mirror of
https://github.com/jwetzell/docker-guacamole.git
synced 2026-08-20 14:39:07 +00:00
Compare commits
43 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| d81299902a | |||
| 4514d2ed93 | |||
| 1dfc348669 | |||
| ce2bc62cf7 | |||
| 4072cf4aeb | |||
| b7b8a81dbc | |||
| 5d81bf648a | |||
| 52d372ae07 | |||
| a4f9da42e2 | |||
| 5c5d7cf74d | |||
| f39270002a | |||
| 4d87d54137 | |||
| 06d7e31ff6 | |||
| 9ef3c98289 | |||
| 79c36610d8 | |||
| eee8901227 | |||
| af02325224 | |||
| 6016e5a3c4 | |||
| bc9058686a | |||
| 661f957c5b | |||
| 1f93e31ab8 | |||
| 3514a84eac | |||
| 3c7acbab48 | |||
| c602be9111 | |||
| 8d1898929f | |||
| 916997c62b | |||
| b65c495492 | |||
| 38f7cf7c41 | |||
| 7fae4045a7 | |||
| 99294c461e | |||
| 255d5c6d0a | |||
| 96a36dcf18 | |||
| 5aeace57a7 | |||
| d6aa86d06f | |||
| 79b8a4a538 | |||
| 19878a35ed | |||
| 4864d3f54c | |||
| aee7baea37 | |||
| a7dfed307d | |||
| cf893c5b32 | |||
| da8a28fc9d | |||
| 8913f805be | |||
| f847b22271 |
+1
-2
@@ -1,3 +1,2 @@
|
|||||||
# These are supported funding model platforms
|
# These are supported funding model platforms
|
||||||
|
custom: ['https://paypal.me/JoelWetzell','https://venmo.com/Joel-Wetzell','https://cash.app/$JoelWetzell']
|
||||||
custom: https://paypal.me/oznu
|
|
||||||
|
|||||||
@@ -1,41 +0,0 @@
|
|||||||
# Security Policies and Procedures
|
|
||||||
|
|
||||||
This document outlines security procedures and general policies for the `docker-guacamole` project.
|
|
||||||
|
|
||||||
* [Reporting a Bug](#reporting-a-bug)
|
|
||||||
* [Disclosure Policy](#disclosure-policy)
|
|
||||||
* [Comments on this Policy](#comments-on-this-policy)
|
|
||||||
|
|
||||||
## Reporting a Bug
|
|
||||||
|
|
||||||
The `docker-guacamole` team and community take all security bugs in `docker-guacamole`
|
|
||||||
seriously. Thank you for improving the security of `docker-guacamole`. We appreciate
|
|
||||||
your efforts and responsible disclosure and will make every effort to acknowledge
|
|
||||||
your contributions.
|
|
||||||
|
|
||||||
Report security bugs by emailing the maintainer at dev@oz.nu
|
|
||||||
|
|
||||||
The maintainer will acknowledge your email within 48 hours, and will send a
|
|
||||||
more detailed response within 48 hours indicating the next steps in handling
|
|
||||||
your report. After the initial reply to your report, the security team will
|
|
||||||
endeavor to keep you informed of the progress towards a fix and full
|
|
||||||
announcement, and may ask for additional information or guidance.
|
|
||||||
|
|
||||||
Report security bugs in third-party modules to the person or team maintaining
|
|
||||||
the module.
|
|
||||||
|
|
||||||
## Disclosure Policy
|
|
||||||
|
|
||||||
When the security team receives a security bug report, they will assign it to a
|
|
||||||
primary handler. This person will coordinate the fix and release process,
|
|
||||||
involving the following steps:
|
|
||||||
|
|
||||||
* Confirm the problem and determine the affected versions.
|
|
||||||
* Audit code to find any potential similar problems.
|
|
||||||
* Prepare fixes for all releases still under maintenance. These fixes will be
|
|
||||||
released as fast as possible to npm.
|
|
||||||
|
|
||||||
## Comments on this Policy
|
|
||||||
|
|
||||||
If you have suggestions on how this process could be improved please submit a
|
|
||||||
pull request.
|
|
||||||
@@ -0,0 +1,29 @@
|
|||||||
|
name: build-base
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
push:
|
||||||
|
paths:
|
||||||
|
- 'Dockerfile.base'
|
||||||
|
jobs:
|
||||||
|
docker:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Set up QEMU
|
||||||
|
uses: docker/setup-qemu-action@v3
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
uses: docker/setup-buildx-action@v3
|
||||||
|
- name: Login to Docker Hub
|
||||||
|
uses: docker/login-action@v3
|
||||||
|
with:
|
||||||
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
- name: Build and push
|
||||||
|
uses: docker/build-push-action@v5
|
||||||
|
with:
|
||||||
|
push: true
|
||||||
|
file: Dockerfile.base
|
||||||
|
tags: jwetzell/guacamole:base
|
||||||
|
cache-from: type=gha
|
||||||
|
cache-to: type=gha,mode=max
|
||||||
|
platforms: linux/amd64,linux/arm64,linux/arm/v7
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
name: build-latest
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
push:
|
||||||
|
paths:
|
||||||
|
- 'Dockerfile'
|
||||||
|
- 'root/**'
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
docker:
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- name: Set up QEMU
|
||||||
|
uses: docker/setup-qemu-action@v3
|
||||||
|
- name: Set up Docker Buildx
|
||||||
|
uses: docker/setup-buildx-action@v3
|
||||||
|
- name: Login to Docker Hub
|
||||||
|
uses: docker/login-action@v3
|
||||||
|
with:
|
||||||
|
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||||
|
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||||
|
- name: Build and push
|
||||||
|
uses: docker/build-push-action@v5
|
||||||
|
with:
|
||||||
|
push: true
|
||||||
|
tags: jwetzell/guacamole:latest
|
||||||
|
cache-from: type=gha
|
||||||
|
cache-to: type=gha,mode=max
|
||||||
|
platforms: linux/amd64,linux/arm64,linux/arm/v7
|
||||||
-42
@@ -1,42 +0,0 @@
|
|||||||
language: bash
|
|
||||||
|
|
||||||
os: linux
|
|
||||||
|
|
||||||
services:
|
|
||||||
- docker
|
|
||||||
|
|
||||||
matrix:
|
|
||||||
include:
|
|
||||||
# amd64
|
|
||||||
- os: linux
|
|
||||||
arch: amd64
|
|
||||||
env:
|
|
||||||
- DOCKERFILE="Dockerfile"
|
|
||||||
- TAG_SUFFIX="latest"
|
|
||||||
- ALT_SUFFIX="amd64"
|
|
||||||
|
|
||||||
# arm32v5
|
|
||||||
- os: linux
|
|
||||||
arch: arm64
|
|
||||||
env:
|
|
||||||
- DOCKERFILE="Dockerfile.raspberry-pi"
|
|
||||||
- TAG_SUFFIX="arm32v5"
|
|
||||||
- ALT_SUFFIX="armhf"
|
|
||||||
|
|
||||||
script:
|
|
||||||
- export TARGET_IMAGE_TAG=$(if [ "$TRAVIS_BRANCH" = "master" ]; then if [ "$TAG_SUFFIX" = "" ]; then echo "latest"; else echo "$TAG_SUFFIX"; fi; else if [ "$TAG_SUFFIX" = "" ]; then echo "$TRAVIS_BRANCH"; else echo "$TRAVIS_BRANCH-$TAG_SUFFIX"; fi; fi)
|
|
||||||
- docker pull $TARGET_IMAGE:$TARGET_IMAGE_TAG && export IMAGE_CACHE="--cache-from $TARGET_IMAGE:$TARGET_IMAGE_TAG" || export IMAGE_CACHE=""
|
|
||||||
- docker build -f $DOCKERFILE $IMAGE_CACHE -t $TARGET_IMAGE:$TARGET_IMAGE_TAG .
|
|
||||||
- docker login --username $DOCKER_USERNAME --password $DOCKER_PASSWORD
|
|
||||||
- docker push $TARGET_IMAGE:$TARGET_IMAGE_TAG
|
|
||||||
|
|
||||||
# push alternate tags
|
|
||||||
- if [ -z "$ALT_SUFFIX" ]; then
|
|
||||||
echo "No alternate tags set for this build.";
|
|
||||||
else
|
|
||||||
echo "Tagging with alternate tag '$ALT_SUFFIX'";
|
|
||||||
export ALT_IMAGE_TAG=$(if [ "$TRAVIS_BRANCH" = "master" ]; then if [ "$ALT_SUFFIX" = "" ]; then echo "error"; else echo "$ALT_SUFFIX"; fi; else if [ "$ALT_SUFFIX" = "" ]; then echo "$TRAVIS_BRANCH"; else echo "$TRAVIS_BRANCH-$ALT_SUFFIX"; fi; fi);
|
|
||||||
docker tag $TARGET_IMAGE:$TARGET_IMAGE_TAG $TARGET_IMAGE:$ALT_IMAGE_TAG;
|
|
||||||
docker push $TARGET_IMAGE:$ALT_IMAGE_TAG;
|
|
||||||
fi
|
|
||||||
|
|
||||||
+23
-53
@@ -1,51 +1,16 @@
|
|||||||
FROM library/tomcat:9-jre11-openjdk-bullseye
|
FROM jwetzell/guacamole:base
|
||||||
|
|
||||||
ENV ARCH=amd64 \
|
|
||||||
GUAC_VER=1.4.0 \
|
|
||||||
GUACAMOLE_HOME=/app/guacamole \
|
|
||||||
PG_MAJOR=9.6 \
|
|
||||||
PGDATA=/config/postgres \
|
|
||||||
POSTGRES_USER=guacamole \
|
|
||||||
POSTGRES_DB=guacamole_db
|
|
||||||
|
|
||||||
# Add Postgres Repository
|
|
||||||
RUN echo "deb http://apt.postgresql.org/pub/repos/apt/ bullseye-pgdg main" >> /etc/apt/sources.list.d/pgdg.list && \
|
|
||||||
wget -q https://www.postgresql.org/media/keys/ACCC4CF8.asc -O - | apt-key add -
|
|
||||||
|
|
||||||
# Install dependencies
|
|
||||||
RUN apt-get update \
|
|
||||||
&& apt-get install -y \
|
|
||||||
libcairo2-dev libjpeg62-turbo-dev libpng-dev \
|
|
||||||
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
|
||||||
libswscale-dev freerdp2-dev libfreerdp-client2-2 libpango1.0-dev \
|
|
||||||
libssh2-1-dev libtelnet-dev libvncserver-dev \
|
|
||||||
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
|
||||||
ghostscript build-essential postgresql-${PG_MAJOR} \
|
|
||||||
&& rm -rf /var/lib/apt/lists/*
|
|
||||||
|
|
||||||
|
|
||||||
# Apply the s6-overlay
|
|
||||||
ADD https://github.com/just-containers/s6-overlay/releases/download/v2.2.0.3/s6-overlay-${ARCH}.tar.gz /tmp
|
|
||||||
RUN tar -xzf /tmp/s6-overlay-${ARCH}.tar.gz -C / \
|
|
||||||
&& tar -xzf /tmp/s6-overlay-${ARCH}.tar.gz -C /usr ./bin \
|
|
||||||
&& rm -rf /tmp/s6-overlay-${ARCH}.tar.gz
|
|
||||||
|
|
||||||
RUN mkdir -p ${GUACAMOLE_HOME} \
|
|
||||||
${GUACAMOLE_HOME}/lib \
|
|
||||||
${GUACAMOLE_HOME}/extensions
|
|
||||||
|
|
||||||
WORKDIR ${GUACAMOLE_HOME}
|
WORKDIR ${GUACAMOLE_HOME}
|
||||||
|
|
||||||
# Link FreeRDP to where guac expects it to be
|
# Link FreeRDP to where guac expects it to be
|
||||||
RUN [ "$ARCH" = "armhf" ] && ln -s /usr/local/lib/freerdp /usr/lib/arm-linux-gnueabihf/freerdp || exit 0
|
RUN ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
||||||
RUN [ "$ARCH" = "amd64" ] && ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
|
||||||
|
|
||||||
RUN echo $PATH
|
|
||||||
|
|
||||||
# Install guacamole-server
|
# Install guacamole-server
|
||||||
RUN curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
|
||||||
|
RUN curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
||||||
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
||||||
&& cd guacamole-server-${GUAC_VER} \
|
&& cd guacamole-server-${GUAC_VER} \
|
||||||
|
&& export LDFLAGS="-lrt" \
|
||||||
&& ./configure --enable-allow-freerdp-snapshots \
|
&& ./configure --enable-allow-freerdp-snapshots \
|
||||||
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
||||||
&& make install \
|
&& make install \
|
||||||
@@ -57,41 +22,45 @@ RUN curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamo
|
|||||||
RUN mkdir ${GUACAMOLE_HOME}/extensions-available
|
RUN mkdir ${GUACAMOLE_HOME}/extensions-available
|
||||||
|
|
||||||
# Install guacamole-client and postgres auth adapter
|
# Install guacamole-client and postgres auth adapter
|
||||||
RUN set -x \
|
RUN set -xe \
|
||||||
&& rm -rf ${CATALINA_HOME}/webapps/ROOT \
|
&& rm -rf ${CATALINA_HOME}/webapps/ROOT \
|
||||||
&& curl -SLo ${CATALINA_HOME}/webapps/ROOT.war "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
&& curl -SLo ${CATALINA_HOME}/webapps/ROOT.war "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
||||||
&& curl -SLo ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.2.24.jar" \
|
&& curl -SLo ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.2.24.jar" \
|
||||||
&& curl -SLO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
||||||
&& tar -xzf guacamole-auth-jdbc-${GUAC_VER}.tar.gz \
|
&& tar -xzf guacamole-auth-jdbc-${GUAC_VER}.tar.gz \
|
||||||
&& cp guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
&& cp guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
||||||
&& cp guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
|
||||||
&& cp guacamole-auth-jdbc-${GUAC_VER}/mysql/guacamole-auth-jdbc-mysql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
|
||||||
&& cp guacamole-auth-jdbc-${GUAC_VER}/sqlserver/guacamole-auth-jdbc-sqlserver-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
|
||||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/schema ${GUACAMOLE_HOME}/ \
|
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/schema ${GUACAMOLE_HOME}/ \
|
||||||
&& rm -rf guacamole-auth-jdbc-${GUAC_VER} guacamole-auth-jdbc-${GUAC_VER}.tar.gz
|
&& rm -rf guacamole-auth-jdbc-${GUAC_VER} guacamole-auth-jdbc-${GUAC_VER}.tar.gz
|
||||||
|
|
||||||
|
# add auth-sso to available extensions folder structur differs from other extensions
|
||||||
RUN set -xe \
|
RUN set -xe \
|
||||||
&& echo "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
&& echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
||||||
&& curl -SLO "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-auth-sso-${GUAC_VER}.tar.gz" \
|
||||||
&& tar -xzf guacamole-auth-sso-${GUAC_VER}.tar.gz \
|
&& tar -xzf guacamole-auth-sso-${GUAC_VER}.tar.gz \
|
||||||
&& cp guacamole-auth-sso-${GUAC_VER}/cas/guacamole-auth-sso-cas-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
&& cp guacamole-auth-sso-${GUAC_VER}/cas/guacamole-auth-sso-cas-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||||
&& cp guacamole-auth-sso-${GUAC_VER}/openid/guacamole-auth-sso-openid-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
&& cp guacamole-auth-sso-${GUAC_VER}/openid/guacamole-auth-sso-openid-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||||
&& cp guacamole-auth-sso-${GUAC_VER}/saml/guacamole-auth-sso-saml-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
&& cp guacamole-auth-sso-${GUAC_VER}/saml/guacamole-auth-sso-saml-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||||
&& rm -rf guacamole-auth-sso-${GUAC_VER} guacamole-auth-sso-${GUAC_VER}.tar.gz
|
&& rm -rf guacamole-auth-sso-${GUAC_VER} guacamole-auth-sso-${GUAC_VER}.tar.gz
|
||||||
|
|
||||||
|
# add vault to available extensions, folder structur differs from other extensions
|
||||||
|
RUN set -xe \
|
||||||
|
&& echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-vault-${GUAC_VER}.tar.gz" \
|
||||||
|
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-vault-${GUAC_VER}.tar.gz" \
|
||||||
|
&& tar -xzf guacamole-vault-${GUAC_VER}.tar.gz \
|
||||||
|
&& cp guacamole-vault-${GUAC_VER}/ksm/guacamole-vault-ksm-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||||
|
&& rm -rf guacamole-vault-${GUAC_VER} guacamole-vault-${GUAC_VER}.tar.gz
|
||||||
|
|
||||||
# Add optional extensions
|
# Add optional extensions
|
||||||
RUN set -xe \
|
RUN set -xe \
|
||||||
&& for i in auth-duo auth-header auth-json auth-ldap auth-quickconnect auth-totp; do \
|
&& for i in auth-duo auth-header auth-json auth-ldap auth-quickconnect auth-totp history-recording-storage; do \
|
||||||
echo "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
echo "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||||
&& curl -SLO "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
&& curl -SLO "https://archive.apache.org/dist/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
||||||
&& tar -xzf guacamole-${i}-${GUAC_VER}.tar.gz \
|
&& tar -xzf guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||||
&& cp guacamole-${i}-${GUAC_VER}/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
&& cp guacamole-${i}-${GUAC_VER}/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
||||||
&& rm -rf guacamole-${i}-${GUAC_VER} guacamole-${i}-${GUAC_VER}.tar.gz \
|
&& rm -rf guacamole-${i}-${GUAC_VER} guacamole-${i}-${GUAC_VER}.tar.gz \
|
||||||
;done
|
;done
|
||||||
|
|
||||||
ENV PATH=/usr/lib/postgresql/${PG_MAJOR}/bin:$PATH
|
ENV PATH="/usr/local/pgsql/bin:$PATH"
|
||||||
ENV GUACAMOLE_HOME=/config/guacamole
|
ENV GUACAMOLE_HOME=/config/guacamole
|
||||||
|
|
||||||
WORKDIR /config
|
WORKDIR /config
|
||||||
@@ -101,3 +70,4 @@ COPY root /
|
|||||||
EXPOSE 8080
|
EXPOSE 8080
|
||||||
|
|
||||||
ENTRYPOINT [ "/init" ]
|
ENTRYPOINT [ "/init" ]
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,60 @@
|
|||||||
|
FROM tomcat:9.0.85-jre11
|
||||||
|
|
||||||
|
ENV GUAC_VER=1.5.5 \
|
||||||
|
GUACAMOLE_HOME=/app/guacamole \
|
||||||
|
PG_VER=9.6.24 \
|
||||||
|
LIBSSH2_VER=1.11.0 \
|
||||||
|
PGDATA=/config/postgres \
|
||||||
|
POSTGRES_USER=guacamole \
|
||||||
|
POSTGRES_DB=guacamole_db
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# Add user for postgres
|
||||||
|
RUN useradd postgres
|
||||||
|
|
||||||
|
# Cleanup default tomcat stuff
|
||||||
|
RUN rm -rf /usr/local/tomcat/webapps.dist
|
||||||
|
|
||||||
|
# Apply the s6-overlay
|
||||||
|
RUN if [ "$TARGETPLATFORM" = "linux/amd64" ]; then ARCHITECTURE=amd64; elif [ "$TARGETPLATFORM" = "linux/arm/v7" ]; then ARCHITECTURE=arm; elif [ "$TARGETPLATFORM" = "linux/arm64" ]; then ARCHITECTURE=aarch64; else ARCHITECTURE=amd64; fi \
|
||||||
|
&& curl -sS -L -O --output-dir /tmp/ --create-dirs "https://github.com/just-containers/s6-overlay/releases/download/v2.2.0.3/s6-overlay-${ARCHITECTURE}-installer" \
|
||||||
|
&& chmod +x /tmp/s6-overlay-${ARCHITECTURE}-installer && /tmp/s6-overlay-${ARCHITECTURE}-installer / \
|
||||||
|
&& rm -rf /tmp/s6-overlay-${ARCHITECTURE}-installer
|
||||||
|
|
||||||
|
# make dirs for guacamole install
|
||||||
|
RUN mkdir -p ${GUACAMOLE_HOME} \
|
||||||
|
${GUACAMOLE_HOME}/lib \
|
||||||
|
${GUACAMOLE_HOME}/extensions
|
||||||
|
|
||||||
|
# Install dependencies
|
||||||
|
RUN apt-get update \
|
||||||
|
&& apt-get install -y curl ca-certificates gnupg \
|
||||||
|
libcairo2-dev libjpeg-turbo8-dev libpng-dev libavformat-dev \
|
||||||
|
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
||||||
|
libswscale-dev freerdp2-dev libfreerdp-client2-2 libpango1.0-dev \
|
||||||
|
libtelnet-dev libvncserver-dev \
|
||||||
|
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
||||||
|
ghostscript build-essential libreadline-dev \
|
||||||
|
&& rm -rf /var/lib/apt/lists/*
|
||||||
|
|
||||||
|
# Download libssh2 and postgresql source
|
||||||
|
ADD https://www.libssh2.org/download/libssh2-${LIBSSH2_VER}.tar.gz /tmp
|
||||||
|
ADD https://ftp.postgresql.org/pub/source/v${PG_VER}/postgresql-${PG_VER}.tar.gz /tmp
|
||||||
|
|
||||||
|
|
||||||
|
# Build & install libssh2
|
||||||
|
RUN tar -xzvf /tmp/libssh2-${LIBSSH2_VER}.tar.gz \
|
||||||
|
&& cd libssh2-${LIBSSH2_VER} \
|
||||||
|
&& ./configure \
|
||||||
|
&& make \
|
||||||
|
&& make install \
|
||||||
|
&& rm -rf /tmp/libssh2-${LIBSSH2_VER}*
|
||||||
|
|
||||||
|
# Build & install postgresql
|
||||||
|
RUN tar -xzvf /tmp/postgresql-${PG_VER}.tar.gz \
|
||||||
|
&& cd postgresql-${PG_VER} \
|
||||||
|
&& ./configure \
|
||||||
|
&& make \
|
||||||
|
&& make install \
|
||||||
|
&& rm -rf /tmp/postgresql-${PG_VER}*
|
||||||
@@ -1,80 +0,0 @@
|
|||||||
FROM arm32v7/tomcat:9-jre11
|
|
||||||
|
|
||||||
ENV ARCH=armhf \
|
|
||||||
GUAC_VER=1.4.0 \
|
|
||||||
GUACAMOLE_HOME=/app/guacamole \
|
|
||||||
PG_MAJOR=9.6 \
|
|
||||||
PGDATA=/config/postgres \
|
|
||||||
POSTGRES_USER=guacamole \
|
|
||||||
POSTGRES_DB=guacamole_db
|
|
||||||
|
|
||||||
# Install base dependencies
|
|
||||||
RUN apt-get update \
|
|
||||||
&& apt-get install -y --allow-unauthenticated \
|
|
||||||
libcairo2-dev libjpeg62-turbo-dev libpng-dev \
|
|
||||||
libossp-uuid-dev libavcodec-dev libavutil-dev \
|
|
||||||
libswscale-dev freerdp2-dev libfreerdp-client2-2 libpango1.0-dev \
|
|
||||||
libssh2-1-dev libtelnet-dev libvncserver-dev \
|
|
||||||
libpulse-dev libssl-dev libvorbis-dev libwebp-dev libwebsockets-dev \
|
|
||||||
ghostscript
|
|
||||||
|
|
||||||
# Install Postgres
|
|
||||||
RUN apt-get install -y postgresql-${PG_MAJOR}
|
|
||||||
|
|
||||||
# Apply the s6-overlay
|
|
||||||
ADD https://github.com/just-containers/s6-overlay/releases/download/v2.2.0.3/s6-overlay-${ARCH}.tar.gz /tmp
|
|
||||||
RUN tar -xzf /tmp/s6-overlay-${ARCH}.tar.gz -C / \
|
|
||||||
&& tar -xzf /tmp/s6-overlay-${ARCH}.tar.gz -C /usr ./bin \
|
|
||||||
&& rm -rf /tmp/s6-overlay-${ARCH}.tar.gz
|
|
||||||
|
|
||||||
RUN mkdir -p ${GUACAMOLE_HOME} \
|
|
||||||
${GUACAMOLE_HOME}/lib \
|
|
||||||
${GUACAMOLE_HOME}/extensions
|
|
||||||
|
|
||||||
WORKDIR ${GUACAMOLE_HOME}
|
|
||||||
|
|
||||||
# Link FreeRDP to where guac expects it to be
|
|
||||||
RUN [ "$ARCH" = "armhf" ] && ln -s /usr/local/lib/freerdp /usr/lib/arm-linux-gnueabihf/freerdp || exit 0
|
|
||||||
RUN [ "$ARCH" = "amd64" ] && ln -s /usr/local/lib/freerdp /usr/lib/x86_64-linux-gnu/freerdp || exit 0
|
|
||||||
|
|
||||||
# Install guacamole-server
|
|
||||||
RUN curl -SLOk "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/source/guacamole-server-${GUAC_VER}.tar.gz" \
|
|
||||||
&& tar -xzf guacamole-server-${GUAC_VER}.tar.gz \
|
|
||||||
&& cd guacamole-server-${GUAC_VER} \
|
|
||||||
&& ./configure --enable-allow-freerdp-snapshots \
|
|
||||||
&& make -j$(getconf _NPROCESSORS_ONLN) \
|
|
||||||
&& make install \
|
|
||||||
&& cd .. \
|
|
||||||
&& rm -rf guacamole-server-${GUAC_VER}.tar.gz guacamole-server-${GUAC_VER} \
|
|
||||||
&& ldconfig
|
|
||||||
|
|
||||||
# Install guacamole-client and postgres auth adapter
|
|
||||||
RUN set -x \
|
|
||||||
&& rm -rf ${CATALINA_HOME}/webapps/ROOT \
|
|
||||||
&& curl -SLko ${CATALINA_HOME}/webapps/ROOT.war "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-${GUAC_VER}.war" \
|
|
||||||
&& curl -SLko ${GUACAMOLE_HOME}/lib/postgresql-42.1.4.jar "https://jdbc.postgresql.org/download/postgresql-42.2.24.jar" \
|
|
||||||
&& curl -SLkO "http://apache.org/dyn/closer.cgi?action=download&filename=guacamole/${GUAC_VER}/binary/guacamole-auth-jdbc-${GUAC_VER}.tar.gz" \
|
|
||||||
&& tar -xzf guacamole-auth-jdbc-${GUAC_VER}.tar.gz \
|
|
||||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/guacamole-auth-jdbc-postgresql-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions/ \
|
|
||||||
&& cp -R guacamole-auth-jdbc-${GUAC_VER}/postgresql/schema ${GUACAMOLE_HOME}/ \
|
|
||||||
&& rm -rf guacamole-auth-jdbc-${GUAC_VER} guacamole-auth-jdbc-${GUAC_VER}.tar.gz
|
|
||||||
|
|
||||||
# Add optional extensions
|
|
||||||
RUN set -xe \
|
|
||||||
&& mkdir ${GUACAMOLE_HOME}/extensions-available \
|
|
||||||
&& for i in auth-ldap auth-duo auth-header auth-cas auth-openid auth-quickconnect auth-totp; do \
|
|
||||||
echo "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
|
||||||
&& curl -SLOk "https://dlcdn.apache.org/guacamole/${GUAC_VER}/binary/guacamole-${i}-${GUAC_VER}.tar.gz" \
|
|
||||||
&& tar -xzf guacamole-${i}-${GUAC_VER}.tar.gz \
|
|
||||||
&& cp guacamole-${i}-${GUAC_VER}/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions-available/ \
|
|
||||||
&& rm -rf guacamole-${i}-${GUAC_VER} guacamole-${i}-${GUAC_VER}.tar.gz \
|
|
||||||
;done
|
|
||||||
|
|
||||||
ENV PATH=/usr/lib/postgresql/${PG_MAJOR}/bin:$PATH
|
|
||||||
ENV GUACAMOLE_HOME=/config/guacamole
|
|
||||||
|
|
||||||
WORKDIR /config
|
|
||||||
|
|
||||||
COPY root /
|
|
||||||
|
|
||||||
ENTRYPOINT [ "/init" ]
|
|
||||||
@@ -23,13 +23,13 @@ docker run \
|
|||||||
|
|
||||||
## Raspberry Pi / ARMv7
|
## Raspberry Pi / ARMv7
|
||||||
|
|
||||||
This image will also allow you to run [Apache Guacamole](https://guacamole.apache.org/) on a Raspberry Pi or other Docker-enabled ARMv5/6/7/8 devices by using the `arm32v7` tag.
|
Now that the image has been converted to a multi-platform image the command for Raspberry Pi's or other ARM devices is the same.
|
||||||
|
|
||||||
```shell
|
```shell
|
||||||
docker run \
|
docker run \
|
||||||
-p 8080:8080 \
|
-p 8080:8080 \
|
||||||
-v </path/to/config>:/config \
|
-v </path/to/config>:/config \
|
||||||
jwetzell/guacamole:arm32v7
|
jwetzell/guacamole
|
||||||
```
|
```
|
||||||
|
|
||||||
## Parameters
|
## Parameters
|
||||||
@@ -56,13 +56,20 @@ docker run \
|
|||||||
|
|
||||||
Currently the available extensions are:
|
Currently the available extensions are:
|
||||||
|
|
||||||
* auth-ldap - [LDAP Authentication](https://guacamole.apache.org/doc/gug/ldap-auth.html)
|
|
||||||
* auth-duo - [Duo two-factor authentication](https://guacamole.apache.org/doc/gug/duo-auth.html)
|
* auth-duo - [Duo two-factor authentication](https://guacamole.apache.org/doc/gug/duo-auth.html)
|
||||||
* auth-header - [HTTP header authentication](https://guacamole.apache.org/doc/gug/header-auth.html)
|
* auth-header - [HTTP header authentication](https://guacamole.apache.org/doc/gug/header-auth.html)
|
||||||
* auth-cas - [CAS Authentication](https://guacamole.apache.org/doc/gug/cas-auth.html)
|
* auth-jdbc-mysql - [MySQL Authentication](https://guacamole.apache.org/doc/gug/jdbc-auth.html)
|
||||||
* auth-openid - [OpenID Connect authentication](https://guacamole.apache.org/doc/gug/openid-auth.html)
|
* auth-jdbc-postgresql - [PostgreSQL Authentication](https://guacamole.apache.org/doc/gug/jdbc-auth.html)
|
||||||
* auth-totp - [TOTP two-factor authentication](https://guacamole.apache.org/doc/gug/totp-auth.html)
|
* auth-jdbc-sqlserver - [SQL Server Authentication](https://guacamole.apache.org/doc/gug/jdbc-auth.html)
|
||||||
|
* auth-json - [Encrypted JSON Authentication](https://guacamole.apache.org/doc/gug/json-auth.html)
|
||||||
|
* auth-ldap - [LDAP Authentication](https://guacamole.apache.org/doc/gug/ldap-auth.html)
|
||||||
* auth-quickconnect - [Ad-hoc connections extension](https://guacamole.apache.org/doc/gug/adhoc-connections.html)
|
* auth-quickconnect - [Ad-hoc connections extension](https://guacamole.apache.org/doc/gug/adhoc-connections.html)
|
||||||
|
* auth-sso-cas - [CAS Authentication](https://guacamole.apache.org/doc/gug/cas-auth.html)
|
||||||
|
* auth-sso-openid - [OpenID Authentication](https://guacamole.apache.org/doc/gug/openid-auth.html)
|
||||||
|
* auth-sso-saml - [SAML Authentication](https://guacamole.apache.org/doc/gug/saml-auth.html)
|
||||||
|
* auth-totp - [TOTP two-factor authentication](https://guacamole.apache.org/doc/gug/totp-auth.html)
|
||||||
|
* history-recording-storage - [Session Recording Playback](https://guacamole.apache.org/doc/gug/recording-playback.html#)
|
||||||
|
* vault - [Retrieving secrets from a vault](https://guacamole.apache.org/doc/gug/vault.html)
|
||||||
|
|
||||||
You should only enable the extensions you require, if an extensions is not configured correctly in the `guacamole.properties` file it may prevent the system from loading. See the [official documentation](https://guacamole.apache.org/doc/gug/) for more details.
|
You should only enable the extensions you require, if an extensions is not configured correctly in the `guacamole.properties` file it may prevent the system from loading. See the [official documentation](https://guacamole.apache.org/doc/gug/) for more details.
|
||||||
|
|
||||||
|
|||||||
@@ -1,16 +0,0 @@
|
|||||||
#!/usr/bin/with-contenv sh
|
|
||||||
|
|
||||||
# clean up extensions
|
|
||||||
for i in auth-ldap auth-duo auth-header auth-cas auth-openid auth-quickconnect auth-totp; do
|
|
||||||
rm -rf ${GUACAMOLE_HOME}/extensions/guacamole-${i}-${GUAC_VER}.jar
|
|
||||||
done
|
|
||||||
|
|
||||||
# if the guacamole version was bumped, delete the contents of the extensions directory - just on the first run
|
|
||||||
if [ "$(cat /config/.database-version)" != "$GUAC_VER" ]; then
|
|
||||||
rm -rf ${GUACAMOLE_HOME}/extensions/*
|
|
||||||
fi
|
|
||||||
|
|
||||||
# enable extensions
|
|
||||||
for i in $(echo "$EXTENSIONS" | tr "," " "); do
|
|
||||||
cp ${GUACAMOLE_HOME}/extensions-available/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions
|
|
||||||
done
|
|
||||||
@@ -0,0 +1,16 @@
|
|||||||
|
#!/usr/bin/with-contenv sh
|
||||||
|
|
||||||
|
echo "Cleaning Extensions from previous Guacamole versions"
|
||||||
|
for e in $(ls -1 ${GUACAMOLE_HOME}/extensions | grep guacamole | grep -v ${GUAC_VER}); do
|
||||||
|
rm ${GUACAMOLE_HOME}/extensions/${e}
|
||||||
|
done
|
||||||
|
|
||||||
|
echo "Cleaning Extensions"
|
||||||
|
for i in auth-duo auth-header auth-json auth-ldap auth-quickconnect auth-sso-cas auth-sso-openid auth-sso-saml auth-totp history-recording-storage vault-ksm; do
|
||||||
|
rm -rf ${GUACAMOLE_HOME}/extensions/guacamole-${i}-${GUAC_VER}.jar
|
||||||
|
done
|
||||||
|
|
||||||
|
# enable extensions
|
||||||
|
for i in $(echo "$EXTENSIONS" | tr "," " "); do
|
||||||
|
cp ${GUACAMOLE_HOME}/extensions-available/guacamole-${i}-${GUAC_VER}.jar ${GUACAMOLE_HOME}/extensions
|
||||||
|
done
|
||||||
@@ -14,14 +14,14 @@ if [ $? -ne 0 ]; then
|
|||||||
echo "$GUAC_VER" > /config/.database-version
|
echo "$GUAC_VER" > /config/.database-version
|
||||||
|
|
||||||
/etc/cont-init.d/30-defaults.sh
|
/etc/cont-init.d/30-defaults.sh
|
||||||
/etc/cont-init.d/50-extensions
|
/etc/cont-init.d/50-extensions.sh
|
||||||
else
|
else
|
||||||
if [ "$(cat /config/.database-version)" != "$GUAC_VER" ]; then
|
if [ "$(cat /config/.database-version)" != "$GUAC_VER" ]; then
|
||||||
cat /app/guacamole/schema/upgrade/upgrade-pre-$GUAC_VER.sql | psql -U $POSTGRES_USER -d $POSTGRES_DB -f -
|
cat /app/guacamole/schema/upgrade/upgrade-pre-$GUAC_VER.sql | psql -U $POSTGRES_USER -d $POSTGRES_DB -f -
|
||||||
echo "$GUAC_VER" > /config/.database-version
|
echo "$GUAC_VER" > /config/.database-version
|
||||||
|
|
||||||
/etc/cont-init.d/30-defaults.sh
|
/etc/cont-init.d/30-defaults.sh
|
||||||
/etc/cont-init.d/50-extensions
|
/etc/cont-init.d/50-extensions.sh
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user