From 8d508f8328b6fac7894818201d255d07b03a2c9a Mon Sep 17 00:00:00 2001 From: Vincent Vanwaelscappel Date: Thu, 20 Apr 2023 21:16:48 +0200 Subject: [PATCH] fix #5780 @4 --- .docker/docker-compose.yml | 1 + .../Operations/Tools/DockerWebContainer.php | 34 ++- app/Notifications/DownloadReady.php | 114 +--------- app/Notifications/ToolboxNotification.php | 118 ++++++++++ resources/tools/dockerwebcontainer/base | 5 +- resources/tools/dockerwebcontainer/mysql | 17 +- resources/tools/dockerwebcontainer/php | 28 ++- .../template/config/composer/.htaccess | 1 + .../template/config/composer/auth.json | 5 + .../template/config/cron/crontab | 5 + .../template/config/cron/host | 1 + .../template/{ => config}/httpd/httpd.conf | 13 +- .../template/config/imagemagick/policy.xml | 96 +++++++++ .../template/config/mariadb/charset.cnf | 4 + .../template/config/mariadb/connections.cnf | 2 + .../template/config/mariadb/finetuning.cnf | 16 ++ .../template/config/mariadb/json.cnf | 3 + .../template/config/mariadb/logs.cnf | 8 + .../template/config/mariadb/sql_mode.cnf | 2 + .../template/config/passwords | 1 + .../template/config/php.ini | 6 + .../template/config/rsyslog/50-default.conf | 48 +++++ .../template/config/rsyslog/init.d | 137 ++++++++++++ .../template/config/rsyslog/rsyslog.conf | 60 ++++++ .../template/config/ssh/root/authorized_keys2 | 2 + .../template/config/ssh/server/moduli | 0 .../template/config/ssh/server/ssh_config | 0 .../template/config/ssh/server/sshd_config | 115 ++++++++++ .../template/config/ssh/user/authorized_keys2 | 2 + .../template/config/sudoers | 1 + .../template/images/httpd/Dockerfile | 3 + .../php-5.6-fpm/Dockerfile | 0 .../php-5.6-fpm/overrides.conf | 0 .../php-5.6-fpm/php-fpm-startup | 0 .../{phpdocker => images}/php-fpm/Dockerfile | 52 ++--- .../php-fpm/overrides.conf | 10 +- .../template/images/php-fpm/startup | 33 +++ .../template/phpdocker/README.html | 204 ------------------ .../template/phpdocker/README.md | 143 ------------ .../php-5.6-fpm/php-ini-overrides.ini | 2 - .../phpdocker/php-fpm/php-ini-overrides.ini | 2 - .../template/www/{ => public}/index.php | 0 42 files changed, 782 insertions(+), 512 deletions(-) create mode 100644 app/Notifications/ToolboxNotification.php create mode 100644 resources/tools/dockerwebcontainer/template/config/composer/.htaccess create mode 100644 resources/tools/dockerwebcontainer/template/config/composer/auth.json create mode 100644 resources/tools/dockerwebcontainer/template/config/cron/crontab create mode 100644 resources/tools/dockerwebcontainer/template/config/cron/host rename resources/tools/dockerwebcontainer/template/{ => config}/httpd/httpd.conf (99%) create mode 100644 resources/tools/dockerwebcontainer/template/config/imagemagick/policy.xml create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/charset.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/connections.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/finetuning.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/json.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/logs.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/mariadb/sql_mode.cnf create mode 100644 resources/tools/dockerwebcontainer/template/config/passwords create mode 100644 resources/tools/dockerwebcontainer/template/config/php.ini create mode 100644 resources/tools/dockerwebcontainer/template/config/rsyslog/50-default.conf create mode 100644 resources/tools/dockerwebcontainer/template/config/rsyslog/init.d create mode 100644 resources/tools/dockerwebcontainer/template/config/rsyslog/rsyslog.conf create mode 100644 resources/tools/dockerwebcontainer/template/config/ssh/root/authorized_keys2 create mode 100644 resources/tools/dockerwebcontainer/template/config/ssh/server/moduli create mode 100644 resources/tools/dockerwebcontainer/template/config/ssh/server/ssh_config create mode 100644 resources/tools/dockerwebcontainer/template/config/ssh/server/sshd_config create mode 100644 resources/tools/dockerwebcontainer/template/config/ssh/user/authorized_keys2 create mode 100644 resources/tools/dockerwebcontainer/template/config/sudoers create mode 100644 resources/tools/dockerwebcontainer/template/images/httpd/Dockerfile rename resources/tools/dockerwebcontainer/template/{phpdocker => images}/php-5.6-fpm/Dockerfile (100%) rename resources/tools/dockerwebcontainer/template/{phpdocker => images}/php-5.6-fpm/overrides.conf (100%) rename resources/tools/dockerwebcontainer/template/{phpdocker => images}/php-5.6-fpm/php-fpm-startup (100%) rename resources/tools/dockerwebcontainer/template/{phpdocker => images}/php-fpm/Dockerfile (60%) rename resources/tools/dockerwebcontainer/template/{phpdocker => images}/php-fpm/overrides.conf (87%) create mode 100644 resources/tools/dockerwebcontainer/template/images/php-fpm/startup delete mode 100644 resources/tools/dockerwebcontainer/template/phpdocker/README.html delete mode 100644 resources/tools/dockerwebcontainer/template/phpdocker/README.md delete mode 100644 resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-ini-overrides.ini delete mode 100644 resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/php-ini-overrides.ini rename resources/tools/dockerwebcontainer/template/www/{ => public}/index.php (100%) diff --git a/.docker/docker-compose.yml b/.docker/docker-compose.yml index 58291d4cc..e31dd2a53 100644 --- a/.docker/docker-compose.yml +++ b/.docker/docker-compose.yml @@ -70,6 +70,7 @@ services: - '/home/toolbox/www/.docker/config/passwords:/root/passwords' # Cron - '/home/toolbox/www/.docker/config/cron/crontab:/etc/crontab' + # Rclone - '/home/toolbox/www/.docker/config/rclone.conf:/application/.config/rclone/rclone.conf' # PHP - '/home/toolbox/www/.docker/config/php.ini:/etc/php/8.1/fpm/conf.d/99-overrides.ini' diff --git a/app/Http/Controllers/Admin/Operations/Tools/DockerWebContainer.php b/app/Http/Controllers/Admin/Operations/Tools/DockerWebContainer.php index d28d53c12..508ec53eb 100644 --- a/app/Http/Controllers/Admin/Operations/Tools/DockerWebContainer.php +++ b/app/Http/Controllers/Admin/Operations/Tools/DockerWebContainer.php @@ -2,6 +2,8 @@ namespace App\Http\Controllers\Admin\Operations\Tools; +use App\Notifications\DownloadReady; +use App\Notifications\ToolboxNotification; use Cubist\Backpack\Magic\Fields\Checkbox; use Cubist\Backpack\Magic\Fields\SelectFromArray; use Cubist\Backpack\Magic\Fields\Text; @@ -32,7 +34,7 @@ trait DockerWebContainer // '7.2' => '7.2', // '7.3' => '7.3', '7.4' => '7.4', - '8.0' => '8.0', +// '8.0' => '8.0', '8.1' => '8.1', '8.2' => '8.2', ], 'value' => '8.2']); @@ -49,9 +51,13 @@ trait DockerWebContainer $variables = ['$name' => $name, '$portadminer' => rand(10000, 60000), '$port' => rand(10000, 60000), + '$sshport' => rand(10000, 60000), '$domain' => $request->get('domain', ''), '$dbpassword' => Str::random(16), - '$phpfpmimage' => 'php-fpm' + '$phpfpmimage' => 'php-fpm', + '$locale' => 'fr_FR', + '$localeshort' => 'fr', + '$sshpassword' => Str::random(16), ]; if (!$variables['$domain']) { @@ -70,13 +76,9 @@ trait DockerWebContainer if (version_compare($variables['$phpversion'], '7.3', '<=')) { $variables['$phpfpmimage'] = 'php-' . $variables['$phpversion'] . '-fpm'; } - } else { - `rm -rf $dir/phpdocker`; } if ($request->get('mysql', true)) { $compose[] = 'mysql'; - } else { - `rm -rf $dir/database`; } $compose[] = 'network'; $composeFileContent = ''; @@ -90,7 +92,25 @@ trait DockerWebContainer $tmpfile = Files::tempnam() . '.zip'; Zip::archive($tmp, $tmpfile); Files::rmdir($tmp); - return response()->download($tmpfile, $name . '.zip')->deleteFileAfterSend(true); + $res = response()->download($tmpfile, $name . '.zip')->deleteFileAfterSend(true); + $notification = __('Le container web :name a été crée avec les informations suivantes', ['name' => $variables['$name']]) . "\n"; + $infos = [ + 'URL' => 'https://' . $variables['$domain'] . '/', + __('Hôte et nom de base de données') => $variables['$name'] . '-mariadb', + __('Utilisateur de la base de données') => 'root', + __('Mot de passe de la base de données') => $variables['$dbpassword'], + 'Adminer' => 'https://adminer.' . $variables['$domain'] . '/', + __('Serveur SSH/SFTP') => $variables['$domain'], + __('Port') => $variables['$sshport'], + __('Utilisateur') => $variables['$name'], + __('Mot de passe') => $variables['$sshpassword'], + ]; + foreach ($infos as $k => $v) { + $notification .= '* ' . $k . ' : ' . $v . "\n"; + } + + backpack_user()->notify(new ToolboxNotification(__('Container :name web prêt', ['name' => $variables['$name']]), $notification, [], true)); + return $res; } } diff --git a/app/Notifications/DownloadReady.php b/app/Notifications/DownloadReady.php index 3fa23a9b7..903c974ba 100644 --- a/app/Notifications/DownloadReady.php +++ b/app/Notifications/DownloadReady.php @@ -2,117 +2,7 @@ namespace App\Notifications; -use Illuminate\Bus\Queueable; -use Illuminate\Notifications\Messages\MailMessage; -use Illuminate\Notifications\Notification; -use Illuminate\Support\HtmlString; -use NotificationChannels\WebPush\WebPushChannel; -use NotificationChannels\WebPush\WebPushMessage; - -class DownloadReady extends Notification +class DownloadReady extends ToolboxNotification { - use Queueable; - - protected $subject; - protected $text; - protected $actions = []; - protected $error = false; - protected $showTextIfNotEmail = false; - - /** - * Create a new notification instance. - * - * @return void - */ - public function __construct($subject = '', $text = '', $actions = [], $showTextIfNotEmail = false) - { - $this->subject = $subject; - $this->text = $text; - $this->actions = $actions; - $this->showTextIfNotEmail = $showTextIfNotEmail; - } - - /** - * Get the notification's delivery channels. - * - * @param mixed $notifiable - * @return array - */ - public function via($notifiable) - { - if ($notifiable->slack) { - if ($notifiable->id == 5) { - return ['database', FluidbookslackChannel::class, 'mail', WebPushChannel::class]; - } - return ['database', FluidbookslackChannel::class]; - } - return ['database', 'mail', WebPushChannel::class]; - } - - /** - * Get the mail representation of the notification. - * - * @param mixed $notifiable - * @return \Illuminate\Notifications\Messages\MailMessage - */ - public function toMail($notifiable) - { - $m = (new MailMessage)->greeting(__('Bonjour !')) - ->subject($this->subject); - if ($this->text) { - $m->line($this->text); - } - foreach ($this->actions as $label => $url) { - $m->line(new HtmlString($label . __(': ') . ' ' . $url . '')); - } - $m->salutation(new HtmlString(__('Cordialement,') . "
" . __('L\'équipe Fluidbook'))); - return $m; - - } - - public function toWebPush($notifiable) - { - $res = (new WebPushMessage) - ->title($this->subject) - ->icon('/images/icons/icon-notification.png') - ->lang($notifiable->locale) - ->options(['TTL' => 150]); - - foreach ($this->actions as $label => $url) { - $res->action($label, $url); - } - if ($this->showTextIfNotEmail) { - $res->body($this->text); - } - } - - /** - * Get the array representation of the notification. - * - * @param mixed $notifiable - * @return array - */ - public function toArray($notifiable) - { - - return [ - 'subject' => $this->subject, - 'text' => $this->text, - 'actions' => $this->actions, - ]; - } - - public function toSlack($notifiable) - { - return [ - 'subject' => $this->subject, - 'text' => $this->showTextIfNotEmail ? $this->text : '', - 'actions' => $this->actions, - ]; - } - - public function toDatabase($notifiable) - { - return $this->toSlack($notifiable); - } + } diff --git a/app/Notifications/ToolboxNotification.php b/app/Notifications/ToolboxNotification.php new file mode 100644 index 000000000..ec04fccee --- /dev/null +++ b/app/Notifications/ToolboxNotification.php @@ -0,0 +1,118 @@ +subject = $subject; + $this->text = $text; + $this->actions = $actions; + $this->showTextIfNotEmail = $showTextIfNotEmail; + } + + /** + * Get the notification's delivery channels. + * + * @param mixed $notifiable + * @return array + */ + public function via($notifiable) + { + if ($notifiable->slack) { + if ($notifiable->id == 5) { + return ['database', FluidbookslackChannel::class, 'mail', WebPushChannel::class]; + } + return ['database', FluidbookslackChannel::class]; + } + return ['database', 'mail', WebPushChannel::class]; + } + + /** + * Get the mail representation of the notification. + * + * @param mixed $notifiable + * @return \Illuminate\Notifications\Messages\MailMessage + */ + public function toMail($notifiable) + { + $m = (new MailMessage)->greeting(__('Bonjour !')) + ->subject($this->subject); + if ($this->text) { + $m->line(new HtmlString($this->text)); + } + foreach ($this->actions as $label => $url) { + $m->line(new HtmlString($label . __(': ') . ' ' . $url . '')); + } + $m->salutation(new HtmlString(__('Cordialement,') . "
" . __('L\'équipe Fluidbook'))); + return $m; + + } + + public function toWebPush($notifiable) + { + $res = (new WebPushMessage) + ->title($this->subject) + ->icon('/images/icons/icon-notification.png') + ->lang($notifiable->locale) + ->options(['TTL' => 150]); + + foreach ($this->actions as $label => $url) { + $res->action($label, $url); + } + if ($this->showTextIfNotEmail) { + $res->body($this->text); + } + } + + /** + * Get the array representation of the notification. + * + * @param mixed $notifiable + * @return array + */ + public function toArray($notifiable) + { + + return [ + 'subject' => $this->subject, + 'text' => $this->text, + 'actions' => $this->actions, + ]; + } + + public function toSlack($notifiable) + { + return [ + 'subject' => $this->subject, + 'text' => $this->showTextIfNotEmail ? $this->text : '', + 'actions' => $this->actions, + ]; + } + + public function toDatabase($notifiable) + { + return $this->toSlack($notifiable); + } +} diff --git a/resources/tools/dockerwebcontainer/base b/resources/tools/dockerwebcontainer/base index 39a9f499e..93716760f 100644 --- a/resources/tools/dockerwebcontainer/base +++ b/resources/tools/dockerwebcontainer/base @@ -2,11 +2,12 @@ version: '3.1' services: webserver: container_name: $name-httpd - image: 'httpd:alpine' + build: './images/httpd' working_dir: /application volumes: - './www/public/:/usr/local/apache2/htdocs/' - - './httpd/httpd.conf:/usr/local/apache2/conf/httpd.conf' + - './www/:/application/' + - './config/httpd/httpd.conf:/usr/local/apache2/conf/httpd.conf' ports: - '$port:80' environment: diff --git a/resources/tools/dockerwebcontainer/mysql b/resources/tools/dockerwebcontainer/mysql index 1ca45641e..12156207c 100644 --- a/resources/tools/dockerwebcontainer/mysql +++ b/resources/tools/dockerwebcontainer/mysql @@ -1,5 +1,5 @@ adminer: - image: adminer:latest + image: 'adminer:latest' container_name: $name-adminer restart: unless-stopped ports: @@ -12,13 +12,22 @@ - $name mariadb: container_name: $name-mariadb - image: 'mariadb' + image: 'mariadb:latest' restart: unless-stopped environment: MARIADB_ROOT_PASSWORD: $dbpassword MARIADB_DATABASE: $name + MARIADB_AUTO_UPGRADE: 1 volumes: - - "./database:/var/lib/mysql" - - "./dump.sql:/docker-entrypoint-initdb.d/dump.sql" + - "./database/dump.sql:/docker-entrypoint-initdb.d/dump.sql" + - "./database/scripts/:/usr/local/bin/scripts/" + - "./database/data:/var/lib/mysql" + - './config/mariadb:/etc/mysql/conf.d:z' networks: - $name + logging: + driver: json-file + options: + max-size: 10M + max-file: 10 + diff --git a/resources/tools/dockerwebcontainer/php b/resources/tools/dockerwebcontainer/php index 6d887acde..73757cba6 100644 --- a/resources/tools/dockerwebcontainer/php +++ b/resources/tools/dockerwebcontainer/php @@ -1,10 +1,32 @@ php-fpm: container_name: $name - build: phpdocker/$phpfpmimage + hostname: $name + build: './images/$phpfpmimage' working_dir: /application volumes: - - '/docker/$name/www:/application' - - '/docker/$name/phpdocker/$phpfpmimage/php-ini-overrides.ini:/etc/php/$phpversion/fpm/conf.d/99-overrides.ini' + # SSH + - './config/ssh/root/:/root/.ssh/' + - './config/ssh/user/:/application/.ssh/' + - './config/ssh/server/:/etc/ssh/' + # Rsyslog + - './config/rsyslog/rsyslog.conf:/etc/rsyslog.conf' + - './config/rsyslog/50-default.conf:/etc/rsyslog.d/50-default.conf' + # Composer + - './config/composer/:/root/.config/composer/' + - './config/composer/:/application/.config/composer/' + # Sudoers + - './config/sudoers:/etc/sudoers.d/toolbox' + - './images/$phpfpmimage/php-ini-overrides.ini:/etc/php/$phpversion/fpm/conf.d/99-overrides.ini' + # ImageMagick + - './config/imagemagick/policy.xml:/etc/ImageMagick-6/policy.xml' + # Passwords + - './config/passwords:/root/passwords' + # PHP + - './config/php.ini:/etc/php/$phpversion/fpm/conf.d/99-overrides.ini' + # Web path + - './www:/application' + ports: + - '$sshport:22' networks: - $name restart: unless-stopped diff --git a/resources/tools/dockerwebcontainer/template/config/composer/.htaccess b/resources/tools/dockerwebcontainer/template/config/composer/.htaccess new file mode 100644 index 000000000..14249c50b --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/composer/.htaccess @@ -0,0 +1 @@ +Deny from all \ No newline at end of file diff --git a/resources/tools/dockerwebcontainer/template/config/composer/auth.json b/resources/tools/dockerwebcontainer/template/config/composer/auth.json new file mode 100644 index 000000000..6b9274a8b --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/composer/auth.json @@ -0,0 +1,5 @@ +{ + "github-oauth": { + "github.com": "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" + } +} diff --git a/resources/tools/dockerwebcontainer/template/config/cron/crontab b/resources/tools/dockerwebcontainer/template/config/cron/crontab new file mode 100644 index 000000000..ea5e3f9a3 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/cron/crontab @@ -0,0 +1,5 @@ +MAILTO=sysadmin@cubedesigners.com +SHELL=/bin/sh +PATH=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin + + diff --git a/resources/tools/dockerwebcontainer/template/config/cron/host b/resources/tools/dockerwebcontainer/template/config/cron/host new file mode 100644 index 000000000..5b762862c --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/cron/host @@ -0,0 +1 @@ +3 4 * * * root /docker/$name/build >/dev/null 2>/dev/null diff --git a/resources/tools/dockerwebcontainer/template/httpd/httpd.conf b/resources/tools/dockerwebcontainer/template/config/httpd/httpd.conf similarity index 99% rename from resources/tools/dockerwebcontainer/template/httpd/httpd.conf rename to resources/tools/dockerwebcontainer/template/config/httpd/httpd.conf index 10f77b655..7956e5fa0 100644 --- a/resources/tools/dockerwebcontainer/template/httpd/httpd.conf +++ b/resources/tools/dockerwebcontainer/template/config/httpd/httpd.conf @@ -198,6 +198,8 @@ LoadModule dir_module modules/mod_dir.so LoadModule alias_module modules/mod_alias.so LoadModule rewrite_module modules/mod_rewrite.so +LoadModule xsendfile_module /usr/lib/apache2/modules/mod_xsendfile.so + # # If you wish httpd to run as a different user or group, you must run @@ -262,8 +264,8 @@ ServerAdmin you@example.com # documents. By default, all requests are taken from this directory, but # symbolic links and aliases may be used to point to other locations. # -DocumentRoot "/usr/local/apache2/htdocs" - +DocumentRoot "/application/public" + # # Possible values for the Options directive are "None", "All", # or any combination of: @@ -291,8 +293,11 @@ DocumentRoot "/usr/local/apache2/htdocs" Require all granted -RemoteIPHeader X-Forwarded-For -ProxyPassMatch ^/(.*\.php(/.*)?)$ "fcgi://$name:9000/application/$1" timeout=1800 +ProxyPassMatch ^/(.*\.php(/.*)?)$ "fcgi://$name:9000/application/public/$1" timeout=1800 + +XSendFile on +XSendFilePath /application + # # DirectoryIndex: sets the file that Apache will serve if a directory diff --git a/resources/tools/dockerwebcontainer/template/config/imagemagick/policy.xml b/resources/tools/dockerwebcontainer/template/config/imagemagick/policy.xml new file mode 100644 index 000000000..cf31ee668 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/imagemagick/policy.xml @@ -0,0 +1,96 @@ + + + + + + ]> + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/charset.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/charset.cnf new file mode 100644 index 000000000..a624a1170 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/charset.cnf @@ -0,0 +1,4 @@ +[mariadb] +collation-server = utf8mb4_unicode_ci +init-connect='SET NAMES utf8mb4' +character-set-server = utf8mb4 diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/connections.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/connections.cnf new file mode 100644 index 000000000..f623ae6ab --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/connections.cnf @@ -0,0 +1,2 @@ +[mariadb] +max_connections = 1024 diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/finetuning.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/finetuning.cnf new file mode 100644 index 000000000..ea9762385 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/finetuning.cnf @@ -0,0 +1,16 @@ +[mariadb] + +skip-name-resolve + +key_buffer_size = 128M +max_allowed_packet = 512M +max_heap_table_size = 512M +tmp_table_size = 256M + +innodb_buffer_pool_size = 4G + +join_buffer_size = 32M +join_buffer_space_limit = 256M +join_cache_level = 12 + +query_cache_size = 256M diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/json.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/json.cnf new file mode 100644 index 000000000..a452aff44 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/json.cnf @@ -0,0 +1,3 @@ +[mariadb] +plugin-maturity=alpha +plugin-load-add=type_mysql_json diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/logs.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/logs.cnf new file mode 100644 index 000000000..2a54d170e --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/logs.cnf @@ -0,0 +1,8 @@ +[mariadb] +skip-log-error + +general_log = 0 +general_log_file = /var/log/mysql/queries.log + +slow_query_log = 0 +slow_query_log_file = /var/log/mysql/slow_queries.log diff --git a/resources/tools/dockerwebcontainer/template/config/mariadb/sql_mode.cnf b/resources/tools/dockerwebcontainer/template/config/mariadb/sql_mode.cnf new file mode 100644 index 000000000..606395376 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/mariadb/sql_mode.cnf @@ -0,0 +1,2 @@ +[mariadb] +sql_mode = ERROR_FOR_DIVISION_BY_ZERO,NO_AUTO_CREATE_USER,NO_ENGINE_SUBSTITUTION diff --git a/resources/tools/dockerwebcontainer/template/config/passwords b/resources/tools/dockerwebcontainer/template/config/passwords new file mode 100644 index 000000000..5f9db609a --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/passwords @@ -0,0 +1 @@ +$name:$sshpassword diff --git a/resources/tools/dockerwebcontainer/template/config/php.ini b/resources/tools/dockerwebcontainer/template/config/php.ini new file mode 100644 index 000000000..c0ef7ab55 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/php.ini @@ -0,0 +1,6 @@ +upload_max_filesize = 8G +post_max_size = 8G +error_log = /proc/self/fd/2 +log_errors = 1 +memory_limit = 12G +max_input_vars = 1000000 diff --git a/resources/tools/dockerwebcontainer/template/config/rsyslog/50-default.conf b/resources/tools/dockerwebcontainer/template/config/rsyslog/50-default.conf new file mode 100644 index 000000000..f939a484b --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/rsyslog/50-default.conf @@ -0,0 +1,48 @@ +# Default rules for rsyslog. +# +# For more information see rsyslog.conf(5) and /etc/rsyslog.conf + +# +# First some standard log files. Log by facility. +# +auth,authpriv.* /var/log/auth.log +*.*;auth,authpriv.none -/var/log/syslog +#cron.* /var/log/cron.log +#daemon.* -/var/log/daemon.log +kern.* -/var/log/kern.log +#lpr.* -/var/log/lpr.log +mail.* -/var/log/mail.log +#user.* -/var/log/user.log + +# +# Logging for the mail system. Split it up so that +# it is easy to write scripts to parse these files. +# +#mail.info -/var/log/mail.info +#mail.warn -/var/log/mail.warn +mail.err /var/log/mail.err + +# +# Some "catch-all" log files. +# +#*.=debug;\ +# auth,authpriv.none;\ +# news.none;mail.none -/var/log/debug +#*.=info;*.=notice;*.=warn;\ +# auth,authpriv.none;\ +# cron,daemon.none;\ +# mail,news.none -/var/log/messages + +# +# Emergencies are sent to everybody logged in. +# +*.emerg :omusrmsg:* + +# +# I like to have messages displayed on the console, but only on a virtual +# console I usually leave idle. +# +#daemon,mail.*;\ +# news.=crit;news.=err;news.=notice;\ +# *.=debug;*.=info;\ +# *.=notice;*.=warn /dev/tty8 diff --git a/resources/tools/dockerwebcontainer/template/config/rsyslog/init.d b/resources/tools/dockerwebcontainer/template/config/rsyslog/init.d new file mode 100644 index 000000000..96ddd1499 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/rsyslog/init.d @@ -0,0 +1,137 @@ +#! /bin/sh +### BEGIN INIT INFO +# Provides: rsyslog +# Required-Start: $remote_fs $time +# Required-Stop: umountnfs $time +# X-Stop-After: sendsigs +# Default-Start: 2 3 4 5 +# Default-Stop: 0 1 6 +# Short-Description: enhanced syslogd +# Description: Rsyslog is an enhanced multi-threaded syslogd. +# It is quite compatible to stock sysklogd and can be +# used as a drop-in replacement. +### END INIT INFO + +# +# Author: Michael Biebl +# + +# PATH should only include /usr/* if it runs after the mountnfs.sh script +PATH=/sbin:/usr/sbin:/bin:/usr/bin +DESC="enhanced syslogd" +NAME=rsyslog + +RSYSLOGD=rsyslogd +RSYSLOGD_BIN=/usr/sbin/rsyslogd +RSYSLOGD_OPTIONS="-c5" +RSYSLOGD_PIDFILE=/var/run/rsyslogd.pid + +SCRIPTNAME=/etc/init.d/$NAME + +# Exit if the package is not installed +[ -x "$RSYSLOGD_BIN" ] || exit 0 + +# Read configuration variable file if it is present +[ -r /etc/default/$NAME ] && . /etc/default/$NAME + +# Define LSB log_* functions. +. /lib/lsb/init-functions + +do_start() +{ + DAEMON="$RSYSLOGD_BIN" + DAEMON_ARGS="$RSYSLOGD_OPTIONS" + PIDFILE="$RSYSLOGD_PIDFILE" + + # Return + # 0 if daemon has been started + # 1 if daemon was already running + # other if daemon could not be started or a failure occured + start-stop-daemon --start --quiet --pidfile $PIDFILE --exec $DAEMON -- $DAEMON_ARGS +} + +do_stop() +{ + DAEMON="$RSYSLOGD_BIN" + PIDFILE="$RSYSLOGD_PIDFILE" + + # Return + # 0 if daemon has been stopped + # 1 if daemon was already stopped + # other if daemon could not be stopped or a failure occurred + start-stop-daemon --stop --quiet --retry=TERM/30/KILL/5 --pidfile $PIDFILE --exec $DAEMON +} + +# +# Tell rsyslogd to close all open files +# +do_rotate() { + DAEMON="$RSYSLOGD_BIN" + PIDFILE="$RSYSLOGD_PIDFILE" + + start-stop-daemon --stop --signal HUP --quiet --pidfile $PIDFILE --exec $DAEMON +} + +create_xconsole() { + XCONSOLE=/dev/xconsole + if [ "$(uname -s)" != "Linux" ]; then + XCONSOLE=/run/xconsole + ln -sf $XCONSOLE /dev/xconsole + fi + if [ ! -e $XCONSOLE ]; then + mknod -m 640 $XCONSOLE p + chown root:adm $XCONSOLE + [ -x /sbin/restorecon ] && /sbin/restorecon $XCONSOLE + fi +} + +sendsigs_omit() { + OMITDIR=/run/sendsigs.omit.d + mkdir -p $OMITDIR + ln -sf $RSYSLOGD_PIDFILE $OMITDIR/rsyslog +} + +case "$1" in + start) + log_daemon_msg "Starting $DESC" "$RSYSLOGD" + create_xconsole + do_start + case "$?" in + 0) sendsigs_omit + log_end_msg 0 ;; + 1) log_progress_msg "already started" + log_end_msg 0 ;; + *) log_end_msg 1 ;; + esac + + ;; + stop) + log_daemon_msg "Stopping $DESC" "$RSYSLOGD" + do_stop + case "$?" in + 0) log_end_msg 0 ;; + 1) log_progress_msg "already stopped" + log_end_msg 0 ;; + *) log_end_msg 1 ;; + esac + + ;; + rotate) + log_daemon_msg "Closing open files" "$RSYSLOGD" + do_rotate + log_end_msg $? + ;; + restart|force-reload) + $0 stop + $0 start + ;; + status) + status_of_proc -p $RSYSLOGD_PIDFILE $RSYSLOGD_BIN $RSYSLOGD && exit 0 || exit $? + ;; + *) + echo "Usage: $SCRIPTNAME {start|stop|rotate|restart|force-reload|status}" >&2 + exit 3 + ;; +esac + +: \ No newline at end of file diff --git a/resources/tools/dockerwebcontainer/template/config/rsyslog/rsyslog.conf b/resources/tools/dockerwebcontainer/template/config/rsyslog/rsyslog.conf new file mode 100644 index 000000000..94bc18f26 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/rsyslog/rsyslog.conf @@ -0,0 +1,60 @@ +# /etc/rsyslog.conf configuration file for rsyslog +# +# For more information install rsyslog-doc and see +# /usr/share/doc/rsyslog-doc/html/configuration/index.html +# +# Default logging rules can be found in /etc/rsyslog.d/50-default.conf + + +################# +#### MODULES #### +################# + +module(load="imuxsock") # provides support for local system logging +#module(load="immark") # provides --MARK-- message capability + +# provides UDP syslog reception +#module(load="imudp") +#input(type="imudp" port="514") + +# provides TCP syslog reception +#module(load="imtcp") +#input(type="imtcp" port="514") + +# provides kernel logging support and enable non-kernel klog messages +# module(load="imklog" permitnonkernelfacility="on") + + +########################### +#### GLOBAL DIRECTIVES #### +########################### + +# +# Use traditional timestamp format. +# To enable high precision timestamps, comment out the following line. +# +$ActionFileDefaultTemplate RSYSLOG_TraditionalFileFormat + +# Filter duplicated messages +$RepeatedMsgReduction on + +# +# Set the default permissions for all log files. +# +$FileOwner syslog +$FileGroup adm +$FileCreateMode 0640 +$DirCreateMode 0755 +$Umask 0022 +$PrivDropToUser syslog +$PrivDropToGroup syslog + +# +# Where to place spool and state files +# +$WorkDirectory /var/spool/rsyslog + +# +# Include all config files in /etc/rsyslog.d/ +# +$IncludeConfig /etc/rsyslog.d/*.conf \ No newline at end of file diff --git a/resources/tools/dockerwebcontainer/template/config/ssh/root/authorized_keys2 b/resources/tools/dockerwebcontainer/template/config/ssh/root/authorized_keys2 new file mode 100644 index 000000000..c5de45b88 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/ssh/root/authorized_keys2 @@ -0,0 +1,2 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAtabxRZZMjtmq+r8uXsBmfLgAtkxqwigGpx0e6Mx066ukIWIafFsguity6aV5QNI4UfxXnX3QXROcWeIiyLBV4yDGxuq7ah4r0X1CjqHUvHoGpXwJ2DIWPeaa8XyXnavmj0SNtKn0f1T+oJS0fcryUTLyxY7eOgNsr+pp1fVmgca9Efj0BKUXV/SUIjp8JX3x0/E/3PAqG81zus2SxzuOO1b0FKXDq43Gx6Ov3Ok7+Pje4G4pB56rJiiXlPxrBlY0e8Pz/7+kFF8izCiztJLtZig32Dx0HbLYGtSvIPJKYxK8DDD/RWWpL3mgNPYZ2PE3wHf4c7CTlxLCDP+NeRS1yQ== vincent+2021@cubedesigners.com +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDYAQ/tdQpfweVSyxgvF7hFtl4ax+0g8uI102LeH4NmZtzh85DmD3ccoN5UvAf3SOU6nTGLBN2i/YGRruYmm3PDDYBwyKmq3d1ZqUd8ItNfmTlVbRQme0qE6uOVfHgiejDqm9SS0kbI0lYi/BHp7sWK0UM18iE6NbsSgxw468FwBhtSiR78dw1yEhZQdtQDxusD6LbsGDsj37bV9YHFPVslzc6Bkf4fg9igm5YStCdmcYG86t0RUZDfHw6YGuIxXWkDRh1fpC6yj3Wv+n4+Zho5Bjlryg+YRhxFzno2VxgIeScIAernhUq3yy2whZU3jrWfXKfxutPmpCowl17ydcMXUr8Zt44RaYSVJI6V2lbw/B3HWW8BjkVmHlzDhulw4sJzWYoQOhiDLrUFprdF49CtYFrfsuVOx1IwETfnKKI0w5JqID+sa1iYCtgP9BdfO/H04iW3pFeaNhKW89c7GNZHhNuAS9x5wmcDpYiu2DH/ZIZIQ2wGKcyiZ0sMXQqBS4U= 33610@AYOR diff --git a/resources/tools/dockerwebcontainer/template/config/ssh/server/moduli b/resources/tools/dockerwebcontainer/template/config/ssh/server/moduli new file mode 100644 index 000000000..e69de29bb diff --git a/resources/tools/dockerwebcontainer/template/config/ssh/server/ssh_config b/resources/tools/dockerwebcontainer/template/config/ssh/server/ssh_config new file mode 100644 index 000000000..e69de29bb diff --git a/resources/tools/dockerwebcontainer/template/config/ssh/server/sshd_config b/resources/tools/dockerwebcontainer/template/config/ssh/server/sshd_config new file mode 100644 index 000000000..f9386d2a9 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/ssh/server/sshd_config @@ -0,0 +1,115 @@ + +# This is the sshd server system-wide configuration file. See +# sshd_config(5) for more information. + +# This sshd was compiled with PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/usr/games + +# The strategy used for options in the default sshd_config shipped with +# OpenSSH is to specify options with their default value where +# possible, but leave them commented. Uncommented options override the +# default value. + +Include /etc/ssh/sshd_config.d/*.conf + +#Port 22 +#AddressFamily any +#ListenAddress 0.0.0.0 +#ListenAddress :: + +#HostKey /etc/ssh/ssh_host_rsa_key +#HostKey /etc/ssh/ssh_host_ecdsa_key +#HostKey /etc/ssh/ssh_host_ed25519_key + +# Ciphers and keying +#RekeyLimit default none + +# Logging +#SyslogFacility AUTH +#LogLevel INFO + +# Authentication: + +#LoginGraceTime 2m +#PermitRootLogin prohibit-password +#StrictModes yes +#MaxAuthTries 6 +#MaxSessions 10 + +#PubkeyAuthentication yes + +# Expect .ssh/authorized_keys2 to be disregarded by default in future. +#AuthorizedKeysFile .ssh/authorized_keys .ssh/authorized_keys2 + +#AuthorizedPrincipalsFile none + +#AuthorizedKeysCommand none +#AuthorizedKeysCommandUser nobody + +# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts +#HostbasedAuthentication no +# Change to yes if you don't trust ~/.ssh/known_hosts for +# HostbasedAuthentication +#IgnoreUserKnownHosts no +# Don't read the user's ~/.rhosts and ~/.shosts files +#IgnoreRhosts yes + +# To disable tunneled clear text passwords, change to no here! +#PasswordAuthentication yes +#PermitEmptyPasswords no + +# Change to yes to enable challenge-response passwords (beware issues with +# some PAM modules and threads) +KbdInteractiveAuthentication no + +# Kerberos options +#KerberosAuthentication no +#KerberosOrLocalPasswd yes +#KerberosTicketCleanup yes +#KerberosGetAFSToken no + +# GSSAPI options +#GSSAPIAuthentication no +#GSSAPICleanupCredentials yes +#GSSAPIStrictAcceptorCheck yes +#GSSAPIKeyExchange no + +# Set this to 'yes' to enable PAM authentication, account processing, +# and session processing. If this is enabled, PAM authentication will +# be allowed through the KbdInteractiveAuthentication and +# PasswordAuthentication. Depending on your PAM configuration, +# PAM authentication via KbdInteractiveAuthentication may bypass +# the setting of "PermitRootLogin without-password". +# If you just want the PAM account and session checks to run without +# PAM authentication, then enable this but set PasswordAuthentication +# and KbdInteractiveAuthentication to 'no'. +UsePAM yes + +#AllowAgentForwarding yes +#AllowTcpForwarding yes +#GatewayPorts no +X11Forwarding yes +#X11DisplayOffset 10 +#X11UseLocalhost yes +#PermitTTY yes +PrintMotd no +#PrintLastLog yes +#TCPKeepAlive yes +#PermitUserEnvironment no +#Compression delayed +#ClientAliveInterval 0 +#ClientAliveCountMax 3 +#UseDNS no +#PidFile /run/sshd.pid +#MaxStartups 10:30:100 +#PermitTunnel no +#ChrootDirectory none +#VersionAddendum none + +# no default banner path +#Banner none + +# Allow client to pass locale environment variables +AcceptEnv LANG LC_* + +# override default of no subsystems +Subsystem sftp /usr/lib/openssh/sftp-server diff --git a/resources/tools/dockerwebcontainer/template/config/ssh/user/authorized_keys2 b/resources/tools/dockerwebcontainer/template/config/ssh/user/authorized_keys2 new file mode 100644 index 000000000..c5de45b88 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/ssh/user/authorized_keys2 @@ -0,0 +1,2 @@ +ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEAtabxRZZMjtmq+r8uXsBmfLgAtkxqwigGpx0e6Mx066ukIWIafFsguity6aV5QNI4UfxXnX3QXROcWeIiyLBV4yDGxuq7ah4r0X1CjqHUvHoGpXwJ2DIWPeaa8XyXnavmj0SNtKn0f1T+oJS0fcryUTLyxY7eOgNsr+pp1fVmgca9Efj0BKUXV/SUIjp8JX3x0/E/3PAqG81zus2SxzuOO1b0FKXDq43Gx6Ov3Ok7+Pje4G4pB56rJiiXlPxrBlY0e8Pz/7+kFF8izCiztJLtZig32Dx0HbLYGtSvIPJKYxK8DDD/RWWpL3mgNPYZ2PE3wHf4c7CTlxLCDP+NeRS1yQ== vincent+2021@cubedesigners.com +ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDYAQ/tdQpfweVSyxgvF7hFtl4ax+0g8uI102LeH4NmZtzh85DmD3ccoN5UvAf3SOU6nTGLBN2i/YGRruYmm3PDDYBwyKmq3d1ZqUd8ItNfmTlVbRQme0qE6uOVfHgiejDqm9SS0kbI0lYi/BHp7sWK0UM18iE6NbsSgxw468FwBhtSiR78dw1yEhZQdtQDxusD6LbsGDsj37bV9YHFPVslzc6Bkf4fg9igm5YStCdmcYG86t0RUZDfHw6YGuIxXWkDRh1fpC6yj3Wv+n4+Zho5Bjlryg+YRhxFzno2VxgIeScIAernhUq3yy2whZU3jrWfXKfxutPmpCowl17ydcMXUr8Zt44RaYSVJI6V2lbw/B3HWW8BjkVmHlzDhulw4sJzWYoQOhiDLrUFprdF49CtYFrfsuVOx1IwETfnKKI0w5JqID+sa1iYCtgP9BdfO/H04iW3pFeaNhKW89c7GNZHhNuAS9x5wmcDpYiu2DH/ZIZIQ2wGKcyiZ0sMXQqBS4U= 33610@AYOR diff --git a/resources/tools/dockerwebcontainer/template/config/sudoers b/resources/tools/dockerwebcontainer/template/config/sudoers new file mode 100644 index 000000000..d7663ef75 --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/config/sudoers @@ -0,0 +1 @@ +toolbox ALL=(ALL) NOPASSWD:ALL diff --git a/resources/tools/dockerwebcontainer/template/images/httpd/Dockerfile b/resources/tools/dockerwebcontainer/template/images/httpd/Dockerfile new file mode 100644 index 000000000..aab8bc21c --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/images/httpd/Dockerfile @@ -0,0 +1,3 @@ +FROM httpd +RUN apt-get update && apt-get install -y --no-install-recommends nano less bash libapache2-mod-xsendfile +RUN apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /usr/share/doc/* diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/Dockerfile b/resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/Dockerfile similarity index 100% rename from resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/Dockerfile rename to resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/Dockerfile diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/overrides.conf b/resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/overrides.conf similarity index 100% rename from resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/overrides.conf rename to resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/overrides.conf diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-fpm-startup b/resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/php-fpm-startup similarity index 100% rename from resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-fpm-startup rename to resources/tools/dockerwebcontainer/template/images/php-5.6-fpm/php-fpm-startup diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/Dockerfile b/resources/tools/dockerwebcontainer/template/images/php-fpm/Dockerfile similarity index 60% rename from resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/Dockerfile rename to resources/tools/dockerwebcontainer/template/images/php-fpm/Dockerfile index 0ee19fc63..f7102e19e 100644 --- a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/Dockerfile +++ b/resources/tools/dockerwebcontainer/template/images/php-fpm/Dockerfile @@ -12,14 +12,18 @@ ENV TERM=linux # Ensure apt doesn't ask questions when installing stuff ENV DEBIAN_FRONTEND=noninteractive -# Install Ondrej repos for Ubuntu jammy, PHP, composer and selected extensions - better selection than -# the distro's packages -RUN apt-get update \ - && apt-get install -y --no-install-recommends gnupg \ +# Add Ondrej PHP repository +RUN apt update \ + && apt install -y --no-install-recommends gnupg \ && echo "deb http://ppa.launchpad.net/ondrej/php/ubuntu jammy main" > /etc/apt/sources.list.d/ondrej-php.list \ - && apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 4F4EA0AAE5267A6C \ - && apt-get update \ - && apt-get -y --no-install-recommends install \ + && apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 4F4EA0AAE5267A6C + +# Install nodejs repository +RUN curl -fsSL https://deb.nodesource.com/setup_19.x | bash - + +RUN apt update + +RUN apt -y --no-install-recommends install \ ca-certificates \ curl \ unzip \ @@ -46,35 +50,35 @@ RUN apt-get update \ php$phpversion-tidy \ php$phpversion-xsl \ php$phpversion-curl \ - php$phpversion-json \ php$phpversion-mcrypt \ - less nano wget curl \ - && apt-get clean \ - && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /usr/share/doc/* ~/.composer + php$phpversion-fpm \ + less nano wget curl -COPY --from=composer:2 /usr/bin/composer /usr/bin/composer +RUN apt -y --no-install-recommends install nodejs sudo openssh-server rsyslog cron mariadb-client -CMD ["php", "-a"] +RUN apt -y --no-install-recommends install locales +RUN sed -i '/$locale.UTF-8/s/^# //g' /etc/locale.gen && \ + locale-gen +ENV LANG $locale.UTF-8 +ENV LANGUAGE $locale:$localshort +ENV LC_ALL $locale.UTF-8 -# If you'd like to be able to use this container on a docker-compose environment as a quiescent PHP CLI container -# you can /bin/bash into, override CMD with the following - bear in mind that this will make docker-compose stop -# slow on such a container, docker-compose kill might do if you're in a hurry -# CMD ["tail", "-f", "/dev/null"] +COPY --from=composer:2 /usr/bin/composer /usr/bin/composer -FROM cli AS fpm +# IF you need some npm globally installed packages +# RUN npm install --unsafe-perm --global -# Install FPM -RUN apt-get update \ - && apt-get -y --no-install-recommends install php$phpversion-fpm \ - && apt-get clean \ - && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* /usr/share/doc/* +CMD ["php", "-a"] STOPSIGNAL SIGQUIT +RUN groupadd sudo;useradd -d /application -g 33 -G sudo -s /bin/bash -u 1001 $name + # PHP-FPM packages need a nudge to make them docker-friendly COPY overrides.conf /etc/php/$phpversion/fpm/pool.d/z-overrides.conf -CMD ["/usr/sbin/php-fpm$phpversion", "-O" ] +COPY --chmod=755 startup /usr/bin/startup +CMD exec /usr/bin/startup # Open up fcgi port EXPOSE 9000 diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/overrides.conf b/resources/tools/dockerwebcontainer/template/images/php-fpm/overrides.conf similarity index 87% rename from resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/overrides.conf rename to resources/tools/dockerwebcontainer/template/images/php-fpm/overrides.conf index 4a99e3e4e..b799bf136 100644 --- a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/overrides.conf +++ b/resources/tools/dockerwebcontainer/template/images/php-fpm/overrides.conf @@ -30,8 +30,8 @@ user = 1001 group = 33 pm = dynamic -pm.max_children = 160 -pm.start_servers = 48 -pm.min_spare_servers = 40 -pm.max_spare_servers = 80 -pm.max_requests = 1000 +pm.max_children = 16 +pm.start_servers = 4 +pm.min_spare_servers = 4 +pm.max_spare_servers = 8 +pm.max_requests = 500 diff --git a/resources/tools/dockerwebcontainer/template/images/php-fpm/startup b/resources/tools/dockerwebcontainer/template/images/php-fpm/startup new file mode 100644 index 000000000..0341d5abc --- /dev/null +++ b/resources/tools/dockerwebcontainer/template/images/php-fpm/startup @@ -0,0 +1,33 @@ +#!/bin/sh + +# Set file rights +umask 0000 +chmod -R 777 /tmp + +chown -R root:root /etc/sudoers.d +chown -R $name:www-data /application + +# Rsyslog +start-stop-daemon --start -b -x /usr/sbin/rsyslogd -- -n + +# SSH Server +ssh-keygen -A +chmod 755 /etc/ssh/*.d +chmod 600 /etc/ssh/*_key +chmod 750 /application +#chmod 600 /application/.ssh/id_rsa +chmod 700 /application/.ssh/ +chmod 600 /application/.ssh/authorized_keys2 +#chmod 600 /root/.ssh/id_rsa +chmod 700 /root/.ssh/ +chmod 600 /root/.ssh/authorized_keys2 +/usr/sbin/service ssh start + +# Cron +chmod 0644 /etc/crontab && crontab -u root /etc/crontab && /usr/sbin/service cron start + +# Set user password +chpasswd < /root/passwords + +# Launch PHP +/usr/sbin/php-fpm$phpversion -O diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/README.html b/resources/tools/dockerwebcontainer/template/phpdocker/README.html deleted file mode 100644 index 95d333258..000000000 --- a/resources/tools/dockerwebcontainer/template/phpdocker/README.html +++ /dev/null @@ -1,204 +0,0 @@ - - - PHPDocker.io Readme - - - - - - -
-
-
-

PHPDocker.io generated environment

- -

Add to your project

- -

Simply, unzip the file into your project, this will create docker-compose.yml on the root of your project and a folder -named phpdocker containing nginx and php-fpm config for it.

- -

Ensure the webserver config on phpdocker/nginx/nginx.conf is correct for your project. PHPDocker.io will have -customised this file according to the front controller location relative to the docker-compose file you chose on the -generator (by default public/index.php).

- -

Note: you may place the files elsewhere in your project. Make sure you modify the locations for the php-fpm dockerfile, -the php.ini overrides and nginx config on docker-compose.yml if you do so.

- -

How to run

- -

Dependencies:

- - - -

Once you're done, simply cd to your project and run docker-compose up -d. This will initialise and start all the -containers, then leave them running in the background.

- -

Services exposed outside your environment

- -

You can access your application via localhost. Mailhog and nginx both respond to any hostname, in case you want to -add your own hostname on your /etc/hosts

- - - - - - - - - - - - - - -
ServiceAddress outside containers
Webserverlocalhost:29000
- -

Hosts within your environment

- -

You'll need to configure your application to use any services you enabled:

- - - - - - - - - - - - - - - - - - - - - -
ServiceHostnamePort number
php-fpmphp-fpm9000
Redisredis6379 (default)
- -

Docker compose cheatsheet

- -

Note: you need to cd first to where your docker-compose.yml file lives.

- -
    -
  • Start containers in the background: docker-compose up -d
  • -
  • Start containers on the foreground: docker-compose up. You will see a stream of logs for every container running. -ctrl+c stops containers.
  • -
  • Stop containers: docker-compose stop
  • -
  • Kill containers: docker-compose kill
  • -
  • View container logs: docker-compose logs for all containers or docker-compose logs SERVICE_NAME for the logs of -all containers in SERVICE_NAME.
  • -
  • Execute command inside of container: docker-compose exec SERVICE_NAME COMMAND where COMMAND is whatever you want -to run. Examples: - -
      -
    • Shell into the PHP container, docker-compose exec php-fpm bash
    • -
    • Run symfony console, docker-compose exec php-fpm bin/console
    • -
    • Open a mysql shell, docker-compose exec mysql mysql -uroot -pCHOSEN_ROOT_PASSWORD
    • -
  • -
- -

Application file permissions

- -

As in all server environments, your application needs the correct file permissions to work properly. You can change the -files throughout the container, so you won't care if the user exists or has the same ID on your host.

- -

docker-compose exec php-fpm chown -R www-data:www-data /application/public

- -

Recommendations

- -

It's hard to avoid file permission issues when fiddling about with containers due to the fact that, from your OS point -of view, any files created within the container are owned by the process that runs the docker engine (this is usually -root). Different OS will also have different problems, for instance you can run stuff in containers -using docker exec -it -u $(id -u):$(id -g) CONTAINER_NAME COMMAND to force your current user ID into the process, but -this will only work if your host OS is Linux, not mac. Follow a couple of simple rules and save yourself a world of -hurt.

- -
    -
  • Run composer outside of the php container, as doing so would install all your dependencies owned by root within your -vendor folder.
  • -
  • Run commands (ie Symfony's console, or Laravel's artisan) straight inside of your container. You can easily open a -shell as described above and do your thing from there.
  • -
- -

Simple basic Xdebug configuration with integration to PHPStorm

- -

Xdebug 2

- -

To configure Xdebug 2 you need add these lines in php-fpm/php-ini-overrides.ini:

- -

For linux:

- -
xdebug.remote_enable = 1
-xdebug.remote_connect_back = 1
-xdebug.remote_autostart = 1
-
- -

For macOS and Windows:

- -
xdebug.remote_enable = 1
-xdebug.remote_host = host.docker.internal
-xdebug.remote_autostart = 1
-
- -

Xdebug 3

- -

To configure Xdebug 3 you need add these lines in php-fpm/php-ini-overrides.ini:

- -

For linux:

- -
xdebug.mode = debug
-xdebug.remote_connect_back = true
-xdebug.start_with_request = yes
-
- -

For macOS and Windows:

- -
xdebug.mode = debug
-xdebug.remote_host = host.docker.internal
-xdebug.start_with_request = yes
-
- -

Add the section “environment” to the php-fpm service in docker-compose.yml:

- -
environment:
-  PHP_IDE_CONFIG: "serverName=Docker"
-
- -

Create a server configuration in PHPStorm:

- -
    -
  • In PHPStorm open Preferences | Languages & Frameworks | PHP | Servers
  • -
  • Add new server
  • -
  • The “Name” field should be the same as the parameter “serverName” value in “environment” in docker-compose.yml (i.e. * -Docker* in the example above)
  • -
  • A value of the "port" field should be the same as first port(before a colon) in "webserver" service in -docker-compose.yml
  • -
  • Select "Use path mappings" and set mappings between a path to your project on a host system and the Docker container.
  • -
  • Finally, add “Xdebug helper” extension in your browser, set breakpoints and start debugging
  • -
-
-
-
- - - - diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/README.md b/resources/tools/dockerwebcontainer/template/phpdocker/README.md deleted file mode 100644 index 9dcfed9c2..000000000 --- a/resources/tools/dockerwebcontainer/template/phpdocker/README.md +++ /dev/null @@ -1,143 +0,0 @@ -PHPDocker.io generated environment -================================== - -# Add to your project # - -Simply, unzip the file into your project, this will create `docker-compose.yml` on the root of your project and a folder -named `phpdocker` containing nginx and php-fpm config for it. - -Ensure the webserver config on `phpdocker/nginx/nginx.conf` is correct for your project. PHPDocker.io will have -customised this file according to the front controller location relative to the docker-compose file you chose on the -generator (by default `public/index.php`). - -Note: you may place the files elsewhere in your project. Make sure you modify the locations for the php-fpm dockerfile, -the php.ini overrides and nginx config on `docker-compose.yml` if you do so. - -# How to run # - -Dependencies: - -* docker. See [https://docs.docker.com/engine/installation](https://docs.docker.com/engine/installation) -* docker-compose. See [docs.docker.com/compose/install](https://docs.docker.com/compose/install/) - -Once you're done, simply `cd` to your project and run `docker-compose up -d`. This will initialise and start all the -containers, then leave them running in the background. - -## Services exposed outside your environment ## - -You can access your application via **`localhost`**. Mailhog and nginx both respond to any hostname, in case you want to -add your own hostname on your `/etc/hosts` - -Service|Address outside containers --------|-------------------------- -Webserver|[localhost:29000](http://localhost:29000) - -## Hosts within your environment ## - -You'll need to configure your application to use any services you enabled: - -Service|Hostname|Port number -------|---------|----------- -php-fpm|php-fpm|9000 -Redis|redis|6379 (default) - -# Docker compose cheatsheet # - -**Note:** you need to cd first to where your docker-compose.yml file lives. - -* Start containers in the background: `docker-compose up -d` -* Start containers on the foreground: `docker-compose up`. You will see a stream of logs for every container running. - ctrl+c stops containers. -* Stop containers: `docker-compose stop` -* Kill containers: `docker-compose kill` -* View container logs: `docker-compose logs` for all containers or `docker-compose logs SERVICE_NAME` for the logs of - all containers in `SERVICE_NAME`. -* Execute command inside of container: `docker-compose exec SERVICE_NAME COMMAND` where `COMMAND` is whatever you want - to run. Examples: - * Shell into the PHP container, `docker-compose exec php-fpm bash` - * Run symfony console, `docker-compose exec php-fpm bin/console` - * Open a mysql shell, `docker-compose exec mysql mysql -uroot -pCHOSEN_ROOT_PASSWORD` - -# Application file permissions # - -As in all server environments, your application needs the correct file permissions to work properly. You can change the -files throughout the container, so you won't care if the user exists or has the same ID on your host. - -`docker-compose exec php-fpm chown -R www-data:www-data /application/public` - -# Recommendations # - -It's hard to avoid file permission issues when fiddling about with containers due to the fact that, from your OS point -of view, any files created within the container are owned by the process that runs the docker engine (this is usually -root). Different OS will also have different problems, for instance you can run stuff in containers -using `docker exec -it -u $(id -u):$(id -g) CONTAINER_NAME COMMAND` to force your current user ID into the process, but -this will only work if your host OS is Linux, not mac. Follow a couple of simple rules and save yourself a world of -hurt. - -* Run composer outside of the php container, as doing so would install all your dependencies owned by `root` within your - vendor folder. -* Run commands (ie Symfony's console, or Laravel's artisan) straight inside of your container. You can easily open a - shell as described above and do your thing from there. - -# Simple basic Xdebug configuration with integration to PHPStorm - -## Xdebug 2 - -To configure **Xdebug 2** you need add these lines in php-fpm/php-ini-overrides.ini: - -### For linux: - -``` -xdebug.remote_enable = 1 -xdebug.remote_connect_back = 1 -xdebug.remote_autostart = 1 -``` - -### For macOS and Windows: - -``` -xdebug.remote_enable = 1 -xdebug.remote_host = host.docker.internal -xdebug.remote_autostart = 1 -``` - -## Xdebug 3 - -To configure **Xdebug 3** you need add these lines in php-fpm/php-ini-overrides.ini: - -### For linux: - -``` -xdebug.mode = debug -xdebug.remote_connect_back = true -xdebug.start_with_request = yes -``` - -### For macOS and Windows: - -``` -xdebug.mode = debug -xdebug.remote_host = host.docker.internal -xdebug.start_with_request = yes -``` - -## Add the section “environment” to the php-fpm service in docker-compose.yml: - -``` -environment: - PHP_IDE_CONFIG: "serverName=Docker" -``` - -### Create a server configuration in PHPStorm: - -* In PHPStorm open Preferences | Languages & Frameworks | PHP | Servers -* Add new server -* The “Name” field should be the same as the parameter “serverName” value in “environment” in docker-compose.yml (i.e. * - Docker* in the example above) -* A value of the "port" field should be the same as first port(before a colon) in "webserver" service in - docker-compose.yml -* Select "Use path mappings" and set mappings between a path to your project on a host system and the Docker container. -* Finally, add “Xdebug helper” extension in your browser, set breakpoints and start debugging - - - diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-ini-overrides.ini b/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-ini-overrides.ini deleted file mode 100644 index bf24fefb3..000000000 --- a/resources/tools/dockerwebcontainer/template/phpdocker/php-5.6-fpm/php-ini-overrides.ini +++ /dev/null @@ -1,2 +0,0 @@ -upload_max_filesize = 2G -post_max_size = 2G diff --git a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/php-ini-overrides.ini b/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/php-ini-overrides.ini deleted file mode 100644 index bf24fefb3..000000000 --- a/resources/tools/dockerwebcontainer/template/phpdocker/php-fpm/php-ini-overrides.ini +++ /dev/null @@ -1,2 +0,0 @@ -upload_max_filesize = 2G -post_max_size = 2G diff --git a/resources/tools/dockerwebcontainer/template/www/index.php b/resources/tools/dockerwebcontainer/template/www/public/index.php similarity index 100% rename from resources/tools/dockerwebcontainer/template/www/index.php rename to resources/tools/dockerwebcontainer/template/www/public/index.php -- 2.39.5