.2 python
|
||||||
cffi 1.15.1 python
|
certbot-dns-vultr 1.1.0 python
|
||||||
charset-normalizer 3.2.0 python
|
certbot-plugin-gandi 1.5.0 python
|
||||||
cloudflare 2.11.6 python
|
certifi 2025.11.12 python
|
||||||
configobj 5.0.8 python
|
cffi 2.0.0 python
|
||||||
coreutils 9.3-r1 apk
|
charset-normalizer 3.4.4 python
|
||||||
cryptography 41.0.3 python
|
cli UNKNOWN binary
|
||||||
curl 8.2.1-r0 apk
|
cli-32 UNKNOWN binary
|
||||||
dataclasses-json 0.5.14 python
|
cli-64 UNKNOWN binary
|
||||||
distro 1.8.0 python
|
cli-arm64 UNKNOWN binary
|
||||||
dns-lexicon 3.11.7 python
|
cloudflare 2.19.4 python
|
||||||
dnslib 0.9.23 python
|
composer 2.9.2 binary
|
||||||
dnspython 2.4.2 python
|
configargparse 1.7.1 python
|
||||||
domeneshop 0.4.3 python
|
configobj 5.0.9 python
|
||||||
fail2ban 1.0.2 python
|
coreutils 9.7-r1 apk
|
||||||
fail2ban 1.0.2-r2 apk
|
coreutils-env 9.7-r1 apk
|
||||||
fail2ban-pyc 1.0.2-r2 apk
|
coreutils-fmt 9.7-r1 apk
|
||||||
filelock 3.12.2 python
|
coreutils-sha512sum 9.7-r1 apk
|
||||||
fontconfig 2.14.2-r3 apk
|
cryptography 46.0.3 python
|
||||||
freetype 2.13.0-r5 apk
|
curl 8.14.1-r2 apk
|
||||||
future 0.18.3 python
|
distro 1.9.0 python
|
||||||
gdbm 1.23-r1 apk
|
dns-lexicon 3.23.2 python
|
||||||
git 2.40.1-r0 apk
|
dnslib 0.9.26 python
|
||||||
git-perl 2.40.1-r0 apk
|
dnspython 2.8.0 python
|
||||||
gmp 6.2.1-r3 apk
|
domeneshop 0.4.4 python
|
||||||
gnupg 2.4.3-r0 apk
|
fail2ban 1.1.0 python
|
||||||
gnupg-dirmngr 2.4.3-r0 apk
|
fail2ban 1.1.0-r3 apk
|
||||||
gnupg-gpgconf 2.4.3-r0 apk
|
fail2ban-pyc 1.1.0-r3 apk
|
||||||
gnupg-keyboxd 2.4.3-r0 apk
|
filelock 3.20.0 python
|
||||||
gnupg-utils 2.4.3-r0 apk
|
findutils 4.10.0-r0 apk
|
||||||
gnupg-wks-client 2.4.3-r0 apk
|
fontconfig 2.15.0-r3 apk
|
||||||
gnutls 3.8.0-r2 apk
|
freetype 2.13.3-r0 apk
|
||||||
google-api-core 2.11.1 python
|
future 1.0.0 python
|
||||||
google-api-python-client 2.96.0 python
|
gdbm 1.24-r0 apk
|
||||||
google-auth 2.22.0 python
|
git 2.49.1-r0 apk
|
||||||
google-auth-httplib2 0.1.0 python
|
git-init-template 2.49.1-r0 apk
|
||||||
googleapis-common-protos 1.60.0 python
|
git-perl 2.49.1-r0 apk
|
||||||
gpg 2.4.3-r0 apk
|
gmp 6.3.0-r3 apk
|
||||||
gpg-agent 2.4.3-r0 apk
|
gnupg 2.4.7-r0 apk
|
||||||
gpg-wks-server 2.4.3-r0 apk
|
gnupg-dirmngr 2.4.7-r0 apk
|
||||||
gpgsm 2.4.3-r0 apk
|
gnupg-gpgconf 2.4.7-r0 apk
|
||||||
gpgv 2.4.3-r0 apk
|
gnupg-keyboxd 2.4.7-r0 apk
|
||||||
httplib2 0.22.0 python
|
gnupg-utils 2.4.7-r0 apk
|
||||||
icu-data-en 73.2-r2 apk
|
gnupg-wks-client 2.4.7-r0 apk
|
||||||
icu-libs 73.2-r2 apk
|
gnutls 3.8.8-r0 apk
|
||||||
idna 3.4 python
|
google-api-core 2.28.1 python
|
||||||
importlib-metadata 6.8.0 python
|
google-api-python-client 2.187.0 python
|
||||||
ip6tables 1.8.9-r2 apk
|
google-auth 2.43.0 python
|
||||||
iptables 1.8.9-r2 apk
|
google-auth-httplib2 0.2.1 python
|
||||||
isodate 0.6.1 python
|
googleapis-common-protos 1.72.0 python
|
||||||
jmespath 1.0.1 python
|
gpg 2.4.7-r0 apk
|
||||||
josepy 1.13.0 python
|
gpg-agent 2.4.7-r0 apk
|
||||||
jq 1.6-r3 apk
|
gpg-wks-server 2.4.7-r0 apk
|
||||||
jsonlines 3.1.0 python
|
gpgsm 2.4.7-r0 apk
|
||||||
jsonpickle 3.0.1 python
|
gpgv 2.4.7-r0 apk
|
||||||
libacl 2.3.1-r3 apk
|
gui UNKNOWN binary
|
||||||
libassuan 2.5.6-r0 apk
|
gui-32 UNKNOWN binary
|
||||||
libattr 2.5.1-r4 apk
|
gui-64 UNKNOWN binary
|
||||||
libavif 0.11.1-r2 apk
|
gui-arm64 UNKNOWN binary
|
||||||
libbsd 0.11.7-r1 apk
|
httplib2 0.31.0 python
|
||||||
libbz2 1.0.8-r5 apk
|
icu-data-en 76.1-r1 apk
|
||||||
libc-utils 0.7.2-r5 apk
|
icu-libs 76.1-r1 apk
|
||||||
libcrypto3 3.1.2-r0 apk
|
idna 3.11 python
|
||||||
libcurl 8.2.1-r0 apk
|
importlib-metadata 8.0.0 python
|
||||||
libdav1d 1.2.1-r0 apk
|
inflect 7.3.1 python
|
||||||
libedit 20221030.3.1-r1 apk
|
inotify-tools 4.23.9.0-r0 apk
|
||||||
libevent 2.1.12-r6 apk
|
inotify-tools-libs 4.23.9.0-r0 apk
|
||||||
libexpat 2.5.0-r1 apk
|
inwx-domrobot 3.2.0 python
|
||||||
libffi 3.4.4-r2 apk
|
iptables 1.8.11-r1 apk
|
||||||
libgcc 12.2.1_git20220924-r10 apk
|
iptables-legacy 1.8.11-r1 apk
|
||||||
libgcrypt 1.10.2-r1 apk
|
isodate 0.7.2 python
|
||||||
libgd 2.3.3-r7 apk
|
jaraco-collections 5.1.0 python
|
||||||
libgpg-error 1.47-r1 apk
|
jaraco-context 5.3.0 python
|
||||||
libice 1.1.1-r2 apk
|
jaraco-functools 4.0.1 python
|
||||||
libidn2 2.3.4-r1 apk
|
jaraco-text 3.12.1 python
|
||||||
libintl 0.21.1-r7 apk
|
jinja2 3.1.6 python
|
||||||
libjpeg-turbo 2.1.5.1-r3 apk
|
jmespath 1.0.1 python
|
||||||
libksba 1.6.4-r0 apk
|
josepy 2.2.0 python
|
||||||
libldap 2.6.5-r0 apk
|
jq 1.8.1-r0 apk
|
||||||
libmaxminddb-libs 1.7.1-r1 apk
|
jsonlines 4.0.0 python
|
||||||
libmcrypt 2.5.8-r10 apk
|
jsonpickle 4.1.1 python
|
||||||
libmd 1.0.4-r2 apk
|
libapk2 2.14.9-r3 apk
|
||||||
libmemcached-libs 1.1.4-r1 apk
|
libassuan 2.5.7-r0 apk
|
||||||
libmnl 1.0.5-r1 apk
|
libattr 2.5.2-r2 apk
|
||||||
libncursesw 6.4_p20230506-r0 apk
|
libavif 1.3.0-r0 apk
|
||||||
libnftnl 1.2.5-r1 apk
|
libbsd 0.12.2-r0 apk
|
||||||
libpanelw 6.4_p20230506-r0 apk
|
libbz2 1.0.8-r6 apk
|
||||||
libpng 1.6.39-r3 apk
|
libcrypto3 3.5.4-r0 apk
|
||||||
libpq 15.3-r0 apk
|
libcurl 8.14.1-r2 apk
|
||||||
libproc2 4.0.3-r1 apk
|
libdav1d 1.5.1-r0 apk
|
||||||
libsasl 2.1.28-r4 apk
|
libedit 20250104.3.1-r1 apk
|
||||||
libseccomp 2.5.4-r2 apk
|
libevent 2.1.12-r8 apk
|
||||||
libsm 1.2.4-r1 apk
|
libexpat 2.7.3-r0 apk
|
||||||
libsodium 1.0.18-r3 apk
|
libffi 3.4.8-r0 apk
|
||||||
libssl3 3.1.2-r0 apk
|
libgcc 14.2.0-r6 apk
|
||||||
libstdc++ 12.2.1_git20220924-r10 apk
|
libgcrypt 1.10.3-r1 apk
|
||||||
libtasn1 4.19.0-r1 apk
|
libgd 2.3.3-r10 apk
|
||||||
libunistring 1.1-r1 apk
|
libgpg-error 1.55-r0 apk
|
||||||
libuuid 2.38.1-r8 apk
|
libice 1.1.2-r0 apk
|
||||||
libwebp 1.3.1-r0 apk
|
libidn2 2.3.7-r0 apk
|
||||||
libx11 1.8.4-r4 apk
|
libintl 0.24.1-r0 apk
|
||||||
libxau 1.0.11-r2 apk
|
libip4tc 1.8.11-r1 apk
|
||||||
libxcb 1.15-r1 apk
|
libip6tc 1.8.11-r1 apk
|
||||||
libxdmcp 1.1.4-r2 apk
|
libjpeg-turbo 3.1.0-r0 apk
|
||||||
libxext 1.3.5-r2 apk
|
libksba 1.6.7-r0 apk
|
||||||
libxml2 2.11.4-r0 apk
|
libldap 2.6.8-r0 apk
|
||||||
libxpm 3.5.16-r1 apk
|
libmaxminddb-libs 1.9.1-r0 apk
|
||||||
libxslt 1.1.38-r0 apk
|
libmd 1.1.0-r0 apk
|
||||||
libxt 1.3.0-r2 apk
|
libmemcached-libs 1.1.4-r1 apk
|
||||||
libzip 1.9.2-r2 apk
|
libmnl 1.0.5-r2 apk
|
||||||
linux-pam 1.5.2-r10 apk
|
libncursesw 6.5_p20250503-r0 apk
|
||||||
logrotate 3.21.0-r1 apk
|
libnftnl 1.2.9-r0 apk
|
||||||
loopialib 0.2.0 python
|
libpanelw 6.5_p20250503-r0 apk
|
||||||
lxml 4.9.3 python
|
libpng 1.6.51-r0 apk
|
||||||
lz4-libs 1.9.4-r4 apk
|
libpq 17.7-r0 apk
|
||||||
marshmallow 3.20.1 python
|
libproc2 4.0.4-r3 apk
|
||||||
memcached 1.6.21 binary
|
libpsl 0.21.5-r3 apk
|
||||||
memcached 1.6.21-r0 apk
|
libsasl 2.1.28-r8 apk
|
||||||
mock 5.1.0 python
|
libseccomp 2.6.0-r0 apk
|
||||||
mpdecimal 2.5.1-r2 apk
|
libsharpyuv 1.5.0-r0 apk
|
||||||
msal 1.23.0 python
|
libsm 1.2.5-r0 apk
|
||||||
msal-extensions 1.0.0 python
|
libsodium 1.0.20-r0 apk
|
||||||
musl 1.2.4-r1 apk
|
libssl3 3.5.4-r0 apk
|
||||||
musl-utils 1.2.4-r1 apk
|
libstdc++ 14.2.0-r6 apk
|
||||||
mypy-extensions 1.0.0 python
|
libtasn1 4.20.0-r0 apk
|
||||||
nano 7.2-r1 apk
|
libunistring 1.3-r0 apk
|
||||||
ncurses-terminfo-base 6.4_p20230506-r0 apk
|
libuuid 2.41-r9 apk
|
||||||
netcat-openbsd 1.219-r1 apk
|
libwebp 1.5.0-r0 apk
|
||||||
nettle 3.8.1-r2 apk
|
libx11 1.8.11-r0 apk
|
||||||
nghttp2-libs 1.55.1-r0 apk
|
libxau 1.0.12-r0 apk
|
||||||
nginx 1.24.0-r6 apk
|
libxcb 1.17.0-r0 apk
|
||||||
nginx-mod-devel-kit 1.24.0-r6 apk
|
libxdmcp 1.1.5-r1 apk
|
||||||
nginx-mod-http-brotli 1.24.0-r6 apk
|
libxext 1.3.6-r2 apk
|
||||||
nginx-mod-http-dav-ext 1.24.0-r6 apk
|
libxml2 2.13.9-r0 apk
|
||||||
nginx-mod-http-echo 1.24.0-r6 apk
|
libxpm 3.5.17-r0 apk
|
||||||
nginx-mod-http-fancyindex 1.24.0-r6 apk
|
libxslt 1.1.43-r3 apk
|
||||||
nginx-mod-http-geoip2 1.24.0-r6 apk
|
libxt 1.3.1-r0 apk
|
||||||
nginx-mod-http-headers-more 1.24.0-r6 apk
|
libxtables 1.8.11-r1 apk
|
||||||
nginx-mod-http-image-filter 1.24.0-r6 apk
|
libyuv 0.0.1887.20251502-r1 apk
|
||||||
nginx-mod-http-perl 1.24.0-r6 apk
|
libzip 1.11.4-r0 apk
|
||||||
nginx-mod-http-redis2 1.24.0-r6 apk
|
linux-pam 1.7.0-r4 apk
|
||||||
nginx-mod-http-set-misc 1.24.0-r6 apk
|
logrotate 3.21.0-r1 apk
|
||||||
nginx-mod-http-upload-progress 1.24.0-r6 apk
|
loopialib 0.2.0 python
|
||||||
nginx-mod-http-xslt-filter 1.24.0-r6 apk
|
lxml 6.0.2 python
|
||||||
nginx-mod-mail 1.24.0-r6 apk
|
lz4-libs 1.10.0-r0 apk
|
||||||
nginx-mod-rtmp 1.24.0-r6 apk
|
markupsafe 3.0.3 python
|
||||||
nginx-mod-stream 1.24.0-r6 apk
|
memcached 1.6.32-r0 apk
|
||||||
nginx-mod-stream-geoip2 1.24.0-r6 apk
|
mock 5.2.0 python
|
||||||
nginx-vim 1.24.0-r6 apk
|
more-itertools 10.3.0 python
|
||||||
npth 1.6-r4 apk
|
mpdecimal 4.0.1-r0 apk
|
||||||
oniguruma 6.9.8-r1 apk
|
msal 1.34.0 python
|
||||||
openssl 3.1.2-r0 apk
|
msal-extensions 1.3.1 python
|
||||||
p11-kit 0.24.1-r2 apk
|
musl 1.2.5-r10 apk
|
||||||
packaging 23.1 python
|
musl-utils 1.2.5-r10 apk
|
||||||
parsedatetime 2.6 python
|
my-test-package 1.0 python
|
||||||
pcre 8.45-r3 apk
|
nano 8.4-r0 apk
|
||||||
pcre2 10.42-r1 apk
|
ncurses-terminfo-base 6.5_p20250503-r0 apk
|
||||||
perl 5.36.1-r2 apk
|
netcat-openbsd 1.229.1-r0 apk
|
||||||
perl-error 0.17029-r1 apk
|
nettle 3.10.1-r0 apk
|
||||||
perl-git 2.40.1-r0 apk
|
nghttp2-libs 1.65.0-r0 apk
|
||||||
php-cli 8.2.8 binary
|
nginx 1.28.0-r3 apk
|
||||||
php-fpm 8.2.8 binary
|
nginx-mod-devel-kit 1.28.0-r3 apk
|
||||||
php82 8.2.8-r0 apk
|
nginx-mod-http-brotli 1.28.0-r3 apk
|
||||||
php82-bcmath 8.2.8-r0 apk
|
nginx-mod-http-dav-ext 1.28.0-r3 apk
|
||||||
php82-bz2 8.2.8-r0 apk
|
nginx-mod-http-echo 1.28.0-r3 apk
|
||||||
php82-common 8.2.8-r0 apk
|
nginx-mod-http-fancyindex 1.28.0-r3 apk
|
||||||
php82-ctype 8.2.8-r0 apk
|
nginx-mod-http-geoip2 1.28.0-r3 apk
|
||||||
php82-curl 8.2.8-r0 apk
|
nginx-mod-http-headers-more 1.28.0-r3 apk
|
||||||
php82-dom 8.2.8-r0 apk
|
nginx-mod-http-image-filter 1.28.0-r3 apk
|
||||||
php82-exif 8.2.8-r0 apk
|
nginx-mod-http-perl 1.28.0-r3 apk
|
||||||
php82-fileinfo 8.2.8-r0 apk
|
nginx-mod-http-redis2 1.28.0-r3 apk
|
||||||
php82-fpm 8.2.8-r0 apk
|
nginx-mod-http-set-misc 1.28.0-r3 apk
|
||||||
php82-ftp 8.2.8-r0 apk
|
nginx-mod-http-upload-progress 1.28.0-r3 apk
|
||||||
php82-gd 8.2.8-r0 apk
|
nginx-mod-http-xslt-filter 1.28.0-r3 apk
|
||||||
php82-gmp 8.2.8-r0 apk
|
nginx-mod-mail 1.28.0-r3 apk
|
||||||
php82-iconv 8.2.8-r0 apk
|
nginx-mod-rtmp 1.28.0-r3 apk
|
||||||
php82-imap 8.2.8-r0 apk
|
nginx-mod-stream 1.28.0-r3 apk
|
||||||
php82-intl 8.2.8-r0 apk
|
nginx-mod-stream-geoip2 1.28.0-r3 apk
|
||||||
php82-ldap 8.2.8-r0 apk
|
nginx-vim 1.28.0-r3 apk
|
||||||
php82-mbstring 8.2.8-r0 apk
|
npth 1.8-r0 apk
|
||||||
php82-mysqli 8.2.8-r0 apk
|
oniguruma 6.9.10-r0 apk
|
||||||
php82-mysqlnd 8.2.8-r0 apk
|
openssl 3.5.4-r0 apk
|
||||||
php82-opcache 8.2.8-r0 apk
|
p11-kit 0.25.5-r2 apk
|
||||||
php82-openssl 8.2.8-r0 apk
|
packaging 24.2 python
|
||||||
php82-pdo 8.2.8-r0 apk
|
parsedatetime 2.6 python
|
||||||
php82-pdo_mysql 8.2.8-r0 apk
|
pcre2 10.46-r0 apk
|
||||||
php82-pdo_odbc 8.2.8-r0 apk
|
perl 5.40.3-r0 apk
|
||||||
php82-pdo_pgsql 8.2.8-r0 apk
|
perl-error 0.17030-r0 apk
|
||||||
php82-pdo_sqlite 8.2.8-r0 apk
|
perl-git 2.49.1-r0 apk
|
||||||
php82-pear 8.2.8-r0 apk
|
php84 8.4.14-r0 apk
|
||||||
php82-pecl-apcu 5.1.22-r0 apk
|
php84-bcmath 8.4.14-r0 apk
|
||||||
php82-pecl-igbinary 3.2.14-r0 apk
|
php84-bz2 8.4.14-r0 apk
|
||||||
php82-pecl-mcrypt 1.0.6-r0 apk
|
php84-common 8.4.14-r0 apk
|
||||||
php82-pecl-memcached 3.2.0-r1 apk
|
php84-ctype 8.4.14-r0 apk
|
||||||
php82-pecl-msgpack 2.2.0-r0 apk
|
php84-curl 8.4.14-r0 apk
|
||||||
php82-pecl-redis 5.3.7-r2 apk
|
php84-dom 8.4.14-r0 apk
|
||||||
php82-pgsql 8.2.8-r0 apk
|
php84-exif 8.4.14-r0 apk
|
||||||
php82-phar 8.2.8-r0 apk
|
php84-fileinfo 8.4.14-r0 apk
|
||||||
php82-posix 8.2.8-r0 apk
|
php84-fpm 8.4.14-r0 apk
|
||||||
php82-session 8.2.8-r0 apk
|
php84-ftp 8.4.14-r0 apk
|
||||||
php82-simplexml 8.2.8-r0 apk
|
php84-gd 8.4.14-r0 apk
|
||||||
php82-soap 8.2.8-r0 apk
|
php84-gmp 8.4.14-r0 apk
|
||||||
php82-sockets 8.2.8-r0 apk
|
php84-iconv 8.4.14-r0 apk
|
||||||
php82-sodium 8.2.8-r0 apk
|
php84-intl 8.4.14-r0 apk
|
||||||
php82-sqlite3 8.2.8-r0 apk
|
php84-ldap 8.4.14-r0 apk
|
||||||
php82-tokenizer 8.2.8-r0 apk
|
php84-mbstring 8.4.14-r0 apk
|
||||||
php82-xml 8.2.8-r0 apk
|
php84-mysqli 8.4.14-r0 apk
|
||||||
php82-xmlreader 8.2.8-r0 apk
|
php84-mysqlnd 8.4.14-r0 apk
|
||||||
php82-xmlwriter 8.2.8-r0 apk
|
php84-opcache 8.4.14-r0 apk
|
||||||
php82-xsl 8.2.8-r0 apk
|
php84-openssl 8.4.14-r0 apk
|
||||||
php82-zip 8.2.8-r0 apk
|
php84-pdo 8.4.14-r0 apk
|
||||||
pinentry 1.2.1-r1 apk
|
php84-pdo_mysql 8.4.14-r0 apk
|
||||||
pip 23.2.1 python
|
php84-pdo_odbc 8.4.14-r0 apk
|
||||||
pkb-client 1.2 python
|
php84-pdo_pgsql 8.4.14-r0 apk
|
||||||
popt 1.19-r2 apk
|
php84-pdo_sqlite 8.4.14-r0 apk
|
||||||
portalocker 2.7.0 python
|
php84-pear 8.4.14-r0 apk
|
||||||
procps-ng 4.0.3-r1 apk
|
php84-pecl-apcu 5.1.27-r0 apk
|
||||||
protobuf 4.24.0 python
|
php84-pecl-igbinary 3.2.16-r1 apk
|
||||||
publicsuffixlist 0.9.4 python
|
php84-pecl-imap 1.0.3-r0 apk
|
||||||
pyOpenSSL 23.2.0 python
|
php84-pecl-memcached 3.3.0-r0 apk
|
||||||
pyRFC3339 1.1 python
|
php84-pecl-msgpack 3.0.0-r0 apk
|
||||||
pyacmedns 0.4 python
|
php84-pecl-redis 6.3.0-r0 apk
|
||||||
pyasn1 0.5.0 python
|
php84-pgsql 8.4.14-r0 apk
|
||||||
pyasn1-modules 0.3.0 python
|
php84-phar 8.4.14-r0 apk
|
||||||
pyc 0.1-r0 apk
|
php84-posix 8.4.14-r0 apk
|
||||||
pycparser 2.21 python
|
php84-session 8.4.14-r0 apk
|
||||||
pyparsing 3.1.1 python
|
php84-simplexml 8.4.14-r0 apk
|
||||||
python 3.11.4 binary
|
php84-soap 8.4.14-r0 apk
|
||||||
python-dateutil 2.8.2 python
|
php84-sockets 8.4.14-r0 apk
|
||||||
python-digitalocean 1.17.0 python
|
php84-sodium 8.4.14-r0 apk
|
||||||
python-transip 0.6.0 python
|
php84-sqlite3 8.4.14-r0 apk
|
||||||
python3 3.11.4-r0 apk
|
php84-tokenizer 8.4.14-r0 apk
|
||||||
python3-pyc 3.11.4-r0 apk
|
php84-xml 8.4.14-r0 apk
|
||||||
python3-pycache-pyc0 3.11.4-r0 apk
|
php84-xmlreader 8.4.14-r0 apk
|
||||||
pytz 2023.3 python
|
php84-xmlwriter 8.4.14-r0 apk
|
||||||
readline 8.2.1-r1 apk
|
php84-xsl 8.4.14-r0 apk
|
||||||
requests 2.31.0 python
|
php84-zip 8.4.14-r0 apk
|
||||||
requests-file 1.5.1 python
|
pinentry 1.3.1-r0 apk
|
||||||
requests-mock 1.11.0 python
|
pip 25.3 python
|
||||||
rsa 4.9 python
|
pkb-client 2.2.0 python
|
||||||
s3transfer 0.6.1 python
|
platformdirs 4.2.2 python
|
||||||
scanelf 1.3.7-r1 apk
|
popt 1.19-r4 apk
|
||||||
setuptools 65.5.0 python
|
procps-ng 4.0.4-r3 apk
|
||||||
shadow 4.13-r4 apk
|
proto-plus 1.26.1 python
|
||||||
six 1.16.0 python
|
protobuf 6.33.1 python
|
||||||
skalibs 2.13.1.1-r1 apk
|
pyacmedns 0.4 python
|
||||||
soupsieve 2.4.1 python
|
pyasn1 0.6.1 python
|
||||||
sqlite-libs 3.41.2-r2 apk
|
pyasn1-modules 0.4.2 python
|
||||||
ssl_client 1.36.1-r2 apk
|
pyc 3.12.12-r0 apk
|
||||||
tiff 4.5.1-r0 apk
|
pycparser 2.23 python
|
||||||
tldextract 3.4.4 python
|
pyjwt 2.10.1 python
|
||||||
typing-inspect 0.9.0 python
|
pynamecheap 0.0.3 python
|
||||||
typing_extensions 4.7.1 python
|
pyopenssl 25.3.0 python
|
||||||
tzdata 2023c-r1 apk
|
pyotp 2.9.0 python
|
||||||
unixodbc 2.3.11-r2 apk
|
pyparsing 3.2.5 python
|
||||||
uritemplate 4.1.1 python
|
pyrfc3339 2.1.0 python
|
||||||
urllib3 1.26.16 python
|
python-dateutil 2.9.0.post0 python
|
||||||
utmps-libs 0.1.2.1-r1 apk
|
python-digitalocean 1.17.0 python
|
||||||
wheel 0.41.1 python
|
python-transip 0.6.0 python
|
||||||
whois 5.5.17-r0 apk
|
python3 3.12.12-r0 apk
|
||||||
xz-libs 5.4.3-r0 apk
|
python3-pyc 3.12.12-r0 apk
|
||||||
zipp 3.16.2 python
|
python3-pycache-pyc0 3.12.12-r0 apk
|
||||||
zlib 1.2.13-r1 apk
|
pyyaml 6.0.3 python
|
||||||
zope.interface 6.0 python
|
readline 8.2.13-r1 apk
|
||||||
zstd-libs 1.5.5-r4 apk
|
requests 2.32.5 python
|
||||||
|
requests-file 3.0.1 python
|
||||||
|
requests-mock 1.12.1 python
|
||||||
|
rsa 4.9.1 python
|
||||||
|
s3transfer 0.15.0 python
|
||||||
|
scanelf 1.3.8-r1 apk
|
||||||
|
setuptools 80.9.0 python
|
||||||
|
shadow 4.17.3-r0 apk
|
||||||
|
six 1.17.0 python
|
||||||
|
skalibs-libs 2.14.4.0-r0 apk
|
||||||
|
soupsieve 2.8 python
|
||||||
|
sqlite-libs 3.49.2-r1 apk
|
||||||
|
ssl_client 1.37.0-r20 apk
|
||||||
|
tiff 4.7.1-r0 apk
|
||||||
|
tldextract 5.3.0 python
|
||||||
|
tomli 2.0.1 python
|
||||||
|
typeguard 4.3.0 python
|
||||||
|
typing-extensions 4.12.2 python
|
||||||
|
typing-extensions 4.15.0 python
|
||||||
|
tzdata 2025b-r0 apk
|
||||||
|
unixodbc 2.3.12-r0 apk
|
||||||
|
uritemplate 4.2.0 python
|
||||||
|
urllib3 2.5.0 python
|
||||||
|
utmps-libs 0.1.3.1-r0 apk
|
||||||
|
wheel 0.45.1 python (+1 duplicate)
|
||||||
|
whois 5.6.3-r0 apk
|
||||||
|
xz-libs 5.8.1-r0 apk
|
||||||
|
zipp 3.19.2 python
|
||||||
|
zlib 1.3.1-r2 apk
|
||||||
|
zope-interface 8.1.1 python
|
||||||
|
zstd-libs 1.5.7-r0 apk
|
||||||
|
|||||||
333
readme-vars.yml
333
readme-vars.yml
@@ -6,72 +6,49 @@ project_url: "https://linuxserver.io"
|
|||||||
project_logo: "https://github.com/linuxserver/docker-templates/raw/master/linuxserver.io/img/swag.gif"
|
project_logo: "https://github.com/linuxserver/docker-templates/raw/master/linuxserver.io/img/swag.gif"
|
||||||
project_blurb: "SWAG - Secure Web Application Gateway (formerly known as letsencrypt, no relation to Let's Encrypt™) sets up an Nginx webserver and reverse proxy with php support and a built-in certbot client that automates free SSL server certificate generation and renewal processes (Let's Encrypt and ZeroSSL). It also contains fail2ban for intrusion prevention."
|
project_blurb: "SWAG - Secure Web Application Gateway (formerly known as letsencrypt, no relation to Let's Encrypt™) sets up an Nginx webserver and reverse proxy with php support and a built-in certbot client that automates free SSL server certificate generation and renewal processes (Let's Encrypt and ZeroSSL). It also contains fail2ban for intrusion prevention."
|
||||||
project_lsio_github_repo_url: "https://github.com/linuxserver/docker-{{ project_name }}"
|
project_lsio_github_repo_url: "https://github.com/linuxserver/docker-{{ project_name }}"
|
||||||
|
project_categories: "Reverse Proxy"
|
||||||
project_blurb_optional_extras_enabled: false
|
|
||||||
project_blurb_optional_extras: []
|
|
||||||
|
|
||||||
# supported architectures
|
# supported architectures
|
||||||
available_architectures:
|
available_architectures:
|
||||||
- { arch: "{{ arch_x86_64 }}", tag: "amd64-latest"}
|
- {arch: "{{ arch_x86_64 }}", tag: "amd64-latest"}
|
||||||
- { arch: "{{ arch_arm64 }}", tag: "arm64v8-latest"}
|
- {arch: "{{ arch_arm64 }}", tag: "arm64v8-latest"}
|
||||||
|
|
||||||
# development version
|
|
||||||
development_versions: false
|
|
||||||
development_versions_items:
|
|
||||||
- { tag: "latest", desc: "Stable releases" }
|
|
||||||
|
|
||||||
|
|
||||||
# container parameters
|
# container parameters
|
||||||
common_param_env_vars_enabled: true #PGID, PUID, etc, you can set it to 'optional'
|
common_param_env_vars_enabled: true
|
||||||
param_container_name: "{{ project_name }}"
|
param_container_name: "{{ project_name }}"
|
||||||
param_usage_include_net: false #you can set it to 'optional'
|
|
||||||
param_net: "host"
|
|
||||||
param_net_desc: "Shares host networking with container."
|
|
||||||
param_usage_include_env: true
|
param_usage_include_env: true
|
||||||
param_env_vars:
|
param_env_vars:
|
||||||
- { env_var: "TZ", env_value: "Europe/London", desc: "Specify a timezone to use EG Europe/London." }
|
- {env_var: "URL", env_value: "example.com", desc: "Top url you have control over (e.g. `example.com` if you own it, or `customsubdomain.example.com` if dynamic dns)."}
|
||||||
- { env_var: "URL", env_value: "yourdomain.url", desc: "Top url you have control over (`customdomain.com` if you own it, or `customsubdomain.ddnsprovider.com` if dynamic dns)." }
|
- {env_var: "VALIDATION", env_value: "http", desc: "Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set).", env_options: ["http", "dns"]}
|
||||||
- { env_var: "VALIDATION", env_value: "http", desc: "Certbot validation method to use, options are `http` or `dns` (`dns` method also requires `DNSPLUGIN` variable set)." }
|
|
||||||
param_usage_include_vols: true
|
param_usage_include_vols: true
|
||||||
param_volumes:
|
param_volumes:
|
||||||
- { vol_path: "/config", vol_host_path: "/path/to/appdata/config", desc: "All the config files including the webroot reside here." }
|
- {vol_path: "/config", vol_host_path: "/path/to/{{ project_name }}/config", desc: "Persistent config files"}
|
||||||
param_usage_include_ports: true
|
param_usage_include_ports: true
|
||||||
param_ports:
|
param_ports:
|
||||||
- { external_port: "443", internal_port: "443", port_desc: "Https port" }
|
- {external_port: "443", internal_port: "443", port_desc: "HTTPS port"}
|
||||||
param_device_map: false
|
|
||||||
param_devices:
|
|
||||||
- { device_path: "/dev/dri", device_host_path: "/dev/dri", desc: "For hardware transcoding" }
|
|
||||||
cap_add_param: true
|
cap_add_param: true
|
||||||
cap_add_param_vars:
|
cap_add_param_vars:
|
||||||
- { cap_add_var: "NET_ADMIN" }
|
- {cap_add_var: "NET_ADMIN", desc: "Required for fail2Ban to be able to modify iptables rules."}
|
||||||
|
|
||||||
# optional container parameters
|
# optional container parameters
|
||||||
opt_param_usage_include_env: true
|
opt_param_usage_include_env: true
|
||||||
opt_param_env_vars:
|
opt_param_env_vars:
|
||||||
- { env_var: "SUBDOMAINS", env_value: "www,", desc: "Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only)" }
|
- {env_var: "SUBDOMAINS", env_value: "www,", desc: "Subdomains you'd like the cert to cover (comma separated, no spaces) ie. `www,ftp,cloud`. For a wildcard cert, set this *exactly* to `wildcard` (wildcard cert is available via `dns` validation only)"}
|
||||||
- { env_var: "CERTPROVIDER", env_value: "", desc: "Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt." }
|
- {env_var: "CERTPROVIDER", env_value: "", desc: "Optionally define the cert provider. Set to `zerossl` for ZeroSSL certs (requires existing [ZeroSSL account](https://app.zerossl.com/signup) and the e-mail address entered in `EMAIL` env var). Otherwise defaults to Let's Encrypt."}
|
||||||
- { env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `gandi`, `gehirn`, `godaddy`, `google`, `google-domains`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`." }
|
- {env_var: "DNSPLUGIN", env_value: "cloudflare", desc: "Required if `VALIDATION` is set to `dns`. Options are `acmedns`, `aliyun`, `azure`, `bunny`, `cloudflare`, `cpanel`, `desec`, `digitalocean`, `directadmin`, `dnsimple`, `dnsmadeeasy`, `dnspod`, `do`, `domeneshop`, `dreamhost`, `duckdns`, `dynu`, `freedns`, `gandi`, `gehirn`, `glesys`, `godaddy`, `google`, `he`, `hetzner`, `infomaniak`, `inwx`, `ionos`, `linode`, `loopia`, `luadns`, `namecheap`, `netcup`, `njalla`, `nsone`, `ovh`, `porkbun`, `rfc2136`, `route53`, `sakuracloud`, `standalone`, `transip`, and `vultr`. Also need to enter the credentials into the corresponding ini (or json for some plugins) file under `/config/dns-conf`."}
|
||||||
- { env_var: "PROPAGATION", env_value: "", desc: "Optionally override (in seconds) the default propagation time for the dns plugins." }
|
- {env_var: "PROPAGATION", env_value: "", desc: "Optionally override (in seconds) the default propagation time for the dns plugins."}
|
||||||
- { env_var: "EMAIL", env_value: "", desc: "Optional e-mail address used for cert expiration notifications (Required for ZeroSSL)." }
|
- {env_var: "EMAIL", env_value: "", desc: "Optional e-mail address used for cert expiration notifications (Required for ZeroSSL)."}
|
||||||
- { env_var: "ONLY_SUBDOMAINS", env_value: "false", desc: "If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true`" }
|
- {env_var: "ONLY_SUBDOMAINS", env_value: "false", desc: "If you wish to get certs only for certain subdomains, but not the main domain (main domain may be hosted on another machine and cannot be validated), set this to `true`"}
|
||||||
- { env_var: "EXTRA_DOMAINS", env_value: "", desc: "Additional fully qualified domain names (comma separated, no spaces) ie. `extradomain.com,subdomain.anotherdomain.org,*.anotherdomain.org`" }
|
- {env_var: "EXTRA_DOMAINS", env_value: "", desc: "Additional fully qualified domain names (comma separated, no spaces) ie. `example.net,subdomain.example.net,*.example.org`"}
|
||||||
- { env_var: "STAGING", env_value: "false", desc: "Set to `true` to retrieve certs in staging mode. Rate limits will be much higher, but the resulting cert will not pass the browser's security test. Only to be used for testing purposes." }
|
- {env_var: "STAGING", env_value: "false", desc: "Set to `true` to retrieve certs in staging mode. Rate limits will be much higher, but the resulting cert will not pass the browser's security test. Only to be used for testing purposes."}
|
||||||
opt_param_usage_include_vols: false
|
- {env_var: "DISABLE_F2B", env_value: "", desc: "Set to `true` to disable the Fail2ban service in the container, if you're already running it elsewhere or using a different IPS."}
|
||||||
opt_param_volumes:
|
- {env_var: "SWAG_AUTORELOAD", env_value: "", desc: "Set to `true` to enable automatic reloading of confs on change without stopping/restarting nginx. Your filesystem must support inotify. This functionality was previously offered [via mod](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload)."}
|
||||||
- { vol_path: "/config", vol_host_path: "/path/to/appdata/config", desc: "Configuration files." }
|
- {env_var: "SWAG_AUTORELOAD_WATCHLIST", env_value: "", desc: "A [pipe](https://en.wikipedia.org/wiki/Vertical_bar)-separated list of additional folders for auto reload to watch in addition to `/config/nginx`"}
|
||||||
opt_param_usage_include_ports: true
|
opt_param_usage_include_ports: true
|
||||||
opt_param_ports:
|
opt_param_ports:
|
||||||
- { external_port: "80", internal_port: "80", port_desc: "Http port (required for http validation and http -> https redirect)" }
|
- {external_port: "80", internal_port: "80", port_desc: "HTTP port (required for HTTP validation and HTTP -> HTTPS redirect)"}
|
||||||
opt_param_device_map: false
|
- {external_port: "443", internal_port: "443/udp", port_desc: "QUIC (HTTP/3) port. Must be enabled in the default and proxy confs."}
|
||||||
opt_param_devices:
|
readonly_supported: true
|
||||||
- { device_path: "/dev/dri", device_host_path: "/dev/dri", desc: "For hardware transcoding" }
|
readonly_message: |
|
||||||
opt_cap_add_param: false
|
* `/tmp` must be mounted to tmpfs
|
||||||
opt_cap_add_param_vars:
|
* fail2ban will not be available
|
||||||
- { cap_add_var: "NET_ADMIN" }
|
|
||||||
|
|
||||||
optional_block_1: false
|
|
||||||
optional_block_1_items: ""
|
|
||||||
|
|
||||||
# application setup block
|
# application setup block
|
||||||
app_setup_block_enabled: true
|
app_setup_block_enabled: true
|
||||||
app_setup_block: |
|
app_setup_block: |
|
||||||
@@ -87,9 +64,24 @@ app_setup_block: |
|
|||||||
1. Certs that only cover your main subdomain (ie. `yoursubdomain.duckdns.org`, leave the `SUBDOMAINS` variable empty)
|
1. Certs that only cover your main subdomain (ie. `yoursubdomain.duckdns.org`, leave the `SUBDOMAINS` variable empty)
|
||||||
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
|
2. Certs that cover sub-subdomains of your main subdomain (ie. `*.yoursubdomain.duckdns.org`, set the `SUBDOMAINS` variable to `wildcard`)
|
||||||
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
|
* `--cap-add=NET_ADMIN` is required for fail2ban to modify iptables
|
||||||
* After setup, navigate to `https://yourdomain.url` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
|
* After setup, navigate to `https://example.com` to access the default homepage (http access through port 80 is disabled by default, you can enable it by editing the default site config at `/config/nginx/site-confs/default.conf`).
|
||||||
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances.
|
* Certs are checked nightly and if expiration is within 30 days, renewal is attempted. If your cert is about to expire in less than 30 days, check the logs under `/config/log/letsencrypt` to see why the renewals have been failing. It is recommended to input your e-mail in docker parameters so you receive expiration notices from Let's Encrypt in those circumstances.
|
||||||
|
|
||||||
|
### Certbot Plugins
|
||||||
|
|
||||||
|
SWAG includes many Certbot plugins out of the box, but not all plugins can be included.
|
||||||
|
If you need a plugin that is not included, the quickest way to have the plugin available is to use our [Universal Package Install Docker Mod](https://github.com/linuxserver/docker-mods/tree/universal-package-install).
|
||||||
|
|
||||||
|
Set the following environment variables on your container:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
DOCKER_MODS=linuxserver/mods:universal-package-install
|
||||||
|
INSTALL_PIP_PACKAGES=certbot-dns-<plugin>
|
||||||
|
```
|
||||||
|
|
||||||
|
Set the required credentials (usually found in the plugin documentation) in `/config/dns-conf/<plugin>.ini`.
|
||||||
|
It is recommended to attempt obtaining a certificate with `STAGING=true` first to make sure the plugin is working as expected.
|
||||||
|
|
||||||
### Security and password protection
|
### Security and password protection
|
||||||
|
|
||||||
* The container detects changes to url and subdomains, revokes existing certs and generates new ones during start.
|
* The container detects changes to url and subdomains, revokes existing certs and generates new ones during start.
|
||||||
@@ -131,7 +123,7 @@ app_setup_block: |
|
|||||||
* You can check which jails are active via `docker exec -it swag fail2ban-client status`
|
* You can check which jails are active via `docker exec -it swag fail2ban-client status`
|
||||||
* You can check the status of a specific jail via `docker exec -it swag fail2ban-client status <jail name>`
|
* You can check the status of a specific jail via `docker exec -it swag fail2ban-client status <jail name>`
|
||||||
* You can unban an IP via `docker exec -it swag fail2ban-client set <jail name> unbanip <IP>`
|
* You can unban an IP via `docker exec -it swag fail2ban-client set <jail name> unbanip <IP>`
|
||||||
* A list of commands can be found here: <https://www.fail2ban.org/wiki/index.php/Commands>
|
* A list of commands for fail2ban-client can be found [here](https://manpages.ubuntu.com/manpages/noble/man1/fail2ban-client.1.html)
|
||||||
|
|
||||||
### Updating configs
|
### Updating configs
|
||||||
|
|
||||||
@@ -147,80 +139,175 @@ app_setup_block: |
|
|||||||
* Proxy sample files WILL be updated, however your renamed (enabled) proxy files will not.
|
* Proxy sample files WILL be updated, however your renamed (enabled) proxy files will not.
|
||||||
* You can check the new sample and adjust your active config as needed.
|
* You can check the new sample and adjust your active config as needed.
|
||||||
|
|
||||||
|
### QUIC support
|
||||||
|
|
||||||
|
This image supports QUIC (also known as HTTP/3) but it must be explicitly enabled in each proxy conf, and the default conf, because if the listener is enabled and you don't expose 443/UDP, it can break connections with some browsers.
|
||||||
|
|
||||||
|
To enable QUIC, expose 443/UDP to your clients, then uncomment both QUIC listeners in all of your active proxy confs, as well as the default conf, and restart the container.
|
||||||
|
|
||||||
|
You should also uncomment the `Alt-Svc` header in your `ssl.conf` so that browsers are aware that you offer QUIC connectivity.
|
||||||
|
|
||||||
|
It is [recommended](https://quic-go.net/docs/quic/optimizations/#udp-buffer-sizes) to increase the UDP send/recieve buffer **on the host** by setting the `net.core.rmem_max` and `net.core.wmem_max` sysctls. Suggested values are 4-16Mb (4194304-16777216 bytes). For persistence between reboots use `/etc/sysctl.d/`.
|
||||||
|
|
||||||
### Migration from the old `linuxserver/letsencrypt` image
|
### Migration from the old `linuxserver/letsencrypt` image
|
||||||
|
|
||||||
Please follow the instructions [on this blog post](https://www.linuxserver.io/blog/2020-08-21-introducing-swag#migrate).
|
Please follow the instructions [on this blog post](https://www.linuxserver.io/blog/2020-08-21-introducing-swag#migrate).
|
||||||
|
# init diagram
|
||||||
|
init_diagram: |
|
||||||
|
"swag:latest": {
|
||||||
|
docker-mods
|
||||||
|
base {
|
||||||
|
fix-attr +\nlegacy cont-init
|
||||||
|
}
|
||||||
|
docker-mods -> base
|
||||||
|
legacy-services
|
||||||
|
custom services
|
||||||
|
init-services -> legacy-services
|
||||||
|
init-services -> custom services
|
||||||
|
custom services -> legacy-services
|
||||||
|
legacy-services -> ci-service-check
|
||||||
|
init-migrations -> init-adduser
|
||||||
|
init-swag-config -> init-certbot-config
|
||||||
|
init-nginx-end -> init-config
|
||||||
|
init-os-end -> init-config
|
||||||
|
init-config -> init-config-end
|
||||||
|
init-crontab-config -> init-config-end
|
||||||
|
init-outdated-config -> init-config-end
|
||||||
|
init-config -> init-crontab-config
|
||||||
|
init-mods-end -> init-custom-files
|
||||||
|
init-adduser -> init-device-perms
|
||||||
|
base -> init-envfile
|
||||||
|
init-swag-samples -> init-fail2ban-config
|
||||||
|
init-os-end -> init-folders
|
||||||
|
init-php -> init-keygen
|
||||||
|
base -> init-migrations
|
||||||
|
init-config-end -> init-mods
|
||||||
|
init-mods-package-install -> init-mods-end
|
||||||
|
init-mods -> init-mods-package-install
|
||||||
|
init-samples -> init-nginx
|
||||||
|
init-version-checks -> init-nginx-end
|
||||||
|
init-adduser -> init-os-end
|
||||||
|
init-device-perms -> init-os-end
|
||||||
|
init-envfile -> init-os-end
|
||||||
|
init-renew -> init-outdated-config
|
||||||
|
init-keygen -> init-permissions
|
||||||
|
init-certbot-config -> init-permissions-config
|
||||||
|
init-nginx -> init-php
|
||||||
|
init-permissions-config -> init-renew
|
||||||
|
init-config -> init-require-url
|
||||||
|
init-folders -> init-samples
|
||||||
|
init-custom-files -> init-services
|
||||||
|
init-fail2ban-config -> init-swag-config
|
||||||
|
init-require-url -> init-swag-folders
|
||||||
|
init-swag-folders -> init-swag-samples
|
||||||
|
init-permissions -> init-version-checks
|
||||||
|
init-services -> svc-cron
|
||||||
|
svc-cron -> legacy-services
|
||||||
|
init-services -> svc-fail2ban
|
||||||
|
svc-fail2ban -> legacy-services
|
||||||
|
init-services -> svc-nginx
|
||||||
|
svc-nginx -> legacy-services
|
||||||
|
init-services -> svc-php-fpm
|
||||||
|
svc-php-fpm -> legacy-services
|
||||||
|
init-services -> svc-swag-auto-reload
|
||||||
|
svc-swag-auto-reload -> legacy-services
|
||||||
|
}
|
||||||
|
Base Images: {
|
||||||
|
"baseimage-alpine-nginx:3.22" <- "baseimage-alpine:3.22"
|
||||||
|
}
|
||||||
|
"swag:latest" <- Base Images
|
||||||
# changelog
|
# changelog
|
||||||
changelogs:
|
changelogs:
|
||||||
- { date: "07.08.23:", desc: "Add Bunny DNS Configuration." }
|
- {date: "04.11.25:", desc: "Switch default Gandi credentials from API Key to Token, allow DNS propagation time for Azure DNS plugin."}
|
||||||
- { date: "27.07.23:", desc: "Added support for dreamhost validation." }
|
- {date: "18.07.25:", desc: "Rebase to Alpine 3.22 with PHP 8.4. Add QUIC support. Drop PHP bindings for mcrypt as it is no longer maintained."}
|
||||||
- { date: "25.05.23:", desc: "Rebase to Alpine 3.18, deprecate armhf." }
|
- {date: "05.05.25:", desc: "Disable Certbot's built in log rotation."}
|
||||||
- { date: "27.04.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf, authentik-location.conf, authentik-server.conf - Simplify auth configs and fix Set-Cookie header bug." }
|
- {date: "19.01.25:", desc: "Add [Auto Reload](https://github.com/linuxserver/docker-mods/tree/swag-auto-reload) functionality to SWAG."}
|
||||||
- { date: "13.04.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, authelia-location.conf, authentik-location.conf, and site-confs/default.conf - Move ssl.conf include to default.conf. Remove Authorization headers in authelia. Sort proxy_set_header in authelia and authentik." }
|
- {date: "17.12.24:", desc: "Rebase to Alpine 3.21."}
|
||||||
- { date: "25.03.23:", desc: "Fix renewal post hook." }
|
- {date: "21.10.24:", desc: "Fix naming issue with Dynu plugin. If you are using Dynu, please make sure your credentials are set in /config/dns-conf/dynu.ini and your DNSPLUGIN variable is set to dynu (not dynudns)."}
|
||||||
- { date: "10.03.23:", desc: "Cleanup unused csr and keys folders. See [certbot 2.3.0 release notes](https://github.com/certbot/certbot/releases/tag/v2.3.0)." }
|
- {date: "30.08.24:", desc: "Fix zerossl cert revocation."}
|
||||||
- { date: "09.03.23:", desc: "Add Google Domains DNS support, `google-domains`." }
|
- {date: "24.07.14:", desc: "Rebase to Alpine 3.20. Remove deprecated Google Domains certbot plugin. Existing users should update their nginx confs to avoid http2 deprecation warnings."}
|
||||||
- { date: "02.03.23:", desc: "Set permissions on crontabs during init." }
|
- {date: "01.07.24:", desc: "Fall back to iptables-legacy if iptables doesn't work."}
|
||||||
- { date: "09.02.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) proxy.conf, authelia-location.conf and authelia-server.conf - Add Authentik configs, update Authelia configs." }
|
- {date: "23.03.24:", desc: "Fix perms on the generated `priv-fullchain-bundle.pem`."}
|
||||||
- { date: "06.02.23:", desc: "Add porkbun support back in." }
|
- {date: "14.03.24:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf - Update Authelia conf samples with support for 4.38."}
|
||||||
- { date: "21.01.23:", desc: "Unpin certbot version (allow certbot 2.x). !!BREAKING CHANGE!! We are temporarily removing the certbot porkbun plugin until a new version is released that is compatible with certbot 2.x." }
|
- {date: "11.03.24:", desc: "Restore support for DynuDNS using `certbot-dns-dynudns`."}
|
||||||
- { date: "20.01.23:", desc: "Rebase to alpine 3.17 with php8.1." }
|
- {date: "06.03.24:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Cleanup default site conf."}
|
||||||
- { date: "16.01.23:", desc: "Remove nchan module because it keeps causing crashes." }
|
- {date: "04.03.24:", desc: "Remove `stream.conf` inside the container to allow users to include their own block in `nginx.conf`."}
|
||||||
- { date: "08.12.22:", desc: "Revamp certbot init."}
|
- {date: "23.01.24:", desc: "Rebase to Alpine 3.19 with php 8.3, add root periodic crontabs for logrotate."}
|
||||||
- { date: "03.12.22:", desc: "Remove defunct cloudxns plugin."}
|
- {date: "01.01.24:", desc: "Add GleSYS DNS plugin."}
|
||||||
- { date: "22.11.22:", desc: "Pin acme to the same version as certbot."}
|
- {date: "11.12.23:", desc: "Deprecate certbot-dns-dynu to resolve dependency conflicts with other plugins."}
|
||||||
- { date: "22.11.22:", desc: "Pin certbot to 1.32.0 until plugin compatibility improves."}
|
- {date: "30.11.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) site-confs/default.conf - Fix index.php being downloaded on 404."}
|
||||||
- { date: "05.11.22:", desc: "Update acmedns plugin handling."}
|
- {date: "23.11.23:", desc: "Run certbot as root to allow fix http validation."}
|
||||||
- { date: "06.10.22:", desc: "Switch to certbot-dns-duckdns. Update cpanel and gandi dns plugin handling. Minor adjustments to init logic." }
|
- {date: "01.10.23:", desc: "Fix \"unrecognized arguments\" issue in DirectAdmin DNS plugin."}
|
||||||
- { date: "05.10.22:", desc: "Use certbot file hooks instead of command line hooks" }
|
- {date: "28.08.23:", desc: "Add Namecheap DNS plugin."}
|
||||||
- { date: "04.10.22:", desc: "Add godaddy and porkbun dns plugins." }
|
- {date: "12.08.23:", desc: "Add FreeDNS plugin. Detect certbot DNS authenticators using CLI."}
|
||||||
- { date: "03.10.22:", desc: "Add default_server back to default site conf's https listen." }
|
- {date: "07.08.23:", desc: "Add Bunny DNS Configuration."}
|
||||||
- { date: "22.09.22:", desc: "Added support for DO DNS validation." }
|
- {date: "27.07.23:", desc: "Added support for dreamhost validation."}
|
||||||
- { date: "22.09.22:", desc: "Added certbot-dns-acmedns for DNS01 validation." }
|
- {date: "25.05.23:", desc: "Rebase to Alpine 3.18, deprecate armhf."}
|
||||||
- { date: "20.08.22:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf - Rebasing to alpine 3.15 with php8. Restructure nginx configs ([see changes announcement](https://info.linuxserver.io/issues/2022-08-20-nginx-base))." }
|
- {date: "27.04.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-location.conf, authelia-server.conf, authentik-location.conf, authentik-server.conf - Simplify auth configs and fix Set-Cookie header bug."}
|
||||||
- { date: "10.08.22:", desc: "Added support for Dynu DNS validation." }
|
- {date: "13.04.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, authelia-location.conf, authentik-location.conf, and site-confs/default.conf - Move ssl.conf include to default.conf. Remove Authorization headers in authelia. Sort proxy_set_header in authelia and authentik."}
|
||||||
- { date: "18.05.22:", desc: "Added support for Azure DNS validation." }
|
- {date: "25.03.23:", desc: "Fix renewal post hook."}
|
||||||
- { date: "09.04.22:", desc: "Added certbot-dns-loopia for DNS01 validation." }
|
- {date: "10.03.23:", desc: "Cleanup unused csr and keys folders. See [certbot 2.3.0 release notes](https://github.com/certbot/certbot/releases/tag/v2.3.0)."}
|
||||||
- { date: "05.04.22:", desc: "Added support for standalone DNS validation." }
|
- {date: "09.03.23:", desc: "Add Google Domains DNS support, `google-domains`."}
|
||||||
- { date: "28.03.22:", desc: "created a logfile for fail2ban nginx-unauthorized in /etc/cont-init.d/50-config" }
|
- {date: "02.03.23:", desc: "Set permissions on crontabs during init."}
|
||||||
- { date: "09.01.22:", desc: "Added a fail2ban jail for nginx unauthorized" }
|
- {date: "09.02.23:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) proxy.conf, authelia-location.conf and authelia-server.conf - Add Authentik configs, update Authelia configs."}
|
||||||
- { date: "21.12.21:", desc: "Fixed issue with iptables not working as expected" }
|
- {date: "06.02.23:", desc: "Add porkbun support back in."}
|
||||||
- { date: "30.11.21:", desc: "Move maxmind to a [new mod](https://github.com/linuxserver/docker-mods/tree/swag-maxmind)" }
|
- {date: "21.01.23:", desc: "Unpin certbot version (allow certbot 2.x). !!BREAKING CHANGE!! We are temporarily removing the certbot porkbun plugin until a new version is released that is compatible with certbot 2.x."}
|
||||||
- { date: "22.11.21:", desc: "Added support for Infomaniak DNS for certificate generation." }
|
- {date: "20.01.23:", desc: "Rebase to alpine 3.17 with php8.1."}
|
||||||
- { date: "20.11.21:", desc: "Added support for dnspod validation." }
|
- {date: "16.01.23:", desc: "Remove nchan module because it keeps causing crashes."}
|
||||||
- { date: "15.11.21:", desc: "Added support for deSEC DNS for wildcard certificate generation." }
|
- {date: "08.12.22:", desc: "Revamp certbot init."}
|
||||||
- { date: "26.10.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) proxy.conf - Mitigate <https://httpoxy.org/> vulnerabilities. Ref: <https://www.nginx.com/blog/mitigating-the-httpoxy-vulnerability-with-nginx#Defeating-the-Attack-using-NGINX-and-NGINX-Plus>" }
|
- {date: "03.12.22:", desc: "Remove defunct cloudxns plugin."}
|
||||||
- { date: "23.10.21:", desc: "Fix Hurricane Electric (HE) DNS validation." }
|
- {date: "22.11.22:", desc: "Pin acme to the same version as certbot."}
|
||||||
- { date: "12.10.21:", desc: "Fix deprecated LE root cert check to fix failures when using `STAGING=true`, and failures in revoking." }
|
- {date: "22.11.22:", desc: "Pin certbot to 1.32.0 until plugin compatibility improves."}
|
||||||
- { date: "06.10.21:", desc: "Added support for Hurricane Electric (HE) DNS validation. Added lxml build deps." }
|
- {date: "05.11.22:", desc: "Update acmedns plugin handling."}
|
||||||
- { date: "01.10.21:", desc: "Check if the cert uses the old LE root cert, revoke and regenerate if necessary. [Here's more info](https://twitter.com/letsencrypt/status/1443621997288767491) on LE root cert expiration" }
|
- {date: "06.10.22:", desc: "Switch to certbot-dns-duckdns. Update cpanel and gandi dns plugin handling. Minor adjustments to init logic."}
|
||||||
- { date: "19.09.21:", desc: "Add an optional header to opt out of Google FLoC in `ssl.conf`." }
|
- {date: "05.10.22:", desc: "Use certbot file hooks instead of command line hooks"}
|
||||||
- { date: "17.09.21:", desc: "Mark `SUBDOMAINS` var as optional." }
|
- {date: "04.10.22:", desc: "Add godaddy and porkbun dns plugins."}
|
||||||
- { date: "01.08.21:", desc: "Add support for ionos dns validation." }
|
- {date: "03.10.22:", desc: "Add default_server back to default site conf's https listen."}
|
||||||
- { date: "15.07.21:", desc: "Fix libmaxminddb issue due to upstream change." }
|
- {date: "22.09.22:", desc: "Added support for DO DNS validation."}
|
||||||
- { date: "07.07.21:", desc: "Rebase to alpine 3.14." }
|
- {date: "22.09.22:", desc: "Added certbot-dns-acmedns for DNS01 validation."}
|
||||||
- { date: "24.06.21:", desc: "Update default nginx conf folder." }
|
- {date: "20.08.22:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf - Rebasing to alpine 3.15 with php8. Restructure nginx configs ([see changes announcement](https://info.linuxserver.io/issues/2022-08-20-nginx-base))."}
|
||||||
- { date: "28.05.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-server.conf - Use `resolver.conf` and patch for `CVE-2021-32637`." }
|
- {date: "10.08.22:", desc: "Added support for Dynu DNS validation."}
|
||||||
- { date: "20.05.21:", desc: "Modify resolver.conf generation to detect and ignore ipv6." }
|
- {date: "18.05.22:", desc: "Added support for Azure DNS validation."}
|
||||||
- { date: "14.05.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, ssl.conf, proxy.conf, and the default site-conf - Rework nginx.conf to be inline with alpine upstream and relocate lines from other files. Use linuxserver.io wheel index for pip packages. Switch to using [ffdhe4096](https://ssl-config.mozilla.org/ffdhe4096.txt) for `dhparams.pem` per [RFC7919](https://datatracker.ietf.org/doc/html/rfc7919). Added `worker_processes.conf`, which sets the number of nginx workers, and `resolver.conf`, which sets the dns resolver. Both conf files are auto-generated only on first start and can be user modified later." }
|
- {date: "09.04.22:", desc: "Added certbot-dns-loopia for DNS01 validation."}
|
||||||
- { date: "21.04.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-server.conf and authelia-location.conf - Add remote name/email headers and pass http method." }
|
- {date: "05.04.22:", desc: "Added support for standalone DNS validation."}
|
||||||
- { date: "12.04.21:", desc: "Add php7-gmp and php7-pecl-mailparse." }
|
- {date: "28.03.22:", desc: "created a logfile for fail2ban nginx-unauthorized in /etc/cont-init.d/50-config"}
|
||||||
- { date: "12.04.21:", desc: "Add support for vultr dns validation." }
|
- {date: "09.01.22:", desc: "Added a fail2ban jail for nginx unauthorized"}
|
||||||
- { date: "14.03.21:", desc: "Add support for directadmin dns validation." }
|
- {date: "21.12.21:", desc: "Fixed issue with iptables not working as expected"}
|
||||||
- { date: "12.02.21:", desc: "Clean up rust/cargo cache, which ballooned the image size in the last couple of builds." }
|
- {date: "30.11.21:", desc: "Move maxmind to a [new mod](https://github.com/linuxserver/docker-mods/tree/swag-maxmind)"}
|
||||||
- { date: "10.02.21:", desc: "Fix aliyun, domeneshop, inwx and transip dns confs for existing users." }
|
- {date: "22.11.21:", desc: "Added support for Infomaniak DNS for certificate generation."}
|
||||||
- { date: "09.02.21:", desc: "Rebasing to alpine 3.13. Add nginx mods brotli and dav-ext. Remove nginx mods lua and lua-upstream (due to regression over the last couple of years)." }
|
- {date: "20.11.21:", desc: "Added support for dnspod validation."}
|
||||||
- { date: "26.01.21:", desc: "Add support for hetzner dns validation." }
|
- {date: "15.11.21:", desc: "Added support for deSEC DNS for wildcard certificate generation."}
|
||||||
- { date: "20.01.21:", desc: "Add check for ZeroSSL EAB retrieval." }
|
- {date: "26.10.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) proxy.conf - Mitigate <https://httpoxy.org/> vulnerabilities. Ref: <https://www.nginx.com/blog/mitigating-the-httpoxy-vulnerability-with-nginx#Defeating-the-Attack-using-NGINX-and-NGINX-Plus>"}
|
||||||
- { date: "08.01.21:", desc: "Add support for getting certs from [ZeroSSL](https://zerossl.com/) via optional `CERTPROVIDER` env var. Update aliyun, domeneshop, inwx and transip dns plugins with the new plugin names. Hide `donoteditthisfile.conf` because users were editing it despite its name. Suppress harmless error when no proxy confs are enabled." }
|
- {date: "23.10.21:", desc: "Fix Hurricane Electric (HE) DNS validation."}
|
||||||
- { date: "03.01.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) /config/nginx/site-confs/default.conf - Add helper pages to aid troubleshooting" }
|
- {date: "12.10.21:", desc: "Fix deprecated LE root cert check to fix failures when using `STAGING=true`, and failures in revoking."}
|
||||||
- { date: "10.12.20:", desc: "Add support for njalla dns validation" }
|
- {date: "06.10.21:", desc: "Added support for Hurricane Electric (HE) DNS validation. Added lxml build deps."}
|
||||||
- { date: "09.12.20:", desc: "Check for template/conf updates and notify in the log. Add support for gehirn and sakuracloud dns validation." }
|
- {date: "01.10.21:", desc: "Check if the cert uses the old LE root cert, revoke and regenerate if necessary. [Here's more info](https://twitter.com/letsencrypt/status/1443621997288767491) on LE root cert expiration"}
|
||||||
- { date: "01.11.20:", desc: "Add support for netcup dns validation" }
|
- {date: "19.09.21:", desc: "Add an optional header to opt out of Google FLoC in `ssl.conf`."}
|
||||||
- { date: "29.10.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) ssl.conf - Add frame-ancestors to Content-Security-Policy." }
|
- {date: "17.09.21:", desc: "Mark `SUBDOMAINS` var as optional."}
|
||||||
- { date: "04.10.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, proxy.conf, and ssl.conf - Minor cleanups and reordering." }
|
- {date: "01.08.21:", desc: "Add support for ionos dns validation."}
|
||||||
- { date: "20.09.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf - Added geoip2 configs. Added MAXMINDDB_LICENSE_KEY variable to readme."}
|
- {date: "15.07.21:", desc: "Fix libmaxminddb issue due to upstream change."}
|
||||||
- { date: "08.09.20:", desc: "Add php7-xsl." }
|
- {date: "07.07.21:", desc: "Rebase to alpine 3.14."}
|
||||||
- { date: "01.09.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, proxy.conf, and various proxy samples - Global websockets across all configs." }
|
- {date: "24.06.21:", desc: "Update default nginx conf folder."}
|
||||||
- { date: "03.08.20:", desc: "Initial release." }
|
- {date: "28.05.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-server.conf - Use `resolver.conf` and patch for `CVE-2021-32637`."}
|
||||||
|
- {date: "20.05.21:", desc: "Modify resolver.conf generation to detect and ignore ipv6."}
|
||||||
|
- {date: "14.05.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, ssl.conf, proxy.conf, and the default site-conf - Rework nginx.conf to be inline with alpine upstream and relocate lines from other files. Use linuxserver.io wheel index for pip packages. Switch to using [ffdhe4096](https://ssl-config.mozilla.org/ffdhe4096.txt) for `dhparams.pem` per [RFC7919](https://datatracker.ietf.org/doc/html/rfc7919). Added `worker_processes.conf`, which sets the number of nginx workers, and `resolver.conf`, which sets the dns resolver. Both conf files are auto-generated only on first start and can be user modified later."}
|
||||||
|
- {date: "21.04.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) authelia-server.conf and authelia-location.conf - Add remote name/email headers and pass http method."}
|
||||||
|
- {date: "12.04.21:", desc: "Add php7-gmp and php7-pecl-mailparse."}
|
||||||
|
- {date: "12.04.21:", desc: "Add support for vultr dns validation."}
|
||||||
|
- {date: "14.03.21:", desc: "Add support for directadmin dns validation."}
|
||||||
|
- {date: "12.02.21:", desc: "Clean up rust/cargo cache, which ballooned the image size in the last couple of builds."}
|
||||||
|
- {date: "10.02.21:", desc: "Fix aliyun, domeneshop, inwx and transip dns confs for existing users."}
|
||||||
|
- {date: "09.02.21:", desc: "Rebasing to alpine 3.13. Add nginx mods brotli and dav-ext. Remove nginx mods lua and lua-upstream (due to regression over the last couple of years)."}
|
||||||
|
- {date: "26.01.21:", desc: "Add support for hetzner dns validation."}
|
||||||
|
- {date: "20.01.21:", desc: "Add check for ZeroSSL EAB retrieval."}
|
||||||
|
- {date: "08.01.21:", desc: "Add support for getting certs from [ZeroSSL](https://zerossl.com/) via optional `CERTPROVIDER` env var. Update aliyun, domeneshop, inwx and transip dns plugins with the new plugin names. Hide `donoteditthisfile.conf` because users were editing it despite its name. Suppress harmless error when no proxy confs are enabled."}
|
||||||
|
- {date: "03.01.21:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) /config/nginx/site-confs/default.conf - Add helper pages to aid troubleshooting"}
|
||||||
|
- {date: "10.12.20:", desc: "Add support for njalla dns validation"}
|
||||||
|
- {date: "09.12.20:", desc: "Check for template/conf updates and notify in the log. Add support for gehirn and sakuracloud dns validation."}
|
||||||
|
- {date: "01.11.20:", desc: "Add support for netcup dns validation"}
|
||||||
|
- {date: "29.10.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) ssl.conf - Add frame-ancestors to Content-Security-Policy."}
|
||||||
|
- {date: "04.10.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, proxy.conf, and ssl.conf - Minor cleanups and reordering."}
|
||||||
|
- {date: "20.09.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf - Added geoip2 configs. Added MAXMINDDB_LICENSE_KEY variable to readme."}
|
||||||
|
- {date: "08.09.20:", desc: "Add php7-xsl."}
|
||||||
|
- {date: "01.09.20:", desc: "[Existing users should update:](https://github.com/linuxserver/docker-swag/blob/master/README.md#updating-configs) nginx.conf, proxy.conf, and various proxy samples - Global websockets across all configs."}
|
||||||
|
- {date: "03.08.20:", desc: "Initial release."}
|
||||||
|
|||||||
2
root/app/le-renew.sh
Normal file → Executable file
2
root/app/le-renew.sh
Normal file → Executable file
@@ -6,4 +6,4 @@ echo
|
|||||||
echo "<------------------------------------------------->"
|
echo "<------------------------------------------------->"
|
||||||
echo "cronjob running on $(date)"
|
echo "cronjob running on $(date)"
|
||||||
echo "Running certbot renew"
|
echo "Running certbot renew"
|
||||||
certbot renew --non-interactive
|
certbot renew --non-interactive --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini
|
||||||
|
|||||||
@@ -1,3 +1,3 @@
|
|||||||
# Instructions: https://github.com/bikram990/certbot-dns-dynu#configuration
|
# Instructions: https://github.com/DustyRah/certbot-dns-dynudns
|
||||||
# Replace with your API token from your dynu account.
|
# Replace with your API token from your dynudns account.
|
||||||
dns_dynu_auth_token = AbCbASsd!@34
|
dns_dynu_auth_token = AbCbASsd!@34
|
||||||
|
|||||||
4
root/defaults/dns-conf/freedns.ini
Normal file
4
root/defaults/dns-conf/freedns.ini
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
# Instructions: https://github.com/schleuss/certbot_dns_freedns#credentials
|
||||||
|
# Replace with your values
|
||||||
|
dns_freedns_username = myremoteuser
|
||||||
|
dns_freedns_password = verysecureremoteuserpassword
|
||||||
@@ -1,7 +1,6 @@
|
|||||||
# Instructions: https://github.com/obynio/certbot-plugin-gandi#usage
|
# Instructions: https://github.com/obynio/certbot-plugin-gandi#usage
|
||||||
# Replace with your value
|
# Replace with your Gandi Live DNS v5 Personal Access Token
|
||||||
# live dns v5 api key
|
dns_gandi_token=TOKEN
|
||||||
dns_gandi_api_key=APIKEY
|
|
||||||
|
|
||||||
# optional organization id, remove it if not used
|
# optional organization id, remove it if not used
|
||||||
#dns_gandi_sharing_id=SHARINGID
|
#dns_gandi_sharing_id=SHARINGID
|
||||||
|
|||||||
5
root/defaults/dns-conf/glesys.ini
Normal file
5
root/defaults/dns-conf/glesys.ini
Normal file
@@ -0,0 +1,5 @@
|
|||||||
|
# Instructions: https://github.com/runfalk/certbot-dns-glesys#usage
|
||||||
|
|
||||||
|
# GleSYS API credentials used by Certbot
|
||||||
|
dns_glesys_user = CL00000
|
||||||
|
dns_glesys_password = apikeygoeshere
|
||||||
@@ -1,4 +0,0 @@
|
|||||||
# Instructions: https://github.com/aaomidi/certbot-dns-google-domains#credentials
|
|
||||||
# Replace with your value
|
|
||||||
dns_google_domains_access_token = abcdef
|
|
||||||
dns_google_domains_zone = example.com
|
|
||||||
4
root/defaults/dns-conf/namecheap.ini
Normal file
4
root/defaults/dns-conf/namecheap.ini
Normal file
@@ -0,0 +1,4 @@
|
|||||||
|
# Instructions: https://github.com/knoxell/certbot-dns-namecheap#credentials
|
||||||
|
# Namecheap API credentials used by Certbot
|
||||||
|
dns_namecheap_username=my-username
|
||||||
|
dns_namecheap_api_key=my-api-key
|
||||||
1
root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default
Normal file → Executable file
1
root/defaults/etc/letsencrypt/renewal-hooks/deploy/10-default
Normal file → Executable file
@@ -5,4 +5,5 @@ cd /config/keys/letsencrypt || exit 1
|
|||||||
openssl pkcs12 -export -out privkey.pfx -inkey privkey.pem -in cert.pem -certfile chain.pem -passout pass:
|
openssl pkcs12 -export -out privkey.pfx -inkey privkey.pem -in cert.pem -certfile chain.pem -passout pass:
|
||||||
sleep 1
|
sleep 1
|
||||||
cat {privkey,fullchain}.pem >priv-fullchain-bundle.pem
|
cat {privkey,fullchain}.pem >priv-fullchain-bundle.pem
|
||||||
|
chmod 600 priv-fullchain-bundle.pem
|
||||||
chown -R abc:abc /config/etc/letsencrypt
|
chown -R abc:abc /config/etc/letsencrypt
|
||||||
|
|||||||
0
root/defaults/etc/letsencrypt/renewal-hooks/post/10-nginx
Normal file → Executable file
0
root/defaults/etc/letsencrypt/renewal-hooks/post/10-nginx
Normal file → Executable file
0
root/defaults/etc/letsencrypt/renewal-hooks/pre/10-nginx
Normal file → Executable file
0
root/defaults/etc/letsencrypt/renewal-hooks/pre/10-nginx
Normal file → Executable file
@@ -12,4 +12,4 @@ datepattern = {^LN-BEG}
|
|||||||
|
|
||||||
# DEV NOTES:
|
# DEV NOTES:
|
||||||
#
|
#
|
||||||
# Author: Will L (driz@linuxserver.io)
|
# Author: notdriz
|
||||||
|
|||||||
@@ -1,10 +1,10 @@
|
|||||||
## Version 2023/04/27 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authelia-location.conf.sample
|
## Version 2025/03/25 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authelia-location.conf.sample
|
||||||
# Make sure that your authelia container is in the same user defined bridge network and is named authelia
|
# Make sure that your authelia container is in the same user defined bridge network and is named authelia
|
||||||
# Rename /config/nginx/proxy-confs/authelia.subdomain.conf.sample to /config/nginx/proxy-confs/authelia.subdomain.conf
|
# Rename /config/nginx/proxy-confs/authelia.subdomain.conf.sample to /config/nginx/proxy-confs/authelia.subdomain.conf
|
||||||
# Make sure that the authelia configuration.yml has 'path: "authelia"' defined
|
|
||||||
|
|
||||||
## Send a subrequest to Authelia to verify if the user is authenticated and has permission to access the resource
|
## Send a subrequest to Authelia to verify if the user is authenticated and has permission to access the resource
|
||||||
auth_request /authelia/api/verify;
|
auth_request /authelia/api/authz/auth-request;
|
||||||
|
|
||||||
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
|
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
|
||||||
error_page 401 = @authelia_proxy_signin;
|
error_page 401 = @authelia_proxy_signin;
|
||||||
|
|
||||||
|
|||||||
@@ -1,25 +1,15 @@
|
|||||||
## Version 2023/04/27 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authelia-server.conf.sample
|
## Version 2025/03/25 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authelia-server.conf.sample
|
||||||
# Make sure that your authelia container is in the same user defined bridge network and is named authelia
|
# Make sure that your authelia container is in the same user defined bridge network and is named authelia
|
||||||
# Rename /config/nginx/proxy-confs/authelia.subdomain.conf.sample to /config/nginx/proxy-confs/authelia.subdomain.conf
|
# Rename /config/nginx/proxy-confs/authelia.subdomain.conf.sample to /config/nginx/proxy-confs/authelia.subdomain.conf
|
||||||
# Make sure that the authelia configuration.yml has 'path: "authelia"' defined
|
|
||||||
|
|
||||||
# location for authelia subfolder requests
|
|
||||||
location ^~ /authelia {
|
|
||||||
auth_request off; # requests to this subfolder must be accessible without authentication
|
|
||||||
include /config/nginx/proxy.conf;
|
|
||||||
include /config/nginx/resolver.conf;
|
|
||||||
set $upstream_authelia authelia;
|
|
||||||
proxy_pass http://$upstream_authelia:9091;
|
|
||||||
}
|
|
||||||
|
|
||||||
# location for authelia auth requests
|
# location for authelia auth requests
|
||||||
location = /authelia/api/verify {
|
location = /authelia/api/authz/auth-request {
|
||||||
internal;
|
internal;
|
||||||
|
|
||||||
include /config/nginx/proxy.conf;
|
include /config/nginx/proxy.conf;
|
||||||
include /config/nginx/resolver.conf;
|
include /config/nginx/resolver.conf;
|
||||||
set $upstream_authelia authelia;
|
set $upstream_authelia authelia;
|
||||||
proxy_pass http://$upstream_authelia:9091;
|
proxy_pass http://$upstream_authelia:9091/api/authz/auth-request;
|
||||||
|
|
||||||
## Include the Set-Cookie header if present
|
## Include the Set-Cookie header if present
|
||||||
auth_request_set $set_cookie $upstream_http_set_cookie;
|
auth_request_set $set_cookie $upstream_http_set_cookie;
|
||||||
@@ -43,11 +33,6 @@ location @authelia_proxy_signin {
|
|||||||
## Translate the Location response header from the auth subrequest into a variable
|
## Translate the Location response header from the auth subrequest into a variable
|
||||||
auth_request_set $signin_url $upstream_http_location;
|
auth_request_set $signin_url $upstream_http_location;
|
||||||
|
|
||||||
if ($signin_url = '') {
|
|
||||||
## Set the $signin_url variable
|
|
||||||
set $signin_url https://$http_host/authelia/?rd=$target_url;
|
|
||||||
}
|
|
||||||
|
|
||||||
## Redirect to login
|
## Redirect to login
|
||||||
return 302 $signin_url;
|
return 302 $signin_url;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -4,6 +4,7 @@
|
|||||||
|
|
||||||
## Send a subrequest to Authentik to verify if the user is authenticated and has permission to access the resource
|
## Send a subrequest to Authentik to verify if the user is authenticated and has permission to access the resource
|
||||||
auth_request /outpost.goauthentik.io/auth/nginx;
|
auth_request /outpost.goauthentik.io/auth/nginx;
|
||||||
|
|
||||||
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
|
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
|
||||||
error_page 401 = @goauthentik_proxy_signin;
|
error_page 401 = @goauthentik_proxy_signin;
|
||||||
|
|
||||||
|
|||||||
@@ -1,10 +1,11 @@
|
|||||||
## Version 2023/04/27 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authentik-server.conf.sample
|
## Version 2025/03/25 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/authentik-server.conf.sample
|
||||||
# Make sure that your authentik container is in the same user defined bridge network and is named authentik-server
|
# Make sure that your authentik container is in the same user defined bridge network and is named authentik-server
|
||||||
# Rename /config/nginx/proxy-confs/authentik.subdomain.conf.sample to /config/nginx/proxy-confs/authentik.subdomain.conf
|
# Rename /config/nginx/proxy-confs/authentik.subdomain.conf.sample to /config/nginx/proxy-confs/authentik.subdomain.conf
|
||||||
|
|
||||||
# location for authentik subfolder requests
|
# location for authentik subfolder requests
|
||||||
location ^~ /outpost.goauthentik.io {
|
location ^~ /outpost.goauthentik.io {
|
||||||
auth_request off; # requests to this subfolder must be accessible without authentication
|
auth_request off; # requests to this subfolder must be accessible without authentication
|
||||||
|
|
||||||
include /config/nginx/proxy.conf;
|
include /config/nginx/proxy.conf;
|
||||||
include /config/nginx/resolver.conf;
|
include /config/nginx/resolver.conf;
|
||||||
set $upstream_authentik authentik-server;
|
set $upstream_authentik authentik-server;
|
||||||
@@ -18,7 +19,7 @@ location = /outpost.goauthentik.io/auth/nginx {
|
|||||||
include /config/nginx/proxy.conf;
|
include /config/nginx/proxy.conf;
|
||||||
include /config/nginx/resolver.conf;
|
include /config/nginx/resolver.conf;
|
||||||
set $upstream_authentik authentik-server;
|
set $upstream_authentik authentik-server;
|
||||||
proxy_pass http://$upstream_authentik:9000;
|
proxy_pass http://$upstream_authentik:9000/outpost.goauthentik.io/auth/nginx;
|
||||||
|
|
||||||
## Include the Set-Cookie header if present
|
## Include the Set-Cookie header if present
|
||||||
auth_request_set $set_cookie $upstream_http_set_cookie;
|
auth_request_set $set_cookie $upstream_http_set_cookie;
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
## Version 2023/06/05 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample
|
## Version 2025/07/18 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/site-confs/default.conf.sample
|
||||||
|
|
||||||
# redirect all traffic to https
|
# redirect all traffic to https
|
||||||
server {
|
server {
|
||||||
@@ -12,8 +12,10 @@ server {
|
|||||||
|
|
||||||
# main server block
|
# main server block
|
||||||
server {
|
server {
|
||||||
listen 443 ssl http2 default_server;
|
listen 443 ssl default_server;
|
||||||
listen [::]:443 ssl http2 default_server;
|
# listen 443 quic reuseport default_server;
|
||||||
|
listen [::]:443 ssl default_server;
|
||||||
|
# listen [::]:443 quic reuseport default_server;
|
||||||
|
|
||||||
server_name _;
|
server_name _;
|
||||||
|
|
||||||
@@ -48,7 +50,7 @@ server {
|
|||||||
# enable for Authentik (requires authentik-server.conf in the server block)
|
# enable for Authentik (requires authentik-server.conf in the server block)
|
||||||
#include /config/nginx/authentik-location.conf;
|
#include /config/nginx/authentik-location.conf;
|
||||||
|
|
||||||
try_files $uri $uri/ /index.html /index.php$is_args$args =404;
|
try_files $uri $uri/ /index.html /index.htm /index.php$is_args$args;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~ ^(.+\.php)(.*)$ {
|
location ~ ^(.+\.php)(.*)$ {
|
||||||
@@ -66,6 +68,7 @@ server {
|
|||||||
#include /config/nginx/authentik-location.conf;
|
#include /config/nginx/authentik-location.conf;
|
||||||
|
|
||||||
fastcgi_split_path_info ^(.+\.php)(.*)$;
|
fastcgi_split_path_info ^(.+\.php)(.*)$;
|
||||||
|
if (!-f $document_root$fastcgi_script_name) { return 404; }
|
||||||
fastcgi_pass 127.0.0.1:9000;
|
fastcgi_pass 127.0.0.1:9000;
|
||||||
fastcgi_index index.php;
|
fastcgi_index index.php;
|
||||||
include /etc/nginx/fastcgi_params;
|
include /etc/nginx/fastcgi_params;
|
||||||
@@ -79,5 +82,3 @@ server {
|
|||||||
|
|
||||||
# enable subdomain method reverse proxy confs
|
# enable subdomain method reverse proxy confs
|
||||||
include /config/nginx/proxy-confs/*.subdomain.conf;
|
include /config/nginx/proxy-confs/*.subdomain.conf;
|
||||||
# enable proxy cache for auth
|
|
||||||
proxy_cache_path cache/ keys_zone=auth_cache:10m;
|
|
||||||
|
|||||||
9
root/defaults/nginx/tinyauth-location.conf.sample
Normal file
9
root/defaults/nginx/tinyauth-location.conf.sample
Normal file
@@ -0,0 +1,9 @@
|
|||||||
|
## Version 2025/06/08 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/tinyauth-location.conf.sample
|
||||||
|
# Make sure that your tinyauth container is in the same user defined bridge network and is named tinyauth
|
||||||
|
# Rename /config/nginx/proxy-confs/tinyauth.subdomain.conf.sample to /config/nginx/proxy-confs/tinyauth.subdomain.conf
|
||||||
|
|
||||||
|
## Send a subrequest to tinyauth to verify if the user is authenticated and has permission to access the resource
|
||||||
|
auth_request /tinyauth;
|
||||||
|
|
||||||
|
## If the subreqest returns 200 pass to the backend, if the subrequest returns 401 redirect to the portal
|
||||||
|
error_page 401 = @tinyauth_login;
|
||||||
35
root/defaults/nginx/tinyauth-server.conf.sample
Normal file
35
root/defaults/nginx/tinyauth-server.conf.sample
Normal file
@@ -0,0 +1,35 @@
|
|||||||
|
## Version 2025/06/08 - Changelog: https://github.com/linuxserver/docker-swag/commits/master/root/defaults/nginx/tinyauth-server.conf.sample
|
||||||
|
# Make sure that your tinyauth container is in the same user defined bridge network and is named tinyauth
|
||||||
|
# Rename /config/nginx/proxy-confs/tinyauth.subdomain.conf.sample to /config/nginx/proxy-confs/tinyauth.subdomain.conf
|
||||||
|
|
||||||
|
# location for tinyauth auth requests
|
||||||
|
location /tinyauth {
|
||||||
|
internal;
|
||||||
|
|
||||||
|
include /config/nginx/proxy.conf;
|
||||||
|
include /config/nginx/resolver.conf;
|
||||||
|
set $upstream_tinyauth tinyauth;
|
||||||
|
proxy_pass http://$upstream_tinyauth:3000/api/auth/nginx;
|
||||||
|
|
||||||
|
proxy_set_header x-forwarded-proto $scheme;
|
||||||
|
proxy_set_header x-forwarded-host $http_host;
|
||||||
|
proxy_set_header x-forwarded-uri $request_uri;
|
||||||
|
}
|
||||||
|
|
||||||
|
# virtual location for tinyauth 401 redirects
|
||||||
|
location @tinyauth_login {
|
||||||
|
internal;
|
||||||
|
|
||||||
|
## Set the $target_url variable based on the original request
|
||||||
|
set_escape_uri $target_url $scheme://$http_host$request_uri;
|
||||||
|
|
||||||
|
## Set the $signin_url variable
|
||||||
|
set $domain $host;
|
||||||
|
if ($host ~* "^[^.]+\.([^.]+\..+)$") {
|
||||||
|
set $domain $1;
|
||||||
|
}
|
||||||
|
set $signin_url https://tinyauth.$domain/login?redirect_uri=$target_url;
|
||||||
|
|
||||||
|
## Redirect to login
|
||||||
|
return 302 $signin_url;
|
||||||
|
}
|
||||||
@@ -1,9 +1,8 @@
|
|||||||
# do daily/weekly/monthly maintenance
|
|
||||||
# min hour day month weekday command
|
# min hour day month weekday command
|
||||||
*/15 * * * * run-parts /etc/periodic/15min
|
*/15 * * * * run-parts /etc/periodic/15min
|
||||||
0 * * * * run-parts /etc/periodic/hourly
|
0 * * * * run-parts /etc/periodic/hourly
|
||||||
0 2 * * * run-parts /etc/periodic/daily
|
0 2 * * * run-parts /etc/periodic/daily
|
||||||
0 3 * * 6 run-parts /etc/periodic/weekly
|
0 3 * * 6 run-parts /etc/periodic/weekly
|
||||||
0 5 1 * * run-parts /etc/periodic/monthly
|
0 5 1 * * run-parts /etc/periodic/monthly
|
||||||
# renew letsencrypt certs
|
|
||||||
8 2 * * * /app/le-renew.sh >> /config/log/letsencrypt/letsencrypt.log 2>&1
|
8 2 * * * /app/le-renew.sh >> /config/log/letsencrypt/renewal.log 2>&1
|
||||||
|
|||||||
@@ -23,9 +23,18 @@ for i in "${SANED_VARS[@]}"; do
|
|||||||
export echo "${i}"="$(echo "${!i}" | tr '[:upper:]' '[:lower:]')"
|
export echo "${i}"="$(echo "${!i}" | tr '[:upper:]' '[:lower:]')"
|
||||||
done
|
done
|
||||||
|
|
||||||
|
# Check for and install requested DNS plugins
|
||||||
|
if grep -q "universal-package-install" <<< "${DOCKER_MODS}" && grep -q "certbot-dns" <<< "${INSTALL_PIP_PACKAGES}"; then
|
||||||
|
echo "**** Installing requested dns plugins ****"
|
||||||
|
/etc/s6-overlay/s6-rc.d/init-mod-universal-package-install-add-package/run
|
||||||
|
/etc/s6-overlay/s6-rc.d/init-mods-package-install/run
|
||||||
|
fi
|
||||||
|
|
||||||
# check to make sure DNSPLUGIN is selected if dns validation is used
|
# check to make sure DNSPLUGIN is selected if dns validation is used
|
||||||
if [[ "${VALIDATION}" = "dns" ]] && [[ ! "${DNSPLUGIN}" =~ ^(acmedns|aliyun|azure|bunny|cloudflare|cpanel|desec|digitalocean|directadmin|dnsimple|dnsmadeeasy|dnspod|do|domeneshop|dreamhost|duckdns|dynu|gandi|gehirn|godaddy|google|google-domains|he|hetzner|infomaniak|inwx|ionos|linode|loopia|luadns|netcup|njalla|nsone|ovh|porkbun|rfc2136|route53|sakuracloud|standalone|transip|vultr)$ ]]; then
|
CERTBOT_DNS_AUTHENTICATORS=$(certbot plugins --authenticators 2>/dev/null | sed -e 's/^Entry point: EntryPoint(name='\''cpanel'\''/Entry point: EntryPoint(name='\''dns-cpanel'\''/' -e '/EntryPoint(name='\''dns-/!d' -e 's/^Entry point: EntryPoint(name='\''dns-\([^ ]*\)'\'',/\1/' | sort)
|
||||||
echo "Please set the DNSPLUGIN variable to a valid plugin name. See docker info for more details."
|
if [[ "${VALIDATION}" = "dns" ]] && ! echo "${CERTBOT_DNS_AUTHENTICATORS}" | grep -q "${DNSPLUGIN}"; then
|
||||||
|
echo "Please set the DNSPLUGIN variable to one of the following:"
|
||||||
|
echo "${CERTBOT_DNS_AUTHENTICATORS}"
|
||||||
sleep infinity
|
sleep infinity
|
||||||
fi
|
fi
|
||||||
|
|
||||||
@@ -44,14 +53,20 @@ function set_ini_value() {
|
|||||||
|
|
||||||
# ensure config files exist and has at least one value set (set_ini_value does not work on empty files)
|
# ensure config files exist and has at least one value set (set_ini_value does not work on empty files)
|
||||||
touch /config/etc/letsencrypt/cli.ini
|
touch /config/etc/letsencrypt/cli.ini
|
||||||
|
lsiown abc:abc /config/etc/letsencrypt/cli.ini
|
||||||
grep -qF 'agree-tos' /config/etc/letsencrypt/cli.ini || echo 'agree-tos=true' >>/config/etc/letsencrypt/cli.ini
|
grep -qF 'agree-tos' /config/etc/letsencrypt/cli.ini || echo 'agree-tos=true' >>/config/etc/letsencrypt/cli.ini
|
||||||
|
|
||||||
|
# Check for broken dns credentials value in cli.ini and remove
|
||||||
|
sed -i '/dns--credentials/d' /config/etc/letsencrypt/cli.ini
|
||||||
|
|
||||||
|
# Disable Certbot's built in log rotation
|
||||||
|
set_ini_value "max-log-backups" "0" /config/etc/letsencrypt/cli.ini
|
||||||
|
|
||||||
# copy dns default configs
|
# copy dns default configs
|
||||||
cp -n /defaults/dns-conf/* /config/dns-conf/ 2> >(grep -v 'cp: not replacing')
|
cp -n /defaults/dns-conf/* /config/dns-conf/ 2> >(grep -v 'cp: not replacing')
|
||||||
lsiown -R abc:abc /config/dns-conf
|
lsiown -R abc:abc /config/dns-conf
|
||||||
|
|
||||||
# copy default renewal hooks
|
# copy default renewal hooks
|
||||||
chmod -R +x /defaults/etc/letsencrypt/renewal-hooks
|
|
||||||
cp -nR /defaults/etc/letsencrypt/renewal-hooks/* /config/etc/letsencrypt/renewal-hooks/ 2> >(grep -v 'cp: not replacing')
|
cp -nR /defaults/etc/letsencrypt/renewal-hooks/* /config/etc/letsencrypt/renewal-hooks/ 2> >(grep -v 'cp: not replacing')
|
||||||
lsiown -R abc:abc /config/etc/letsencrypt/renewal-hooks
|
lsiown -R abc:abc /config/etc/letsencrypt/renewal-hooks
|
||||||
|
|
||||||
@@ -153,14 +168,14 @@ fi
|
|||||||
rm -rf /config/keys/letsencrypt
|
rm -rf /config/keys/letsencrypt
|
||||||
if [[ "${ONLY_SUBDOMAINS}" = "true" ]] && [[ ! "${SUBDOMAINS}" = "wildcard" ]]; then
|
if [[ "${ONLY_SUBDOMAINS}" = "true" ]] && [[ ! "${SUBDOMAINS}" = "wildcard" ]]; then
|
||||||
DOMAIN="$(echo "${SUBDOMAINS}" | tr ',' ' ' | awk '{print $1}').${URL}"
|
DOMAIN="$(echo "${SUBDOMAINS}" | tr ',' ' ' | awk '{print $1}').${URL}"
|
||||||
ln -s ../etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt
|
ln -s /config/etc/letsencrypt/live/"${DOMAIN}" /config/keys/letsencrypt
|
||||||
else
|
else
|
||||||
ln -s ../etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt
|
ln -s /config/etc/letsencrypt/live/"${URL}" /config/keys/letsencrypt
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# cleanup unused csr and keys folders
|
# cleanup unused csr and keys folders
|
||||||
rm -rf /etc/letsencrypt/csr
|
rm -rf /config/etc/letsencrypt/csr
|
||||||
rm -rf /etc/letsencrypt/keys
|
rm -rf /config/etc/letsencrypt/keys
|
||||||
|
|
||||||
# checking for changes in cert variables, revoking certs if necessary
|
# checking for changes in cert variables, revoking certs if necessary
|
||||||
if [[ ! "${URL}" = "${ORIGURL}" ]] ||
|
if [[ ! "${URL}" = "${ORIGURL}" ]] ||
|
||||||
@@ -173,26 +188,17 @@ if [[ ! "${URL}" = "${ORIGURL}" ]] ||
|
|||||||
[[ ! "${STAGING}" = "${ORIGSTAGING}" ]] ||
|
[[ ! "${STAGING}" = "${ORIGSTAGING}" ]] ||
|
||||||
[[ ! "${CERTPROVIDER}" = "${ORIGCERTPROVIDER}" ]]; then
|
[[ ! "${CERTPROVIDER}" = "${ORIGCERTPROVIDER}" ]]; then
|
||||||
echo "Different validation parameters entered than what was used before. Revoking and deleting existing certificate, and an updated one will be created"
|
echo "Different validation parameters entered than what was used before. Revoking and deleting existing certificate, and an updated one will be created"
|
||||||
if [[ "${ORIGCERTPROVIDER}" = "zerossl" ]] && [[ -n "${ORIGEMAIL}" ]]; then
|
if [[ "${ORIGCERTPROVIDER}" = "zerossl" ]]; then
|
||||||
REV_ACMESERVER=("https://acme.zerossl.com/v2/DV90")
|
REV_ACMESERVER=("https://acme.zerossl.com/v2/DV90")
|
||||||
REV_ZEROSSL_EAB_KID=$(awk -F "=" '/eab-kid/ {print $2}' "/config/etc/letsencrypt/renewal/${ORIGDOMAIN}.conf" | tr -d ' ')
|
|
||||||
REV_ZEROSSL_EAB_HMAC_KEY=$(awk -F "=" '/eab-hmac-key/ {print $2}' "/config/etc/letsencrypt/renewal/${ORIGDOMAIN}.conf" | tr -d ' ')
|
|
||||||
if [[ -z "${REV_ZEROSSL_EAB_KID}" ]] || [[ -z "${REV_ZEROSSL_EAB_HMAC_KEY}" ]]; then
|
|
||||||
REV_ZEROSSL_EAB_KID=$(awk -F "=" '/eab-kid/ {print $2}' /config/etc/letsencrypt/cli.ini | tr -d ' ')
|
|
||||||
REV_ZEROSSL_EAB_HMAC_KEY=$(awk -F "=" '/eab-hmac-key/ {print $2}' /config/etc/letsencrypt/cli.ini | tr -d ' ')
|
|
||||||
fi
|
|
||||||
if [[ -n "${REV_ZEROSSL_EAB_KID}" ]] && [[ -n "${REV_ZEROSSL_EAB_HMAC_KEY}" ]]; then
|
|
||||||
REV_ACMESERVER+=("--eab-kid" "${REV_ZEROSSL_EAB_KID}" "--eab-hmac-key" "${REV_ZEROSSL_EAB_HMAC_KEY}")
|
|
||||||
fi
|
|
||||||
elif [[ "${ORIGSTAGING}" = "true" ]]; then
|
elif [[ "${ORIGSTAGING}" = "true" ]]; then
|
||||||
REV_ACMESERVER=("https://acme-staging-v02.api.letsencrypt.org/directory")
|
REV_ACMESERVER=("https://acme-staging-v02.api.letsencrypt.org/directory")
|
||||||
else
|
else
|
||||||
REV_ACMESERVER=("https://acme-v02.api.letsencrypt.org/directory")
|
REV_ACMESERVER=("https://acme-v02.api.letsencrypt.org/directory")
|
||||||
fi
|
fi
|
||||||
if [[ -f /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem ]]; then
|
if [[ -f /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem ]]; then
|
||||||
certbot revoke --non-interactive --cert-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem --server "${REV_ACMESERVER[@]}" || true
|
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem --key-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/privkey.pem --server "${REV_ACMESERVER[@]}" || true
|
||||||
else
|
else
|
||||||
certbot revoke --non-interactive --cert-name "${ORIGDOMAIN}" --server "${REV_ACMESERVER[@]}" || true
|
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-name "${ORIGDOMAIN}" --server "${REV_ACMESERVER[@]}" || true
|
||||||
fi
|
fi
|
||||||
rm -rf /config/etc/letsencrypt/{accounts,archive,live,renewal}
|
rm -rf /config/etc/letsencrypt/{accounts,archive,live,renewal}
|
||||||
fi
|
fi
|
||||||
@@ -205,9 +211,9 @@ if [[ -f "/config/keys/letsencrypt/chain.pem" ]] && { [[ "${CERTPROVIDER}" == "l
|
|||||||
echo "The cert seems to be using the old LE root cert, which is no longer valid. Deleting and revoking."
|
echo "The cert seems to be using the old LE root cert, which is no longer valid. Deleting and revoking."
|
||||||
REV_ACMESERVER=("https://acme-v02.api.letsencrypt.org/directory")
|
REV_ACMESERVER=("https://acme-v02.api.letsencrypt.org/directory")
|
||||||
if [[ -f /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem ]]; then
|
if [[ -f /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem ]]; then
|
||||||
certbot revoke --non-interactive --cert-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem --server "${REV_ACMESERVER[@]}" || true
|
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-path /config/etc/letsencrypt/live/"${ORIGDOMAIN}"/fullchain.pem --server "${REV_ACMESERVER[@]}" || true
|
||||||
else
|
else
|
||||||
certbot revoke --non-interactive --cert-name "${ORIGDOMAIN}" --server "${REV_ACMESERVER[@]}" || true
|
certbot revoke --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --cert-name "${ORIGDOMAIN}" --server "${REV_ACMESERVER[@]}" || true
|
||||||
fi
|
fi
|
||||||
rm -rf /config/etc/letsencrypt/{accounts,archive,live,renewal}
|
rm -rf /config/etc/letsencrypt/{accounts,archive,live,renewal}
|
||||||
fi
|
fi
|
||||||
@@ -297,12 +303,12 @@ if [[ "${VALIDATION}" = "dns" ]]; then
|
|||||||
sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini
|
sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini
|
||||||
fi
|
fi
|
||||||
# plugins that don't support setting propagation
|
# plugins that don't support setting propagation
|
||||||
if [[ "${DNSPLUGIN}" =~ ^(azure|gandi|route53|standalone)$ ]]; then
|
if [[ "${DNSPLUGIN}" =~ ^(gandi|route53|standalone)$ ]]; then
|
||||||
if [[ -n "${PROPAGATION}" ]]; then echo "${DNSPLUGIN} dns plugin does not support setting propagation time"; fi
|
if [[ -n "${PROPAGATION}" ]]; then echo "${DNSPLUGIN} dns plugin does not support setting propagation time"; fi
|
||||||
sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini
|
sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini
|
||||||
fi
|
fi
|
||||||
# plugins that use old parameter naming convention
|
# plugins that use old parameter naming convention
|
||||||
if [[ "${DNSPLUGIN}" =~ ^(cpanel|directadmin)$ ]]; then
|
if [[ "${DNSPLUGIN}" =~ ^(cpanel)$ ]]; then
|
||||||
sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini
|
sed -i "/^dns-${DNSPLUGIN}-credentials\b/d" /config/etc/letsencrypt/cli.ini
|
||||||
sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini
|
sed -i "/^dns-${DNSPLUGIN}-propagation-seconds\b/d" /config/etc/letsencrypt/cli.ini
|
||||||
set_ini_value "authenticator" "${DNSPLUGIN}" /config/etc/letsencrypt/cli.ini
|
set_ini_value "authenticator" "${DNSPLUGIN}" /config/etc/letsencrypt/cli.ini
|
||||||
@@ -340,7 +346,7 @@ if [[ ! -f "/config/keys/letsencrypt/fullchain.pem" ]]; then
|
|||||||
set_ini_value "eab-hmac-key" "${ZEROSSL_EAB_HMAC_KEY}" /config/etc/letsencrypt/cli.ini
|
set_ini_value "eab-hmac-key" "${ZEROSSL_EAB_HMAC_KEY}" /config/etc/letsencrypt/cli.ini
|
||||||
fi
|
fi
|
||||||
echo "Generating new certificate"
|
echo "Generating new certificate"
|
||||||
certbot certonly --non-interactive --renew-by-default
|
certbot certonly --config-dir /config/etc/letsencrypt --logs-dir /config/log/letsencrypt --work-dir /tmp/letsencrypt --config /config/etc/letsencrypt/cli.ini --non-interactive --renew-by-default
|
||||||
if [[ ! -d /config/keys/letsencrypt ]]; then
|
if [[ ! -d /config/keys/letsencrypt ]]; then
|
||||||
if [[ "${VALIDATION}" = "dns" ]]; then
|
if [[ "${VALIDATION}" = "dns" ]]; then
|
||||||
echo "ERROR: Cert does not exist! Please see the validation error above. Make sure you entered correct credentials into the ${DNSCREDENTIALFILE} file."
|
echo "ERROR: Cert does not exist! Please see the validation error above. Make sure you entered correct credentials into the ${DNSCREDENTIALFILE} file."
|
||||||
|
|||||||
@@ -1,38 +0,0 @@
|
|||||||
#!/usr/bin/with-contenv bash
|
|
||||||
# shellcheck shell=bash
|
|
||||||
|
|
||||||
# make folders
|
|
||||||
mkdir -p \
|
|
||||||
/config/crontabs
|
|
||||||
|
|
||||||
## root
|
|
||||||
# if crontabs do not exist in config
|
|
||||||
if [[ ! -f /config/crontabs/root ]]; then
|
|
||||||
# copy crontab from system
|
|
||||||
if crontab -l -u root; then
|
|
||||||
crontab -l -u root >/config/crontabs/root
|
|
||||||
fi
|
|
||||||
|
|
||||||
# if crontabs still do not exist in config (were not copied from system)
|
|
||||||
# copy crontab from included defaults (using -n, do not overwrite an existing file)
|
|
||||||
cp -n /etc/crontabs/root /config/crontabs/ 2> >(grep -v 'cp: not replacing')
|
|
||||||
fi
|
|
||||||
# set permissions and import user crontabs
|
|
||||||
lsiown root:root /config/crontabs/root
|
|
||||||
crontab -u root /config/crontabs/root
|
|
||||||
|
|
||||||
## abc
|
|
||||||
# if crontabs do not exist in config
|
|
||||||
if [[ ! -f /config/crontabs/abc ]]; then
|
|
||||||
# copy crontab from system
|
|
||||||
if crontab -l -u abc; then
|
|
||||||
crontab -l -u abc >/config/crontabs/abc
|
|
||||||
fi
|
|
||||||
|
|
||||||
# if crontabs still do not exist in config (were not copied from system)
|
|
||||||
# copy crontab from included defaults (using -n, do not overwrite an existing file)
|
|
||||||
cp -n /etc/crontabs/abc /config/crontabs/ 2> >(grep -v 'cp: not replacing')
|
|
||||||
fi
|
|
||||||
# set permissions and import user crontabs
|
|
||||||
lsiown abc:abc /config/crontabs/abc
|
|
||||||
crontab -u abc /config/crontabs/abc
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
/etc/s6-overlay/s6-rc.d/init-crontabs-config/run
|
|
||||||
@@ -1,29 +1,40 @@
|
|||||||
#!/usr/bin/with-contenv bash
|
#!/usr/bin/with-contenv bash
|
||||||
# shellcheck shell=bash
|
# shellcheck shell=bash
|
||||||
|
|
||||||
# copy/update the fail2ban config defaults to/in /config
|
if [[ -z ${LSIO_READ_ONLY_FS} ]] && [[ -z ${LSIO_NON_ROOT_USER} ]] && [[ "${DISABLE_F2B,,}" != "true" ]]; then
|
||||||
cp -R /defaults/fail2ban/filter.d /config/fail2ban/
|
if ! iptables -L &> /dev/null; then
|
||||||
cp -R /defaults/fail2ban/action.d /config/fail2ban/
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/iptables
|
||||||
# if jail.local is missing in /config, copy default
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/iptables-save
|
||||||
if [[ ! -f /config/fail2ban/jail.local ]]; then
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/iptables-restore
|
||||||
cp /defaults/fail2ban/jail.local /config/fail2ban/jail.local
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/ip6tables
|
||||||
fi
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/ip6tables-save
|
||||||
# Replace fail2ban config with user config
|
ln -sf /usr/sbin/xtables-legacy-multi /usr/sbin/ip6tables-restore
|
||||||
if [[ -d /etc/fail2ban/filter.d ]]; then
|
fi
|
||||||
rm -rf /etc/fail2ban/filter.d
|
|
||||||
fi
|
|
||||||
if [[ -d /etc/fail2ban/action.d ]]; then
|
|
||||||
rm -rf /etc/fail2ban/action.d
|
|
||||||
fi
|
|
||||||
cp -R /config/fail2ban/filter.d /etc/fail2ban/
|
|
||||||
cp -R /config/fail2ban/action.d /etc/fail2ban/
|
|
||||||
cp /defaults/fail2ban/fail2ban.local /etc/fail2ban/
|
|
||||||
cp /config/fail2ban/jail.local /etc/fail2ban/jail.local
|
|
||||||
|
|
||||||
# logfiles needed by fail2ban
|
# copy/update the fail2ban config defaults to/in /config
|
||||||
if [[ ! -f /config/log/nginx/error.log ]]; then
|
cp -R /defaults/fail2ban/filter.d /config/fail2ban/
|
||||||
touch /config/log/nginx/error.log
|
cp -R /defaults/fail2ban/action.d /config/fail2ban/
|
||||||
fi
|
# if jail.local is missing in /config, copy default
|
||||||
if [[ ! -f /config/log/nginx/access.log ]]; then
|
if [[ ! -f /config/fail2ban/jail.local ]]; then
|
||||||
touch /config/log/nginx/access.log
|
cp /defaults/fail2ban/jail.local /config/fail2ban/jail.local
|
||||||
|
fi
|
||||||
|
# Replace fail2ban config with user config
|
||||||
|
if [[ -d /etc/fail2ban/filter.d ]]; then
|
||||||
|
rm -rf /etc/fail2ban/filter.d
|
||||||
|
fi
|
||||||
|
if [[ -d /etc/fail2ban/action.d ]]; then
|
||||||
|
rm -rf /etc/fail2ban/action.d
|
||||||
|
fi
|
||||||
|
cp -R /config/fail2ban/filter.d /etc/fail2ban/
|
||||||
|
cp -R /config/fail2ban/action.d /etc/fail2ban/
|
||||||
|
cp /defaults/fail2ban/fail2ban.local /etc/fail2ban/
|
||||||
|
cp /config/fail2ban/jail.local /etc/fail2ban/jail.local
|
||||||
|
|
||||||
|
# logfiles needed by fail2ban
|
||||||
|
if [[ ! -f /config/log/nginx/error.log ]]; then
|
||||||
|
touch /config/log/nginx/error.log
|
||||||
|
fi
|
||||||
|
if [[ ! -f /config/log/nginx/access.log ]]; then
|
||||||
|
touch /config/log/nginx/access.log
|
||||||
|
fi
|
||||||
fi
|
fi
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
/etc/s6-overlay/s6-rc.d/init-folders-config/run
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
/etc/s6-overlay/s6-rc.d/init-nginx-config/run
|
|
||||||
@@ -11,3 +11,9 @@ if [[ -f /config/nginx/ldap.conf ]]; then
|
|||||||
Ensure your configs are updated and remove /config/nginx/ldap.conf
|
Ensure your configs are updated and remove /config/nginx/ldap.conf
|
||||||
If you do not use this config, simply remove it."
|
If you do not use this config, simply remove it."
|
||||||
fi
|
fi
|
||||||
|
if grep -qrle ' /etc/letsencrypt' /config/nginx; then
|
||||||
|
echo " The following nginx confs are using certificates from the obsolete location
|
||||||
|
/etc/letsencrypt and should be updated to point to /config/etc/letsencrypt
|
||||||
|
"
|
||||||
|
echo -n " " && grep -rle ' /etc/letsencrypt' /config/nginx
|
||||||
|
fi
|
||||||
|
|||||||
@@ -2,8 +2,7 @@
|
|||||||
# shellcheck shell=bash
|
# shellcheck shell=bash
|
||||||
|
|
||||||
# permissions
|
# permissions
|
||||||
|
find /config/log ! -path '/config/log/logrotate.status' -exec chmod +r {} \+
|
||||||
|
|
||||||
lsiown -R abc:abc \
|
lsiown -R abc:abc \
|
||||||
/config
|
/config
|
||||||
chmod -R 0644 /etc/logrotate.d
|
|
||||||
chmod -R +r /config/log
|
|
||||||
chmod +x /app/le-renew.sh
|
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
oneshot
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
/etc/s6-overlay/s6-rc.d/init-samples-config/run
|
|
||||||
@@ -22,6 +22,14 @@ if [[ ! -f /config/nginx/authentik-server.conf ]]; then
|
|||||||
cp /defaults/nginx/authentik-server.conf.sample /config/nginx/authentik-server.conf
|
cp /defaults/nginx/authentik-server.conf.sample /config/nginx/authentik-server.conf
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# copy tinyauth config files if they don't exist
|
||||||
|
if [[ ! -f /config/nginx/tinyauth-location.conf ]]; then
|
||||||
|
cp /defaults/nginx/tinyauth-location.conf.sample /config/nginx/tinyauth-location.conf
|
||||||
|
fi
|
||||||
|
if [[ ! -f /config/nginx/tinyauth-server.conf ]]; then
|
||||||
|
cp /defaults/nginx/tinyauth-server.conf.sample /config/nginx/tinyauth-server.conf
|
||||||
|
fi
|
||||||
|
|
||||||
# copy old ldap config file to new location
|
# copy old ldap config file to new location
|
||||||
if [[ -f /config/nginx/ldap.conf ]] && [[ ! -f /config/nginx/ldap-server.conf ]]; then
|
if [[ -f /config/nginx/ldap.conf ]] && [[ ! -f /config/nginx/ldap-server.conf ]]; then
|
||||||
cp /config/nginx/ldap.conf /config/nginx/ldap-server.conf
|
cp /config/nginx/ldap.conf /config/nginx/ldap-server.conf
|
||||||
1
root/etc/s6-overlay/s6-rc.d/init-swag-config/up
Normal file
1
root/etc/s6-overlay/s6-rc.d/init-swag-config/up
Normal file
@@ -0,0 +1 @@
|
|||||||
|
/etc/s6-overlay/s6-rc.d/init-swag-config/run
|
||||||
@@ -3,10 +3,10 @@
|
|||||||
|
|
||||||
# make our folders and links
|
# make our folders and links
|
||||||
mkdir -p \
|
mkdir -p \
|
||||||
/config/{fail2ban,crontabs,dns-conf} \
|
/config/{fail2ban,dns-conf} \
|
||||||
/config/etc/letsencrypt/renewal-hooks \
|
/config/etc/letsencrypt/renewal-hooks \
|
||||||
/config/log/{fail2ban,letsencrypt,nginx} \
|
/config/log/{fail2ban,letsencrypt,nginx} \
|
||||||
/config/nginx/proxy-confs \
|
/config/nginx/proxy-confs \
|
||||||
/run/fail2ban
|
/run/fail2ban \
|
||||||
rm -rf /etc/letsencrypt
|
/tmp/letsencrypt
|
||||||
ln -s /config/etc/letsencrypt /etc/letsencrypt
|
|
||||||
1
root/etc/s6-overlay/s6-rc.d/init-swag-folders/up
Normal file
1
root/etc/s6-overlay/s6-rc.d/init-swag-folders/up
Normal file
@@ -0,0 +1 @@
|
|||||||
|
/etc/s6-overlay/s6-rc.d/init-swag-folders/run
|
||||||
@@ -9,5 +9,5 @@ if [[ -d /defaults/nginx/proxy-confs/ ]]; then
|
|||||||
-maxdepth 1 \
|
-maxdepth 1 \
|
||||||
-name "*.conf.sample" \
|
-name "*.conf.sample" \
|
||||||
-type f \
|
-type f \
|
||||||
-exec cp "{}" /config/nginx/proxy-confs/ +
|
-exec cp "{}" /config/nginx/proxy-confs/ \;
|
||||||
fi
|
fi
|
||||||
1
root/etc/s6-overlay/s6-rc.d/init-swag-samples/up
Normal file
1
root/etc/s6-overlay/s6-rc.d/init-swag-samples/up
Normal file
@@ -0,0 +1 @@
|
|||||||
|
/etc/s6-overlay/s6-rc.d/init-swag-samples/run
|
||||||
@@ -1,7 +0,0 @@
|
|||||||
#!/usr/bin/with-contenv bash
|
|
||||||
# shellcheck shell=bash
|
|
||||||
|
|
||||||
# Echo init finish for test runs
|
|
||||||
if [[ -n "${TEST_RUN}" ]]; then
|
|
||||||
echo '[services.d] done.'
|
|
||||||
fi
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
oneshot
|
|
||||||
@@ -1 +0,0 @@
|
|||||||
/etc/s6-overlay/s6-rc.d/init-test-run/run
|
|
||||||
@@ -1,5 +1,9 @@
|
|||||||
#!/usr/bin/with-contenv bash
|
#!/usr/bin/with-contenv bash
|
||||||
# shellcheck shell=bash
|
# shellcheck shell=bash
|
||||||
|
|
||||||
exec \
|
if [[ -z ${LSIO_READ_ONLY_FS} ]] && [[ -z ${LSIO_NON_ROOT_USER} ]] && [[ "${DISABLE_F2B,,}" != "true" ]]; then
|
||||||
fail2ban-client -x -f start
|
exec \
|
||||||
|
fail2ban-client -x -f start
|
||||||
|
else
|
||||||
|
sleep infinity
|
||||||
|
fi
|
||||||
|
|||||||
41
root/etc/s6-overlay/s6-rc.d/svc-swag-auto-reload/run
Executable file
41
root/etc/s6-overlay/s6-rc.d/svc-swag-auto-reload/run
Executable file
@@ -0,0 +1,41 @@
|
|||||||
|
#!/usr/bin/with-contenv bash
|
||||||
|
# shellcheck shell=bash
|
||||||
|
|
||||||
|
if [[ ${SWAG_AUTORELOAD,,} == "true" ]]; then
|
||||||
|
if [[ -f "/etc/s6-overlay/s6-rc.d/svc-mod-swag-auto-reload/run" ]]; then
|
||||||
|
echo "ERROR: Legacy SWAG Auto Reload Mod detected, to use the built-in Auto Reload functionality please remove it from your container config."
|
||||||
|
sleep infinity
|
||||||
|
else
|
||||||
|
echo "Auto-reload: Watching the following folders for changes to .conf files:"
|
||||||
|
echo "/config/nginx"
|
||||||
|
ACTIVE_WATCH=("/config/nginx")
|
||||||
|
for i in $(echo "${SWAG_AUTORELOAD_WATCHLIST}" | tr "|" " "); do
|
||||||
|
if [ -f "${i}" ] || [ -d "${i}" ]; then
|
||||||
|
echo "${i}"
|
||||||
|
ACTIVE_WATCH+=("${i}")
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
function wait_for_changes {
|
||||||
|
inotifywait -rq \
|
||||||
|
--event modify,move,create,delete \
|
||||||
|
--includei '\.conf$' \
|
||||||
|
"${ACTIVE_WATCH[@]}"
|
||||||
|
}
|
||||||
|
|
||||||
|
while wait_for_changes; do
|
||||||
|
NGINX_CONF=()
|
||||||
|
if ! grep -q "/config/nginx/nginx.conf" /etc/nginx/nginx.conf; then
|
||||||
|
NGINX_CONF=("-c" "/config/nginx/nginx.conf")
|
||||||
|
fi
|
||||||
|
if /usr/sbin/nginx "${NGINX_CONF[@]}" -t; then
|
||||||
|
echo "Changes to nginx config detected and the changes are valid, reloading nginx"
|
||||||
|
/usr/sbin/nginx "${NGINX_CONF[@]}" -s reload
|
||||||
|
else
|
||||||
|
echo "Changes to nginx config detected but the changes are not valid, skipping nginx reload. Please fix your config."
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
sleep infinity
|
||||||
|
fi
|
||||||
1
root/etc/s6-overlay/s6-rc.d/svc-swag-auto-reload/type
Normal file
1
root/etc/s6-overlay/s6-rc.d/svc-swag-auto-reload/type
Normal file
@@ -0,0 +1 @@
|
|||||||
|
longrun
|
||||||
7
root/migrations/02-swag-old-certbot-paths
Executable file
7
root/migrations/02-swag-old-certbot-paths
Executable file
@@ -0,0 +1,7 @@
|
|||||||
|
#!/usr/bin/with-contenv bash
|
||||||
|
# shellcheck shell=bash
|
||||||
|
|
||||||
|
# Migrate existing renewal confs with old paths from /etc/letsencrypt to /config/etc/letsencrypt
|
||||||
|
if ls /config/etc/letsencrypt/renewal/*.conf >/dev/null 2>&1; then
|
||||||
|
sed -i 's| /etc/letsencrypt| /config/etc/letsencrypt|' /config/etc/letsencrypt/renewal/*.conf
|
||||||
|
fi
|
||||||
Reference in New Issue
Block a user