mirror of
https://github.com/jwetzell/docker-guacamole.git
synced 2026-08-20 14:39:07 +00:00
Compare commits
89 Commits
1.3.0
...
1.6.0-20260804
| Author | SHA1 | Date | |
|---|---|---|---|
| f68cb42d2f | |||
| 0046b9f92a | |||
| 56d8f0a882 | |||
| ed49d82733 | |||
| eb2e007d31 | |||
| 9284e7ab3a | |||
| cb52162bfb | |||
| 0e6ea6c206 | |||
| b312a3eace | |||
| b00cb7a9f2 | |||
| 80044f54a7 | |||
| 6f62295c8b | |||
| 07290e82c8 | |||
| ecdf5c8137 | |||
| 7945b12de0 | |||
| ccd2ec594c | |||
| 28b82a68a8 | |||
| 87fd435aac | |||
| d7178feb80 | |||
| 54982f26f3 | |||
| 3cf4b6c741 | |||
| e27dedf9a8 | |||
| 248049dc38 | |||
| 6b8de99ece | |||
| 7adcd7f3dc | |||
| d81299902a | |||
| 4514d2ed93 | |||
| 1dfc348669 | |||
| ce2bc62cf7 | |||
| 4072cf4aeb | |||
| b7b8a81dbc | |||
| 5d81bf648a | |||
| 52d372ae07 | |||
| a4f9da42e2 | |||
| 5c5d7cf74d | |||
| f39270002a | |||
| 4d87d54137 | |||
| 06d7e31ff6 | |||
| 9ef3c98289 | |||
| 79c36610d8 | |||
| eee8901227 | |||
| af02325224 | |||
| 6016e5a3c4 | |||
| bc9058686a | |||
| 661f957c5b | |||
| 1f93e31ab8 | |||
| 3514a84eac | |||
| 3c7acbab48 | |||
| c602be9111 | |||
| 8d1898929f | |||
| 916997c62b | |||
| b65c495492 | |||
| 38f7cf7c41 | |||
| 7fae4045a7 | |||
| 99294c461e | |||
| 255d5c6d0a | |||
| 96a36dcf18 | |||
| 5aeace57a7 | |||
| d6aa86d06f | |||
| 79b8a4a538 | |||
| 19878a35ed | |||
| 4864d3f54c | |||
| aee7baea37 | |||
| a7dfed307d | |||
| cf893c5b32 | |||
| da8a28fc9d | |||
| 8913f805be | |||
| f847b22271 | |||
| a6cec88716 | |||
| d82bbd2dc0 | |||
| 2000eac4f1 | |||
| 42cee1cfd8 | |||
| f2622ce529 | |||
| c17430112e | |||
| 1cca7390a0 | |||
| 969b7e1369 | |||
| c6103f4971 | |||
| 5ce96be0ab | |||
| 017d8ea844 | |||
| 7e8fa4f0e8 | |||
| a0ce971309 | |||
| 114f165d2c | |||
| 6143e1e044 | |||
| 8a190d106d | |||
| b46412052e | |||
| e877512ed0 | |||
| 8b2f15bed6 | |||
| 1980e52002 | |||
| 3188da1ecc |
+1
-2
@@ -1,3 +1,2 @@
|
||||
# These are supported funding model platforms
|
||||
|
||||
custom: https://paypal.me/oznu
|
||||
custom: ['https://paypal.me/JoelWetzell','https://venmo.com/Joel-Wetzell','https://cash.app/$JoelWetzell']
|
||||
|
||||
@@ -1,41 +0,0 @@
|
||||
# Security Policies and Procedures
|
||||
|
||||
This document outlines security procedures and general policies for the `docker-guacamole` project.
|
||||
|
||||
* [Reporting a Bug](#reporting-a-bug)
|
||||
* [Disclosure Policy](#disclosure-policy)
|
||||
* [Comments on this Policy](#comments-on-this-policy)
|
||||
|
||||
## Reporting a Bug
|
||||
|
||||
The `docker-guacamole` team and community take all security bugs in `docker-guacamole`
|
||||
seriously. Thank you for improving the security of `docker-guacamole`. We appreciate
|
||||
your efforts and responsible disclosure and will make every effort to acknowledge
|
||||
your contributions.
|
||||
|
||||
Report security bugs by emailing the maintainer at dev@oz.nu
|
||||
|
||||
The maintainer will acknowledge your email within 48 hours, and will send a
|
||||
more detailed response within 48 hours indicating the next steps in handling
|
||||
your report. After the initial reply to your report, the security team will
|
||||
endeavor to keep you informed of the progress towards a fix and full
|
||||
announcement, and may ask for additional information or guidance.
|
||||
|
||||
Report security bugs in third-party modules to the person or team maintaining
|
||||
the module.
|
||||
|
||||
## Disclosure Policy
|
||||
|
||||
When the security team receives a security bug report, they will assign it to a
|
||||
primary handler. This person will coordinate the fix and release process,
|
||||
involving the following steps:
|
||||
|
||||
* Confirm the problem and determine the affected versions.
|
||||
* Audit code to find any potential similar problems.
|
||||
* Prepare fixes for all releases still under maintenance. These fixes will be
|
||||
released as fast as possible to npm.
|
||||
|
||||
## Comments on this Policy
|
||||
|
||||
If you have suggestions on how this process could be improved please submit a
|
||||
pull request.
|
||||
@@ -0,0 +1,6 @@
|
||||
version: 2
|
||||
updates:
|
||||
- package-ecosystem: 'github-actions'
|
||||
directory: '/'
|
||||
schedule:
|
||||
interval: 'weekly'
|
||||
@@ -1,17 +0,0 @@
|
||||
# Number of days of inactivity before an issue becomes stale
|
||||
daysUntilStale: 30
|
||||
# Number of days of inactivity before a stale issue is closed
|
||||
daysUntilClose: 5
|
||||
# Issues with these labels will never be considered stale
|
||||
exemptLabels:
|
||||
- pinned
|
||||
- security
|
||||
# Label to use when marking an issue as stale
|
||||
staleLabel: stale
|
||||
# Comment to post when marking an issue as stale. Set to `false` to disable
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
# Comment to post when closing a stale issue. Set to `false` to disable
|
||||
closeComment: false
|
||||
@@ -0,0 +1,31 @@
|
||||
name: build-base
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
push:
|
||||
paths:
|
||||
- 'Dockerfile.base'
|
||||
branches:
|
||||
- 'master'
|
||||
jobs:
|
||||
docker:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Build and push
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
push: true
|
||||
file: Dockerfile.base
|
||||
tags: jwetzell/guacamole:base
|
||||
cache-from: type=gha
|
||||
cache-to: type=gha,mode=max
|
||||
platforms: linux/amd64,linux/arm64,linux/arm/v7
|
||||
@@ -0,0 +1,30 @@
|
||||
name: build-latest
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
push:
|
||||
paths:
|
||||
- 'Dockerfile'
|
||||
- 'root/**'
|
||||
|
||||
jobs:
|
||||
docker:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Build and push
|
||||
uses: docker/build-push-action@v5
|
||||
with:
|
||||
push: true
|
||||
tags: jwetzell/guacamole:latest
|
||||
cache-from: type=gha
|
||||
cache-to: type=gha,mode=max
|
||||
platforms: linux/amd64,linux/arm64,linux/arm/v7
|
||||
-42
@@ -1,42 +0,0 @@
|
||||
language: bash
|
||||
|
||||
os: linux
|
||||
|
||||
services:
|
||||
- docker
|
||||
|
||||
matrix:
|
||||
include:
|
||||
# amd64
|
||||
- os: linux
|
||||
arch: amd64
|
||||
env:
|
||||
- DOCKERFILE="Dockerfile"
|
||||
- TAG_SUFFIX="latest"
|
||||
- ALT_SUFFIX="amd64"
|
||||
|
||||
# arm32v5
|
||||
- os: linux
|
||||
arch: arm64
|
||||
env:
|
||||
- DOCKERFILE="Dockerfile.raspberry-pi"
|
||||
- TAG_SUFFIX="arm32v5"
|
||||
- ALT_SUFFIX="armhf"
|
||||
|
||||
script:
|
||||
- export TARGET_IMAGE_TAG=$(if [ "$TRAVIS_BRANCH" = "master" ]; then if [ "$TAG_SUFFIX" = "" ]; then echo "latest"; else echo "$TAG_SUFFIX"; fi; else if [ "$TAG_SUFFIX" = "" ]; then echo "$TRAVIS_BRANCH"; else echo "$TRAVIS_BRANCH-$TAG_SUFFIX"; fi; fi)
|
||||
- docker pull $TARGET_IMAGE:$TARGET_IMAGE_TAG && export IMAGE_CACHE="--cache-from $TARGET_IMAGE:$TARGET_IMAGE_TAG" || export IMAGE_CACHE=""
|
||||
- docker build -f $DOCKERFILE $IMAGE_CACHE -t $TARGET_IMAGE:$TARGET_IMAGE_TAG .
|
||||
- docker login --username $DOCKER_USERNAME --password $DOCKER_PASSWORD
|
||||
- docker push $TARGET_IMAGE:$TARGET_IMAGE_TAG
|
||||
|
||||
# push alternate tags
|
||||
- if [ -z "$ALT_SUFFIX" ]; then
|
||||
echo "No alternate tags set for this build.";
|
||||
else
|
||||
echo "Tagging with alternate tag '$ALT_SUFFIX'";
|
||||
export ALT_IMAGE_TAG=$(if [ "$TRAVIS_BRANCH" = "master" ]; then if [ "$ALT_SUFFIX" = "" ]; then echo "error"; else echo "$ALT_SUFFIX"; fi; else if [ "$ALT_SUFFIX" = "" ]; then echo "$TRAVIS_BRANCH"; else echo "$TRAVIS_BRANCH-$ALT_SUFFIX"; fi; fi);
|
||||
docker tag $TARGET_IMAGE:$TARGET_IMAGE_TAG $TARGET_IMAGE:$ALT_IMAGE_TAG;
|
||||
docker push $TARGET_IMAGE:$ALT_IMAGE_TAG;
|
||||
fi
|
||||
|
||||
+44
-50
@@ -1,73 +1,66 @@
|
||||
FROM library/tomcat:9-jre11
|
||||
|
||||
ENV ARCH=amd64 \
|
||||
GUAC_VER=1.3.0 \
|
||||
GUACAMOLE_HOME=/app/guacamole \
|
||||
PG_MAJOR=9.6 \
|
||||
PGDATA=/config/postgres \
|
||||
POSTGRES_USER=guacamole \
|
||||
POSTGRES_DB=guacamole_db
|
||||
|
||||
# Apply the s6-overlay
|
||||
|
||||
RUN curl -SLO "https://github.com/just-containers/s6-overlay/releases/download/v1.20.0.0/s6-overlay-${ARCH}.tar.gz" \
|
||||
&& tar -xzf s6-overlay-${ARCH}.tar.gz -C / \
|
||||
&& tar -xzf s6-overlay-${ARCH}.tar.gz -C /usr ./bin \
|
||||
&& rm -rf s6-overlay-${ARCH}.tar.gz \
|
||||
&& mkdir -p ${GUACAMOLE_HOME} \
|
||||
${GUACAMOLE_HOME}/lib \
|
||||
${GUACAMOLE_HOME}/extensions
|
||||
FROM jwetzell/guacamole:base
|
||||
|
||||
WORKDIR ${GUACAMOLE_HOME}
|
||||
|
||||
# Install dependencies
|
||||
RUN apt-get update && apt-get install -y \
|
||||
libcairo2-dev libjpeg62-turbo-dev libpng-dev \
|
||||
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
||||
libswscale-dev freerdp2-dev libfreerdp-client2-2 libpango1.0-dev \
|
||||
libssh2-1-dev libtelnet-dev libvncserver-dev \
|
||||
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
||||
ghostscript postgresql-${PG_MAJOR} \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Link FreeRDP to where guac expects it to be
|
||||
RUN [ "$ARCH" = "armhf" ] && ln -s /usr/local/lib/freerdp /usr/lib/arm-linux-gnueabihf/freerdp || exit 0
|
||||
RUN [ "$ARCH" = "amd64" ] && ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
||||
RUN ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
||||
|
||||
# Install guacamole-server
|
||||
RUN curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
||||
&& cd guacamole-server-${GUAC_VER} \
|
||||
&& ./configure --enable-allow-freerdp-snapshots \
|
||||
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
||||
&& make install \
|
||||
&& cd .. \
|
||||
&& rm -rf guacamole-server-${GUAC_VER}.tar.gz guacamole-server-${GUAC_VER} \
|
||||
&& ldconfig
|
||||
|
||||
RUN curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
||||
&& cd guacamole-server-${GUAC_VER} \
|
||||
&& export LDFLAGS="-lrt" \
|
||||
&& ./configure --enable-allow-freerdp-snapshots \
|
||||
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
||||
&& make install \
|
||||
&& cd .. \
|
||||
&& rm -rf guacamole-server-${GUAC_VER}.tar.gz guacamole-server-${GUAC_VER} \
|
||||
&& ldconfig
|
||||
|
||||
# Create directory for extensions
|
||||
RUN mkdir ${GUACAMOLE_HOME}/extensions-available
|
||||
|
||||
# Install guacamole-client and postgres auth adapter
|
||||
RUN set -x \
|
||||
RUN set -xe \
|
||||
&& rm -rf ${CATALINA_HOME}/webapps/ROOT \
|
||||
&& curl -SLo ${CATALINA_HOME}/webapps/ROOT.war "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
||||
&& curl -SLo ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.1.4.jar" \
|
||||
&& curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLo ${CATALINA_HOME}/webapps/ROOT.war "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
||||
&& curl -SLo ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.2.24.jar" \
|
||||
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-auth-jdbc-${GUAC_VER}.tar.gz \
|
||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
||||
&& cp guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/schema ${GUACAMOLE_HOME}/ \
|
||||
&& rm -rf guacamole-auth-jdbc-${GUAC_VER} guacamole-auth-jdbc-${GUAC_VER}.tar.gz
|
||||
|
||||
# add auth-sso to available extensions folder structur differs from other extensions
|
||||
RUN set -xe \
|
||||
&& echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-auth-sso-${GUAC_VER}.tar.gz \
|
||||
&& cp guacamole-auth-sso-${GUAC_VER}/cas/guacamole-auth-sso-cas-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& cp guacamole-auth-sso-${GUAC_VER}/openid/guacamole-auth-sso-openid-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& cp guacamole-auth-sso-${GUAC_VER}/saml/guacamole-auth-sso-saml-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& rm -rf guacamole-auth-sso-${GUAC_VER} guacamole-auth-sso-${GUAC_VER}.tar.gz
|
||||
|
||||
# add vault to available extensions, folder structur differs from other extensions
|
||||
RUN set -xe \
|
||||
&& echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-vault-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-vault-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-vault-${GUAC_VER}.tar.gz \
|
||||
&& cp guacamole-vault-${GUAC_VER}/ksm/guacamole-vault-ksm-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& rm -rf guacamole-vault-${GUAC_VER} guacamole-vault-${GUAC_VER}.tar.gz
|
||||
|
||||
# Add optional extensions
|
||||
RUN set -xe \
|
||||
&& mkdir ${GUACAMOLE_HOME}/extensions-available \
|
||||
&& for i in auth-ldap auth-duo auth-header auth-cas auth-openid auth-quickconnect auth-totp; do \
|
||||
echo "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& for i in auth-ban auth-duo auth-header auth-json auth-ldap auth-quickconnect auth-totp auth-restrict history-recording-storage; do \
|
||||
echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||
&& cp guacamole-${i}-${GUAC_VER}/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& rm -rf guacamole-${i}-${GUAC_VER} guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||
;done
|
||||
|
||||
ENV PATH=/usr/lib/postgresql/${PG_MAJOR}/bin:$PATH
|
||||
ENV PATH="/usr/local/pgsql/bin:$PATH"
|
||||
ENV GUACAMOLE_HOME=/config/guacamole
|
||||
|
||||
WORKDIR /config
|
||||
@@ -77,3 +70,4 @@ COPY root /
|
||||
EXPOSE 8080
|
||||
|
||||
ENTRYPOINT [ "/init" ]
|
||||
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
FROM tomcat:9.0.120-jdk17-temurin-noble
|
||||
ARG TARGETPLATFORM
|
||||
|
||||
ENV GUAC_VER=1.6.0 \
|
||||
GUACAMOLE_HOME=/app/guacamole \
|
||||
PG_VER=9.6.24 \
|
||||
LIBSSH2_VER=1.11.0 \
|
||||
PGDATA=/config/postgres \
|
||||
POSTGRES_USER=guacamole \
|
||||
POSTGRES_DB=guacamole_db
|
||||
|
||||
# Add user for postgres
|
||||
RUN useradd postgres
|
||||
|
||||
# Cleanup default tomcat stuff
|
||||
RUN rm -rf /usr/local/tomcat/webapps.dist
|
||||
|
||||
RUN echo $TARGETPLATFORM
|
||||
|
||||
# Apply the s6-overlay
|
||||
RUN if [ "$TARGETPLATFORM" = "linux/amd64" ]; then ARCHITECTURE=amd64; elif [ "$TARGETPLATFORM" = "linux/arm/v7" ]; then ARCHITECTURE=armhf; elif [ "$TARGETPLATFORM" = "linux/arm/v8" ]; then ARCHITECTURE=aarch64; elif [ "$TARGETPLATFORM" = "linux/arm64" ]; then ARCHITECTURE=aarch64; fi \
|
||||
&& curl -sS -L -O --output-dir /tmp/ --create-dirs "https://github.com/just-containers/s6-overlay/releases/download/v2.2.0.3/s6-overlay-${ARCHITECTURE}-installer" \
|
||||
&& chmod +x /tmp/s6-overlay-${ARCHITECTURE}-installer && /tmp/s6-overlay-${ARCHITECTURE}-installer / \
|
||||
&& rm -rf /tmp/s6-overlay-${ARCHITECTURE}-installer
|
||||
|
||||
# make dirs for guacamole install
|
||||
RUN mkdir -p ${GUACAMOLE_HOME} \
|
||||
${GUACAMOLE_HOME}/lib \
|
||||
${GUACAMOLE_HOME}/extensions
|
||||
|
||||
# Install dependencies
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y curl ca-certificates gnupg \
|
||||
libcairo2-dev libjpeg-turbo8-dev libpng-dev libavformat-dev \
|
||||
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
||||
libswscale-dev freerdp2-dev libpango1.0-dev \
|
||||
libtelnet-dev libvncserver-dev \
|
||||
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
||||
ghostscript build-essential libreadline-dev \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Download libssh2 and postgresql source
|
||||
ADD https://www.libssh2.org/download/libssh2-${LIBSSH2_VER}.tar.gz /tmp
|
||||
ADD https://ftp.postgresql.org/pub/source/v${PG_VER}/postgresql-${PG_VER}.tar.gz /tmp
|
||||
|
||||
|
||||
# Build & install libssh2
|
||||
RUN tar -xzvf /tmp/libssh2-${LIBSSH2_VER}.tar.gz \
|
||||
&& cd libssh2-${LIBSSH2_VER} \
|
||||
&& ./configure \
|
||||
&& make \
|
||||
&& make install \
|
||||
&& rm -rf /tmp/libssh2-${LIBSSH2_VER}*
|
||||
|
||||
# Build & install postgresql
|
||||
RUN tar -xzvf /tmp/postgresql-${PG_VER}.tar.gz \
|
||||
&& cd postgresql-${PG_VER} \
|
||||
&& ./configure \
|
||||
&& make \
|
||||
&& make install \
|
||||
&& rm -rf /tmp/postgresql-${PG_VER}*
|
||||
@@ -1,77 +0,0 @@
|
||||
FROM arm32v5/tomcat:9-jre11
|
||||
|
||||
ENV ARCH=armhf \
|
||||
GUAC_VER=1.3.0 \
|
||||
GUACAMOLE_HOME=/app/guacamole \
|
||||
PG_MAJOR=9.6 \
|
||||
PGDATA=/config/postgres \
|
||||
POSTGRES_USER=guacamole \
|
||||
POSTGRES_DB=guacamole_db
|
||||
|
||||
# Apply the s6-overlay
|
||||
|
||||
RUN curl -SLO "https://github.com/just-containers/s6-overlay/releases/download/v1.20.0.0/s6-overlay-${ARCH}.tar.gz" \
|
||||
&& tar -xzf s6-overlay-${ARCH}.tar.gz -C / \
|
||||
&& tar -xzf s6-overlay-${ARCH}.tar.gz -C /usr ./bin \
|
||||
&& rm -rf s6-overlay-${ARCH}.tar.gz \
|
||||
&& mkdir -p ${GUACAMOLE_HOME} \
|
||||
${GUACAMOLE_HOME}/lib \
|
||||
${GUACAMOLE_HOME}/extensions
|
||||
|
||||
WORKDIR ${GUACAMOLE_HOME}
|
||||
|
||||
# Install dependencies
|
||||
RUN apt-get update && apt-get install -y \
|
||||
libcairo2-dev libjpeg62-turbo-dev libpng-dev \
|
||||
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
||||
libswscale-dev freerdp2-dev libfreerdp-client2-2 libpango1.0-dev \
|
||||
libssh2-1-dev libtelnet-dev libvncserver-dev \
|
||||
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
||||
ghostscript postgresql-${PG_MAJOR} \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Link FreeRDP to where guac expects it to be
|
||||
RUN [ "$ARCH" = "armhf" ] && ln -s /usr/local/lib/freerdp /usr/lib/arm-linux-gnueabihf/freerdp || exit 0
|
||||
RUN [ "$ARCH" = "amd64" ] && ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
||||
|
||||
# Install guacamole-server
|
||||
RUN curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
||||
&& cd guacamole-server-${GUAC_VER} \
|
||||
&& ./configure --enable-allow-freerdp-snapshots \
|
||||
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
||||
&& make install \
|
||||
&& cd .. \
|
||||
&& rm -rf guacamole-server-${GUAC_VER}.tar.gz guacamole-server-${GUAC_VER} \
|
||||
&& ldconfig
|
||||
|
||||
# Install guacamole-client and postgres auth adapter
|
||||
RUN set -x \
|
||||
&& rm -rf ${CATALINA_HOME}/webapps/ROOT \
|
||||
&& curl -SLo ${CATALINA_HOME}/webapps/ROOT.war "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
||||
&& curl -SLo ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.1.4.jar" \
|
||||
&& curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-auth-jdbc-${GUAC_VER}.tar.gz \
|
||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/schema ${GUACAMOLE_HOME}/ \
|
||||
&& rm -rf guacamole-auth-jdbc-${GUAC_VER} guacamole-auth-jdbc-${GUAC_VER}.tar.gz
|
||||
|
||||
# Add optional extensions
|
||||
RUN set -xe \
|
||||
&& mkdir ${GUACAMOLE_HOME}/extensions-available \
|
||||
&& for i in auth-ldap auth-duo auth-header auth-cas auth-openid auth-quickconnect auth-totp; do \
|
||||
echo "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||
&& tar -xzf guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||
&& cp guacamole-${i}-${GUAC_VER}/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||
&& rm -rf guacamole-${i}-${GUAC_VER} guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||
;done
|
||||
|
||||
ENV PATH=/usr/lib/postgresql/${PG_MAJOR}/bin:$PATH
|
||||
ENV GUACAMOLE_HOME=/config/guacamole
|
||||
|
||||
WORKDIR /config
|
||||
|
||||
COPY root /
|
||||
|
||||
ENTRYPOINT [ "/init" ]
|
||||
@@ -1,7 +1,9 @@
|
||||
[](https://hub.docker.com/r/oznu/guacamole/) [](https://travis-ci.org/oznu/docker-guacamole) [](https://hub.docker.com/r/oznu/guacamole/)
|
||||
[ ](https://hub.docker.com/r/jwetzell/guacamole)
|
||||
|
||||
# Docker Guacamole
|
||||
|
||||
**THIS REPO IS A CONTINUATION OF [oznu/docker-guacamole](https://github.com/oznu/docker-guacamole).**
|
||||
|
||||
A Docker Container for [Apache Guacamole](https://guacamole.apache.org/), a client-less remote desktop gateway. It supports standard protocols like VNC, RDP, and SSH over HTML5.
|
||||
|
||||
This image will run on most platforms that support Docker including Docker for Mac, Docker for Windows, Synology DSM and Raspberry Pi 3 boards.
|
||||
@@ -16,18 +18,18 @@ This container runs the guacamole web client, the guacd server and a postgres da
|
||||
docker run \
|
||||
-p 8080:8080 \
|
||||
-v </path/to/config>:/config \
|
||||
oznu/guacamole
|
||||
jwetzell/guacamole:1.6.0-20250711
|
||||
```
|
||||
|
||||
## Raspberry Pi / ARMv6
|
||||
## Raspberry Pi / ARMv7
|
||||
|
||||
This image will also allow you to run [Apache Guacamole](https://guacamole.apache.org/) on a Raspberry Pi or other Docker-enabled ARMv5/6/7/8 devices by using the `armhf` tag.
|
||||
Now that the image has been converted to a multi-platform image the command for Raspberry Pi's or other ARM devices is the same.
|
||||
|
||||
```shell
|
||||
docker run \
|
||||
-p 8080:8080 \
|
||||
-v </path/to/config>:/config \
|
||||
oznu/guacamole:armhf
|
||||
jwetzell/guacamole:1.6.0-20250711
|
||||
```
|
||||
|
||||
## Parameters
|
||||
@@ -49,18 +51,24 @@ docker run \
|
||||
-p 8080:8080 \
|
||||
-v </path/to/config>:/config \
|
||||
-e "EXTENSIONS=auth-ldap,auth-duo"
|
||||
oznu/guacamole
|
||||
jwetzell/guacamole:1.6.0-20250711
|
||||
```
|
||||
|
||||
Currently the available extensions are:
|
||||
|
||||
* auth-ldap - [LDAP Authentication](https://guacamole.apache.org/doc/gug/ldap-auth.html)
|
||||
* auth-ban - [Blocking brute-force attacks](https://guacamole.apache.org/doc/gug/auth-ban.html)
|
||||
* auth-duo - [Duo two-factor authentication](https://guacamole.apache.org/doc/gug/duo-auth.html)
|
||||
* auth-header - [HTTP header authentication](https://guacamole.apache.org/doc/gug/header-auth.html)
|
||||
* auth-cas - [CAS Authentication](https://guacamole.apache.org/doc/gug/cas-auth.html)
|
||||
* auth-openid - [OpenID Connect authentication](https://guacamole.apache.org/doc/gug/openid-auth.html)
|
||||
* auth-totp - [TOTP two-factor authentication](https://guacamole.apache.org/doc/gug/totp-auth.html)
|
||||
* auth-json - [Encrypted JSON Authentication](https://guacamole.apache.org/doc/gug/json-auth.html)
|
||||
* auth-ldap - [LDAP Authentication](https://guacamole.apache.org/doc/gug/ldap-auth.html)
|
||||
* auth-quickconnect - [Ad-hoc connections extension](https://guacamole.apache.org/doc/gug/adhoc-connections.html)
|
||||
* auth-sso-cas - [CAS Authentication](https://guacamole.apache.org/doc/gug/cas-auth.html)
|
||||
* auth-sso-openid - [OpenID Authentication](https://guacamole.apache.org/doc/gug/openid-auth.html)
|
||||
* auth-sso-saml - [SAML Authentication](https://guacamole.apache.org/doc/gug/saml-auth.html)
|
||||
* auth-restrict - [Login / Connection restrictions](https://guacamole.apache.org/doc/gug/auth-restrict.html)
|
||||
* auth-totp - [TOTP two-factor authentication](https://guacamole.apache.org/doc/gug/totp-auth.html)
|
||||
* history-recording-storage - [Session Recording Playback](https://guacamole.apache.org/doc/gug/recording-playback.html#)
|
||||
* vault - [Retrieving secrets from a vault](https://guacamole.apache.org/doc/gug/vault.html)
|
||||
|
||||
You should only enable the extensions you require, if an extensions is not configured correctly in the `guacamole.properties` file it may prevent the system from loading. See the [official documentation](https://guacamole.apache.org/doc/gug/) for more details.
|
||||
|
||||
@@ -76,7 +84,7 @@ Mapped volumes behave differently when running Docker for Windows and you may en
|
||||
version: "2"
|
||||
services:
|
||||
guacamole:
|
||||
image: oznu/guacamole
|
||||
image: jwetzell/guacamole:1.6.0-20250711
|
||||
container_name: guacamole
|
||||
volumes:
|
||||
- postgres:/config
|
||||
@@ -86,11 +94,3 @@ volumes:
|
||||
postgres:
|
||||
driver: local
|
||||
```
|
||||
|
||||
## License
|
||||
|
||||
Copyright (C) 2017-2020 oznu
|
||||
|
||||
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
|
||||
|
||||
This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the [GNU General Public License](./LICENSE) for more details.
|
||||
@@ -1,16 +0,0 @@
|
||||
#!/usr/bin/with-contenv sh
|
||||
|
||||
# clean up extensions
|
||||
for i in auth-ldap auth-duo auth-header auth-cas auth-openid auth-quickconnect auth-totp; do
|
||||
rm -rf ${GUACAMOLE_HOME}/extensions/guacamole-${i}-${GUAC_VER}.jar
|
||||
done
|
||||
|
||||
# if the guacamole version was bumped, delete the contents of the extensions directory - just on the first run
|
||||
if [ "$(cat /config/.database-version)" != "$GUAC_VER" ]; then
|
||||
rm -rf ${GUACAMOLE_HOME}/extensions/*
|
||||
fi
|
||||
|
||||
# enable extensions
|
||||
for i in $(echo "$EXTENSIONS" | tr "," " "); do
|
||||
cp ${GUACAMOLE_HOME}/extensions-available/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions
|
||||
done
|
||||
@@ -0,0 +1,16 @@
|
||||
#!/usr/bin/with-contenv sh
|
||||
|
||||
echo "Cleaning Extensions from previous Guacamole versions"
|
||||
for e in $(ls -1 ${GUACAMOLE_HOME}/extensions | grep guacamole | grep -v ${GUAC_VER}); do
|
||||
rm ${GUACAMOLE_HOME}/extensions/${e}
|
||||
done
|
||||
|
||||
echo "Cleaning Extensions"
|
||||
for i in auth-duo auth-header auth-json auth-ldap auth-quickconnect auth-sso-cas auth-sso-openid auth-sso-saml auth-totp history-recording-storage vault-ksm; do
|
||||
rm -rf ${GUACAMOLE_HOME}/extensions/guacamole-${i}-${GUAC_VER}.jar
|
||||
done
|
||||
|
||||
# enable extensions
|
||||
for i in $(echo "$EXTENSIONS" | tr "," " "); do
|
||||
cp ${GUACAMOLE_HOME}/extensions-available/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions
|
||||
done
|
||||
@@ -14,14 +14,14 @@ if [ $? -ne 0 ]; then
|
||||
echo "$GUAC_VER" > /config/.database-version
|
||||
|
||||
/etc/cont-init.d/30-defaults.sh
|
||||
/etc/cont-init.d/50-extensions
|
||||
/etc/cont-init.d/50-extensions.sh
|
||||
else
|
||||
if [ "$(cat /config/.database-version)" != "$GUAC_VER" ]; then
|
||||
cat /app/guacamole/schema/upgrade/upgrade-pre-$GUAC_VER.sql | psql -U $POSTGRES_USER -d $POSTGRES_DB -f -
|
||||
echo "$GUAC_VER" > /config/.database-version
|
||||
|
||||
/etc/cont-init.d/30-defaults.sh
|
||||
/etc/cont-init.d/50-extensions
|
||||
/etc/cont-init.d/50-extensions.sh
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
#!/usr/bin/with-contenv sh
|
||||
|
||||
echo "Starting guacamole guacd..."
|
||||
s6-setuidgid root guacd -f
|
||||
s6-setuidgid root guacd -f -b 127.0.0.1
|
||||
|
||||
Reference in New Issue
Block a user