fix: Add Docker entrypoint script with gosu to manage volume permissions and drop user privileges.

This commit is contained in:
Michael committed 2026-01-07 11:09:42 +01:00
1 parent a149bf266c
commit 5d4dfa5e05
3 files changed
+39 -28

No files matched your search

+9 -6
View File
@@ -65,7 +65,7 @@ RUN dart compile exe server.dart -o server
# ============================================
FROM debian:stable-slim
# Install runtime dependencies and tools for fetching FFmpeg
# Install runtime dependencies, tools for fetching FFmpeg, and gosu for privilege dropping
RUN apt-get update && apt-get install -y --no-install-recommends \
ca-certificates \
sqlite3 \
@@ -73,6 +73,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
wget \
xz-utils \
gosu \
&& rm -rf /var/lib/apt/lists/*
# Install FFmpeg with NVIDIA NVENC support from BtbN static builds
@@ -97,11 +98,12 @@ RUN mkdir -p /app/data /app/web /tmp/xtremflow_streams \
COPY --from=web-builder /app/build/web /app/web
COPY --from=server-builder /app/bin/server /app/server
# Set permission for the executable
RUN chmod +x /app/server
# Copy entrypoint script and set permissions
COPY entrypoint.sh /app/entrypoint.sh
RUN chmod +x /app/server /app/entrypoint.sh
# Switch to non-root user
USER xtremuser
# NOTE: We stay as root to allow entrypoint.sh to fix volume permissions
# The entrypoint script will drop privileges to xtremuser after fixing permissions
# Expose port
EXPOSE 8089
@@ -110,5 +112,6 @@ EXPOSE 8089
HEALTHCHECK --interval=30s --timeout=3s \
CMD curl -f http://localhost:8089/index.html || exit 1
# Start server
# Use entrypoint to fix permissions then start server as xtremuser
ENTRYPOINT ["/app/entrypoint.sh"]
CMD ["/app/server", "--port", "8089", "--path", "/app/web"]
+17
View File
@@ -0,0 +1,17 @@
#!/bin/bash
# Entrypoint script for XtremFlow
# Fixes permissions on mounted volumes before starting the server
set -e
# Fix ownership of data directory (runs as root initially)
echo "Fixing permissions on /app/data..."
chown -R xtremuser:xtremuser /app/data 2>/dev/null || true
# Create subdirectories if they don't exist
mkdir -p /app/data/logs /app/data/tmp
chown -R xtremuser:xtremuser /app/data/logs /app/data/tmp 2>/dev/null || true
# Drop privileges and run the server as xtremuser
echo "Starting server as xtremuser..."
exec gosu xtremuser "$@"
+13 -22
View File
@@ -1,32 +1,23 @@
# Analyse et Optimisation de XtremFlow
# Fix Docker Database Permissions
## Contexte
## Context
Audit complet de l'application XtremFlow demandé par l'utilisateur pour identifier des améliorations en termes d'efficience, de rapidité et de sécurité.
SQLite database in Docker container is read-only due to volume permissions mismatch between root and xtremuser.
## Focus Actuel
## Current Focus
Analyse statique du code et de l'infrastructure.
Implementation complete - ready for rebuild and deploy.
## Master Plan
- [x] Analyser l'architecture Backend (Dart/Server) pour la sécurité et la perf.
- [x] Analyser le Frontend (Flutter) pour l'efficience et le rendu.
- [x] Analyser la configuration Docker pour la sécurité et la taille de l'image.
- [x] Rédiger un rapport d'audit avec des propositions concrètes.
- [ ] (Optionnel) Implémenter les correctifs critiques si demandé.
### Implémentation - Sécurisation & Optimisation
- [x] **Backend / Serveur**
- [x] Extraire la logique de proxy dans `bin/api/proxy_handler.dart`.
- [x] Sécuriser la route `/api/xtream` avec `authMiddleware`.
- [x] Intégrer la validation de domaine et le streaming.
- [x] **Streaming**
- [x] Sanitizer `streamId`.
- [x] **Docker**
- [x] Optimiser Dockerfile (Native + User non-root).
- [x] Analyze the error and identify root cause
- [x] Create entrypoint.sh script to fix permissions at startup
- [x] Update Dockerfile to use entrypoint script with gosu
- [ ] Rebuild and deploy to test
## Progress Log
- Démarrage de la mission d'analyse.
- Identified `SqliteException(8): attempt to write a readonly database` error
- Root cause: Docker volume created with different permissions than xtremuser
- Created `entrypoint.sh` with chown fix and gosu privilege drop
- Updated Dockerfile: added gosu, ENTRYPOINT, removed USER directive