2 Commits

Author SHA1 Message Date
Ducky SSH User
0a37b04506 Fix Alpine Linux addgroup/adduser syntax for non-root user creation
All checks were successful
Build and Release / build (push) Successful in 12s
2025-12-20 06:45:21 +00:00
Ducky SSH User
a5a683d1de Fix Docker Compose and Dockerfile issues: remove image pull, fix entrypoint permissions 2025-12-20 06:36:20 +00:00
3 changed files with 24 additions and 28 deletions

View File

@@ -25,21 +25,21 @@ WORKDIR /app
COPY --from=builder /app/nerd-monitor-agent . COPY --from=builder /app/nerd-monitor-agent .
# Create non-root user # Create entrypoint script BEFORE switching users
RUN addgroup -D appgroup && adduser -D appuser -G appgroup RUN echo '#!/bin/sh' > /app/entrypoint.sh && \
USER appuser echo 'SERVER=${SERVER:-localhost:8080}' >> /app/entrypoint.sh && \
echo 'INTERVAL=${INTERVAL:-15s}' >> /app/entrypoint.sh && \
echo 'AGENT_ID=${AGENT_ID:-}' >> /app/entrypoint.sh && \
echo 'if [ -z "$AGENT_ID" ]; then' >> /app/entrypoint.sh && \
echo ' exec ./nerd-monitor-agent --server "$SERVER" --interval "$INTERVAL"' >> /app/entrypoint.sh && \
echo 'else' >> /app/entrypoint.sh && \
echo ' exec ./nerd-monitor-agent --server "$SERVER" --interval "$INTERVAL" --id "$AGENT_ID"' >> /app/entrypoint.sh && \
echo 'fi' >> /app/entrypoint.sh && \
chmod +x /app/entrypoint.sh
# Create entrypoint script to handle environment variables # Create non-root user
RUN echo '#!/bin/sh\n\ RUN addgroup -g 1000 appgroup && adduser -D -u 1000 -G appgroup appuser
SERVER=${SERVER:-localhost:8080}\n\ USER appuser
INTERVAL=${INTERVAL:-15s}\n\
AGENT_ID=${AGENT_ID:-}\n\
if [ -z "$AGENT_ID" ]; then\n\
exec ./nerd-monitor-agent --server "$SERVER" --interval "$INTERVAL"\n\
else\n\
exec ./nerd-monitor-agent --server "$SERVER" --interval "$INTERVAL" --id "$AGENT_ID"\n\
fi\n\
' > /app/entrypoint.sh && chmod +x /app/entrypoint.sh
# Run the agent # Run the agent
ENTRYPOINT ["/app/entrypoint.sh"] ENTRYPOINT ["/app/entrypoint.sh"]

View File

@@ -32,8 +32,17 @@ RUN apk add --no-cache ca-certificates
# Copy binary from builder # Copy binary from builder
COPY --from=builder /app/nerd-monitor-server . COPY --from=builder /app/nerd-monitor-server .
# Create entrypoint script BEFORE switching users
RUN echo '#!/bin/sh' > /app/entrypoint.sh && \
echo 'ADDR=${ADDR:-0.0.0.0}' >> /app/entrypoint.sh && \
echo 'PORT=${PORT:-8080}' >> /app/entrypoint.sh && \
echo 'USERNAME=${USERNAME:-admin}' >> /app/entrypoint.sh && \
echo 'PASSWORD=${PASSWORD:-admin}' >> /app/entrypoint.sh && \
echo 'exec ./nerd-monitor-server -addr "$ADDR" -port "$PORT" -username "$USERNAME" -password "$PASSWORD"' >> /app/entrypoint.sh && \
chmod +x /app/entrypoint.sh
# Create non-root user # Create non-root user
RUN addgroup -D appgroup && adduser -D appuser -G appgroup RUN addgroup -g 1000 appgroup && adduser -D -u 1000 -G appgroup appuser
USER appuser USER appuser
# Expose port # Expose port
@@ -43,14 +52,5 @@ EXPOSE 8080
HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \ HEALTHCHECK --interval=30s --timeout=3s --start-period=5s --retries=3 \
CMD wget --quiet --tries=1 --spider http://localhost:8080/login || exit 1 CMD wget --quiet --tries=1 --spider http://localhost:8080/login || exit 1
# Create entrypoint script to handle environment variables
RUN echo '#!/bin/sh\n\
ADDR=${ADDR:-0.0.0.0}\n\
PORT=${PORT:-8080}\n\
USERNAME=${USERNAME:-admin}\n\
PASSWORD=${PASSWORD:-admin}\n\
exec ./nerd-monitor-server -addr "$ADDR" -port "$PORT" -username "$USERNAME" -password "$PASSWORD"\n\
' > /app/entrypoint.sh && chmod +x /app/entrypoint.sh
# Run the server # Run the server
ENTRYPOINT ["/app/entrypoint.sh"] ENTRYPOINT ["/app/entrypoint.sh"]

View File

@@ -1,5 +1,3 @@
version: '3.8'
# ============================================================================ # ============================================================================
# Nerd Monitor Docker Compose Configuration # Nerd Monitor Docker Compose Configuration
# ============================================================================ # ============================================================================
@@ -40,7 +38,6 @@ services:
context: . context: .
dockerfile: Dockerfile.server dockerfile: Dockerfile.server
container_name: nerd-monitor-server container_name: nerd-monitor-server
image: nerd-monitor-server:latest
ports: ports:
- "8080:8080" - "8080:8080"
environment: environment:
@@ -82,7 +79,6 @@ services:
build: build:
context: . context: .
dockerfile: Dockerfile.agent dockerfile: Dockerfile.agent
image: nerd-monitor-agent:latest
environment: environment:
# Agent configuration # Agent configuration
SERVER: "server:8080" # Connect to the server service SERVER: "server:8080" # Connect to the server service