Unprivileged docker (WIP)#1685
Closed
dokterbob wants to merge 4 commits intoWebODM:masterfrom
Closed
Conversation
b3c8600 to
06a924a
Compare
Closed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Continuation of #1681.
In addition to a point rightly made on legacy support, the current nginx config expects to run as root.
Cleaner way to address this is arguably to run nginx (or similar) in a separate container (but this might yield challenges around current certbot setup).
nginx issues:
Guidelines towards this setup (which, as a bonus, upgrades nginx and certbot, which are kinda really critical to security):
Alternative approach might be using something like Traefik or Caddy which have ACME built in (and should yield much smaller image sizes).
Leaving this lingering, for now.