Compare commits
21 Commits
Author | SHA1 | Date | |
---|---|---|---|
b82a2d38fa | |||
33ccf93911 | |||
![]() |
0179b787b1 | ||
![]() |
5f1906feb8 | ||
![]() |
f708d1f194 | ||
![]() |
ef8106adcd | ||
![]() |
cc14a5e76a | ||
![]() |
43ee8da6ef | ||
![]() |
836c86e165 | ||
![]() |
0a84b8e997 | ||
![]() |
4666fae569 | ||
![]() |
12fa7c5ef6 | ||
![]() |
ca5461743d | ||
![]() |
5fbc7e8112 | ||
![]() |
c7d1c72737 | ||
![]() |
dc25bd9e65 | ||
![]() |
eed796c375 | ||
![]() |
78fdcfd36b | ||
![]() |
b7c9c4166c | ||
![]() |
d86126bf70 | ||
![]() |
aa88052b5a |
13
.drone.yml
Normal file
13
.drone.yml
Normal file
@ -0,0 +1,13 @@
|
||||
kind: pipeline
|
||||
name: default
|
||||
|
||||
workspace:
|
||||
base: /go
|
||||
path: src/deadbeef.codes/steven/docker-webdav-nginx
|
||||
|
||||
steps:
|
||||
|
||||
- name: docker build
|
||||
image: plugins/docker
|
||||
settings:
|
||||
repo: registry.deadbeef.codes/docker-webdav-nginx
|
18
.github/renovate.json
vendored
18
.github/renovate.json
vendored
@ -1,18 +0,0 @@
|
||||
{
|
||||
"$schema": "https://docs.renovatebot.com/renovate-schema.json",
|
||||
"extends": [
|
||||
"config:base"
|
||||
],
|
||||
"dependencyDashboard": true,
|
||||
"dependencyDashboardTitle": "Renovate Dashboard",
|
||||
"labels": ["renovatebot"],
|
||||
"packageRules": [
|
||||
{
|
||||
"managers": ["github-actions"],
|
||||
"matchUpdateTypes": ["patch"],
|
||||
"automerge": true,
|
||||
"automergeType": "pr",
|
||||
"platformAutomerge": true
|
||||
}
|
||||
]
|
||||
}
|
5
.github/trivy.yaml
vendored
5
.github/trivy.yaml
vendored
@ -1,5 +0,0 @@
|
||||
format: table
|
||||
severity:
|
||||
- CRITICAL
|
||||
vulnerability:
|
||||
ignore-unfixed: true
|
109
.github/workflows/main.yml
vendored
109
.github/workflows/main.yml
vendored
@ -1,109 +0,0 @@
|
||||
name: CI/CD
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- "[0-9]+.[0-9]+.[0-9]+"
|
||||
schedule:
|
||||
- cron: "0 5 * * 0"
|
||||
workflow_dispatch:
|
||||
|
||||
env:
|
||||
USER: loganmarchione
|
||||
REPO: docker-webdav-nginx
|
||||
|
||||
jobs:
|
||||
ci:
|
||||
name: Build and test
|
||||
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Check out the codebase
|
||||
uses: actions/checkout@v3
|
||||
|
||||
- name: Set variables
|
||||
run: |
|
||||
VER=$(cat VERSION)
|
||||
echo "VERSION=$VER" >> $GITHUB_ENV
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
|
||||
- name: Build Docker Image
|
||||
uses: docker/build-push-action@v4
|
||||
with:
|
||||
push: false
|
||||
context: .
|
||||
file: Dockerfile
|
||||
load: true
|
||||
tags: |
|
||||
${{ env.USER }}/${{ env.REPO }}:${{ env.VERSION }}
|
||||
${{ env.USER }}/${{ env.REPO }}:latest
|
||||
|
||||
- name: Test image
|
||||
run: |
|
||||
docker images
|
||||
docker run --name test-container --detach --env WEBDAV_USER=user --env WEBDAV_PASS=password1 --volume 'webdav:/var/www/webdav' ${USER}/${REPO}:${VERSION}
|
||||
docker ps -a
|
||||
|
||||
- name: Container scan with Dockle
|
||||
uses: goodwithtech/dockle-action@0.1.0
|
||||
with:
|
||||
image: '${{ env.USER }}/${{ env.REPO }}:${{ env.VERSION }}'
|
||||
format: 'list'
|
||||
exit-code: '1'
|
||||
exit-level: 'warn'
|
||||
ignore: 'CIS-DI-0001'
|
||||
|
||||
- name: Container scan with hadolint
|
||||
uses: hadolint/hadolint-action@v3.1.0
|
||||
with:
|
||||
failure-threshold: error
|
||||
ignore: DL3008,DL3018
|
||||
|
||||
- name: Container scan with Trivy
|
||||
uses: aquasecurity/trivy-action@0.9.2
|
||||
with:
|
||||
scan-type: 'image'
|
||||
image-ref: '${{ env.USER }}/${{ env.REPO }}:${{ env.VERSION }}'
|
||||
trivy-config: ./github/trivy.yaml
|
||||
|
||||
cd:
|
||||
name: Deploy
|
||||
|
||||
needs: ci
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- name: Check out the codebase
|
||||
uses: actions/checkout@v3
|
||||
|
||||
- name: Set variables
|
||||
run: |
|
||||
VER=$(cat VERSION)
|
||||
echo "VERSION=$VER" >> $GITHUB_ENV
|
||||
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_HUB_USER }}
|
||||
password: ${{ secrets.DOCKER_HUB_PASS }}
|
||||
logout: true
|
||||
|
||||
- name: Build Docker Image
|
||||
uses: docker/build-push-action@v4
|
||||
with:
|
||||
push: true
|
||||
context: .
|
||||
file: Dockerfile
|
||||
platforms: linux/amd64,linux/arm64,linux/arm/v7
|
||||
tags: |
|
||||
${{ env.USER }}/${{ env.REPO }}:${{ env.VERSION }}
|
||||
${{ env.USER }}/${{ env.REPO }}:latest
|
19
Dockerfile
19
Dockerfile
@ -1,19 +1,14 @@
|
||||
FROM debian:11-slim
|
||||
FROM debian:12-slim
|
||||
|
||||
ARG BUILD_DATE
|
||||
|
||||
LABEL \
|
||||
maintainer="Logan Marchione <logan@loganmarchione.com>" \
|
||||
org.opencontainers.image.authors="Logan Marchione <logan@loganmarchione.com>" \
|
||||
org.opencontainers.image.title="docker-webdav-nginx" \
|
||||
org.opencontainers.image.description="Runs a Nginx WebDav server in Docker" \
|
||||
org.opencontainers.image.created=$BUILD_DATE
|
||||
# Originally
|
||||
# LABEL maintainer="Logan Marchione <logan@loganmarchione.com>" \
|
||||
LABEL maintainer="himself@stevenpolley.net"
|
||||
|
||||
ARG DEBIAN_FRONTEND=noninteractive
|
||||
|
||||
RUN apt-get update && apt-get -y install --no-install-recommends \
|
||||
apache2-utils \
|
||||
netcat \
|
||||
netcat-openbsd \
|
||||
nginx-extras && \
|
||||
rm -rf /var/lib/apt/lists/* && \
|
||||
mkdir -p "/var/www/webdav/restricted" && \
|
||||
@ -25,13 +20,13 @@ EXPOSE 80
|
||||
|
||||
VOLUME [ "/var/www/webdav" ]
|
||||
|
||||
COPY password.sh /
|
||||
COPY entrypoint.sh /
|
||||
|
||||
COPY VERSION /
|
||||
|
||||
COPY webdav.conf /etc/nginx/sites-enabled/webdav
|
||||
|
||||
ENTRYPOINT ["/password.sh"]
|
||||
ENTRYPOINT ["/entrypoint.sh"]
|
||||
|
||||
CMD ["nginx", "-g", "daemon off;"]
|
||||
|
||||
|
23
README.md
23
README.md
@ -1,7 +1,6 @@
|
||||
# docker-webdav-nginx
|
||||
[](https://drone.deadbeef.codes/steven/docker-webdav-nginx)
|
||||
|
||||
[](https://github.com/loganmarchione/docker-webdav-nginx/actions/workflows/main.yml)
|
||||
[](https://hub.docker.com/r/loganmarchione/docker-webdav-nginx)
|
||||
# docker-webdav-nginx
|
||||
|
||||
Runs a Nginx WebDav server in Docker
|
||||
- Source code: [GitHub](https://github.com/loganmarchione/docker-webdav-nginx)
|
||||
@ -31,9 +30,10 @@ Runs a Nginx WebDav server in Docker
|
||||
|
||||
### Environment variables
|
||||
| Variable | Required? | Definition | Example | Comments |
|
||||
|-------------|-----------|----------------------------------|----------------------------|--------------------------------------------------------------|
|
||||
|----------------------------|--------------------|----------------------------------------------------------------------------------------------------------------|----------------------------|--------------------------------------------------------------|
|
||||
| WEBDAV_USER | No | WebDav username | user | user AND pass need to be set for authentication to work |
|
||||
| WEBDAV_PASS | No | WebDav password | password1 | user AND pass need to be set for authentication to work |
|
||||
| NGINX_CLIENT_MAX_BODY_SIZE | No (default: 250M) | Nginx's [client_max_body_size](https://nginx.org/en/docs/http/ngx_http_core_module.html#client_max_body_size) | 500M | Be sure to include the units. Set to `0` to disable. |
|
||||
|
||||
### Ports
|
||||
| Port on host | Port in container | Comments |
|
||||
@ -51,11 +51,12 @@ Below is an example docker-compose.yml file.
|
||||
version: '3'
|
||||
services:
|
||||
webdav:
|
||||
container_name: webdav
|
||||
container_name: docker-webdav-nginx
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
- WEBDAV_USER=user
|
||||
- WEBDAV_PASS=password1
|
||||
- NGINX_CLIENT_MAX_BODY_SIZE=500M
|
||||
networks:
|
||||
- webdav
|
||||
ports:
|
||||
@ -72,4 +73,16 @@ volumes:
|
||||
driver: local
|
||||
```
|
||||
|
||||
Below is an example of running locally (used to edit/test/debug).
|
||||
```
|
||||
# Build the Dockerfile
|
||||
docker compose -f docker-compose-dev.yml up -d
|
||||
|
||||
# View logs
|
||||
docker compose -f docker-compose-dev.yml logs -f
|
||||
|
||||
# Destroy when done
|
||||
docker compose -f docker-compose-dev.yml down
|
||||
```
|
||||
|
||||
## TODO
|
||||
|
25
docker-compose-dev.yml
Normal file
25
docker-compose-dev.yml
Normal file
@ -0,0 +1,25 @@
|
||||
version: '3'
|
||||
services:
|
||||
webdav:
|
||||
container_name: docker-webdav-nginx
|
||||
restart: unless-stopped
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
environment:
|
||||
- WEBDAV_USER=user
|
||||
- WEBDAV_PASS=password1
|
||||
- NGINX_CLIENT_MAX_BODY_SIZE=500M
|
||||
networks:
|
||||
- webdav
|
||||
ports:
|
||||
- '8888:80'
|
||||
volumes:
|
||||
- 'webdav:/var/www/webdav'
|
||||
|
||||
networks:
|
||||
webdav:
|
||||
|
||||
volumes:
|
||||
webdav:
|
||||
driver: local
|
27
entrypoint.sh
Executable file
27
entrypoint.sh
Executable file
@ -0,0 +1,27 @@
|
||||
#!/bin/sh -e
|
||||
|
||||
printf "########################################\n"
|
||||
printf "# Container starting up!\n"
|
||||
printf "########################################\n"
|
||||
|
||||
# Check for WebDav user/pass
|
||||
printf "# STATE: Checking for WebDav user/pass\n"
|
||||
if [ -n "$WEBDAV_USER" ] && [ -n "$WEBDAV_PASS" ]
|
||||
then
|
||||
printf "# STATE: WebDav user/pass written to /etc/nginx/webdav_credentials\n"
|
||||
htpasswd -b -c /etc/nginx/webdav_credentials $WEBDAV_USER $WEBDAV_PASS > /dev/null 2>&1
|
||||
else
|
||||
printf "# WARN: No WebDav user/pass were set, the "restricted" directory has no authentication on it!\n"
|
||||
sed -i "s/.*auth_basic.*//g" /etc/nginx/sites-enabled/webdav
|
||||
sed -i "s/.*auth_basic_user_file.*//g" /etc/nginx/sites-enabled/webdav
|
||||
fi
|
||||
|
||||
# Check for client_max_body_size setting
|
||||
if [ -n "$NGINX_CLIENT_MAX_BODY_SIZE" ]
|
||||
then
|
||||
printf "# STATE: Setting client_max_body_size to $NGINX_CLIENT_MAX_BODY_SIZE\n"
|
||||
sed -i "s/client_max_body_size 250M;/client_max_body_size $NGINX_CLIENT_MAX_BODY_SIZE;/g" /etc/nginx/sites-enabled/webdav
|
||||
fi
|
||||
|
||||
printf "# STATE: Nginx is starting up now, the logs you see below are error_log and access_log from Nginx\n"
|
||||
exec "$@"
|
21
password.sh
21
password.sh
@ -1,21 +0,0 @@
|
||||
#!/bin/sh -e
|
||||
|
||||
printf "#####\n"
|
||||
printf "# Container starting up!\n"
|
||||
printf "#####\n"
|
||||
|
||||
# Check for WebDav user/pass
|
||||
printf "# STATE: Checking for WebDav user/pass\n"
|
||||
if [ -n "$WEBDAV_USER" ] && [ -n "$WEBDAV_PASS" ]
|
||||
then
|
||||
printf "# STATE: WebDav user/pass written to /etc/nginx/webdav_credentials\n"
|
||||
htpasswd -b -c /etc/nginx/webdav_credentials $WEBDAV_USER $WEBDAV_PASS > /dev/null 2>&1
|
||||
else
|
||||
printf "# WARN: No WebDav user/pass were set, the 'restricted' diretory has no authentication on it!\n"
|
||||
sed -i 's/.*auth_basic.*//g' /etc/nginx/sites-enabled/webdav
|
||||
sed -i 's/.*auth_basic_user_file.*//g' /etc/nginx/sites-enabled/webdav
|
||||
fi
|
||||
|
||||
|
||||
printf "# STATE: Nginx is starting up now, the logs you see below are error_log and access_log from Nginx\n"
|
||||
exec "$@"
|
@ -5,6 +5,8 @@ server {
|
||||
root /var/www/webdav;
|
||||
autoindex on;
|
||||
|
||||
client_max_body_size 250M;
|
||||
|
||||
location /public {
|
||||
dav_methods PUT DELETE MKCOL COPY MOVE;
|
||||
dav_ext_methods PROPFIND OPTIONS;
|
||||
|
Loading…
x
Reference in New Issue
Block a user