mirror of
https://github.com/R0m1k3/xtremflow.git
synced 2026-10-11 17:30:00 +02:00
fix: Add Docker entrypoint script with gosu to manage volume permissions and drop user privileges.
This commit is contained in:
1 parent
a149bf266c
commit
5d4dfa5e05
3 files changed
+39
-28
No files matched your search
+9
-6
@@ -65,7 +65,7 @@ RUN dart compile exe server.dart -o server
|
||||
# ============================================
|
||||
FROM debian:stable-slim
|
||||
|
||||
# Install runtime dependencies and tools for fetching FFmpeg
|
||||
# Install runtime dependencies, tools for fetching FFmpeg, and gosu for privilege dropping
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
ca-certificates \
|
||||
sqlite3 \
|
||||
@@ -73,6 +73,7 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
curl \
|
||||
wget \
|
||||
xz-utils \
|
||||
gosu \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Install FFmpeg with NVIDIA NVENC support from BtbN static builds
|
||||
@@ -97,11 +98,12 @@ RUN mkdir -p /app/data /app/web /tmp/xtremflow_streams \
|
||||
COPY --from=web-builder /app/build/web /app/web
|
||||
COPY --from=server-builder /app/bin/server /app/server
|
||||
|
||||
# Set permission for the executable
|
||||
RUN chmod +x /app/server
|
||||
# Copy entrypoint script and set permissions
|
||||
COPY entrypoint.sh /app/entrypoint.sh
|
||||
RUN chmod +x /app/server /app/entrypoint.sh
|
||||
|
||||
# Switch to non-root user
|
||||
USER xtremuser
|
||||
# NOTE: We stay as root to allow entrypoint.sh to fix volume permissions
|
||||
# The entrypoint script will drop privileges to xtremuser after fixing permissions
|
||||
|
||||
# Expose port
|
||||
EXPOSE 8089
|
||||
@@ -110,5 +112,6 @@ EXPOSE 8089
|
||||
HEALTHCHECK --interval=30s --timeout=3s \
|
||||
CMD curl -f http://localhost:8089/index.html || exit 1
|
||||
|
||||
# Start server
|
||||
# Use entrypoint to fix permissions then start server as xtremuser
|
||||
ENTRYPOINT ["/app/entrypoint.sh"]
|
||||
CMD ["/app/server", "--port", "8089", "--path", "/app/web"]
|
||||
@@ -0,0 +1,17 @@
|
||||
#!/bin/bash
|
||||
# Entrypoint script for XtremFlow
|
||||
# Fixes permissions on mounted volumes before starting the server
|
||||
|
||||
set -e
|
||||
|
||||
# Fix ownership of data directory (runs as root initially)
|
||||
echo "Fixing permissions on /app/data..."
|
||||
chown -R xtremuser:xtremuser /app/data 2>/dev/null || true
|
||||
|
||||
# Create subdirectories if they don't exist
|
||||
mkdir -p /app/data/logs /app/data/tmp
|
||||
chown -R xtremuser:xtremuser /app/data/logs /app/data/tmp 2>/dev/null || true
|
||||
|
||||
# Drop privileges and run the server as xtremuser
|
||||
echo "Starting server as xtremuser..."
|
||||
exec gosu xtremuser "$@"
|
||||
@@ -1,32 +1,23 @@
|
||||
# Analyse et Optimisation de XtremFlow
|
||||
# Fix Docker Database Permissions
|
||||
|
||||
## Contexte
|
||||
## Context
|
||||
|
||||
Audit complet de l'application XtremFlow demandé par l'utilisateur pour identifier des améliorations en termes d'efficience, de rapidité et de sécurité.
|
||||
SQLite database in Docker container is read-only due to volume permissions mismatch between root and xtremuser.
|
||||
|
||||
## Focus Actuel
|
||||
## Current Focus
|
||||
|
||||
Analyse statique du code et de l'infrastructure.
|
||||
Implementation complete - ready for rebuild and deploy.
|
||||
|
||||
## Master Plan
|
||||
|
||||
- [x] Analyser l'architecture Backend (Dart/Server) pour la sécurité et la perf.
|
||||
- [x] Analyser le Frontend (Flutter) pour l'efficience et le rendu.
|
||||
- [x] Analyser la configuration Docker pour la sécurité et la taille de l'image.
|
||||
- [x] Rédiger un rapport d'audit avec des propositions concrètes.
|
||||
- [ ] (Optionnel) Implémenter les correctifs critiques si demandé.
|
||||
|
||||
### Implémentation - Sécurisation & Optimisation
|
||||
|
||||
- [x] **Backend / Serveur**
|
||||
- [x] Extraire la logique de proxy dans `bin/api/proxy_handler.dart`.
|
||||
- [x] Sécuriser la route `/api/xtream` avec `authMiddleware`.
|
||||
- [x] Intégrer la validation de domaine et le streaming.
|
||||
- [x] **Streaming**
|
||||
- [x] Sanitizer `streamId`.
|
||||
- [x] **Docker**
|
||||
- [x] Optimiser Dockerfile (Native + User non-root).
|
||||
- [x] Analyze the error and identify root cause
|
||||
- [x] Create entrypoint.sh script to fix permissions at startup
|
||||
- [x] Update Dockerfile to use entrypoint script with gosu
|
||||
- [ ] Rebuild and deploy to test
|
||||
|
||||
## Progress Log
|
||||
|
||||
- Démarrage de la mission d'analyse.
|
||||
- Identified `SqliteException(8): attempt to write a readonly database` error
|
||||
- Root cause: Docker volume created with different permissions than xtremuser
|
||||
- Created `entrypoint.sh` with chown fix and gosu privilege drop
|
||||
- Updated Dockerfile: added gosu, ENTRYPOINT, removed USER directive
|
||||
Reference in new issue
Block a user