0% found this document useful (0 votes)
10 views4 pages

Dockerfile for Shadowsocksr Setup

This Dockerfile defines the configuration for a PHP Docker image based on php:8.1-apache with WordPress installed. It installs PHP extensions, configures Apache and PHP settings, downloads and extracts the latest WordPress release, and defines the default Apache process to run.

Uploaded by

yosi.suarez
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
10 views4 pages

Dockerfile for Shadowsocksr Setup

This Dockerfile defines the configuration for a PHP Docker image based on php:8.1-apache with WordPress installed. It installs PHP extensions, configures Apache and PHP settings, downloads and extracts the latest WordPress release, and defines the default Apache process to run.

Uploaded by

yosi.suarez
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as TXT, PDF, TXT or read online on Scribd

#

# NOTE: THIS DOCKERFILE IS GENERATED VIA "[Link]"


#
# PLEASE DO NOT EDIT IT DIRECTLY.
#

FROM php:8.1-apache

# persistent dependencies
RUN set -eux; \
apt-get update; \
apt-get install -y --no-install-recommends \
# Ghostscript is required for rendering PDF previews
ghostscript \
; \
rm -rf /var/lib/apt/lists/*

# install the PHP extensions we need


([Link]
extensions)
RUN set -ex; \
\
savedAptMark="$(apt-mark showmanual)"; \
\
apt-get update; \
apt-get install -y --no-install-recommends \
libfreetype6-dev \
libicu-dev \
libjpeg-dev \
libmagickwand-dev \
libpng-dev \
libwebp-dev \
libzip-dev \
; \
\
docker-php-ext-configure gd \
--with-freetype \
--with-jpeg \
--with-webp \
; \
docker-php-ext-install -j "$(nproc)" \
bcmath \
exif \
gd \
intl \
mysqli \
zip \
; \
# [Link]
#
[Link]
(causes a lot of build failures, but strangely only intermittent ones 🤔)
# see also [Link]
# this is "pecl install imagick-3.7.0", but by hand so we can apply a small hack /
part of the above commit
curl -fL -o [Link] '[Link] \
echo '5a364354109029d224bcbb2e82e15b248be9b641227f45e63425c06531792d3e
*[Link]' | sha256sum -c -; \
tar --extract --directory /tmp --file [Link] imagick-3.7.0; \
grep '^//#endif$' /tmp/imagick-3.7.0/[Link]; \
test "$(grep -c '^//#endif$' /tmp/imagick-3.7.0/[Link])" = '1'; \
sed -i -e 's!^//#endif$!#endif!' /tmp/imagick-3.7.0/[Link]; \
grep '^//#endif$' /tmp/imagick-3.7.0/[Link] && exit 1 || :; \
docker-php-ext-install /tmp/imagick-3.7.0; \
rm -rf [Link] /tmp/imagick-3.7.0; \
\
# some misbehaving extensions end up outputting to stdout 🙈
([Link]
out="$(php -r 'exit(0);')"; \
[ -z "$out" ]; \
err="$(php -r 'exit(0);' 3>&1 1>&2 2>&3)"; \
[ -z "$err" ]; \
\
extDir="$(php -r 'echo ini_get("extension_dir");')"; \
[ -d "$extDir" ]; \
# reset apt-mark's "manual" list so that "purge --auto-remove" will remove all
build dependencies
apt-mark auto '.*' > /dev/null; \
apt-mark manual $savedAptMark; \
ldd "$extDir"/*.so \
| awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1)
{ next }; gsub("^/(usr/)?", "", so); print so }' \
| sort -u \
| xargs -r dpkg-query --search \
| cut -d: -f1 \
| sort -u \
| xargs -rt apt-mark manual; \
\
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false;
\
rm -rf /var/lib/apt/lists/*; \
\
! { ldd "$extDir"/*.so | grep 'not found'; }; \
# check for output like "PHP Warning: PHP Startup: Unable to load dynamic library
'foo' (tried: ...)
err="$(php --version 3>&1 1>&2 2>&3)"; \
[ -z "$err" ]

# set recommended [Link] settings


# see [Link]
RUN set -eux; \
docker-php-ext-enable opcache; \
{ \
echo 'opcache.memory_consumption=128'; \
echo 'opcache.interned_strings_buffer=8'; \
echo 'opcache.max_accelerated_files=4000'; \
echo 'opcache.revalidate_freq=2'; \
} > /usr/local/etc/php/conf.d/[Link]
# [Link]
logging
RUN { \
# [Link]
# [Link]
echo 'error_reporting = E_ERROR | E_WARNING | E_PARSE | E_CORE_ERROR |
E_CORE_WARNING | E_COMPILE_ERROR | E_COMPILE_WARNING | E_RECOVERABLE_ERROR'; \
echo 'display_errors = Off'; \
echo 'display_startup_errors = Off'; \
echo 'log_errors = On'; \
echo 'error_log = /dev/stderr'; \
echo 'log_errors_max_len = 1024'; \
echo 'ignore_repeated_errors = On'; \
echo 'ignore_repeated_source = Off'; \
echo 'html_errors = Off'; \
} > /usr/local/etc/php/conf.d/[Link]

RUN set -eux; \


a2enmod rewrite expires; \
\
# [Link]
a2enmod remoteip; \
{ \
echo 'RemoteIPHeader X-Forwarded-For'; \
# these IP ranges are reserved for "private" use and should thus *usually* be safe
inside Docker
echo 'RemoteIPInternalProxy [Link]/8'; \
echo 'RemoteIPInternalProxy [Link]/12'; \
echo 'RemoteIPInternalProxy [Link]/16'; \
echo 'RemoteIPInternalProxy [Link]/16'; \
echo 'RemoteIPInternalProxy [Link]/8'; \
} > /etc/apache2/conf-available/[Link]; \
a2enconf remoteip; \
# [Link]
# (replace all instances of "%h" with "%a" in LogFormat)
find /etc/apache2 -type f -name '*.conf' -exec sed -ri
's/([[:space:]]*LogFormat[[:space:]]+"[^"]*)%h([^"]*")/\1%a\2/g' '{}' +

RUN set -eux; \


version='6.4.3'; \
sha1='ee3bc3a73ab3cfa535c46f111eb641b3467fa44e'; \
\
curl -o [Link] -fL "[Link]
$[Link]"; \
echo "$sha1 *[Link]" | sha1sum -c -; \
\
# upstream tarballs include ./wordpress/ so this gives us /usr/src/wordpress
tar -xzf [Link] -C /usr/src/; \
rm [Link]; \
\
# [Link]
[ ! -e /usr/src/wordpress/.htaccess ]; \
{ \
echo '# BEGIN WordPress'; \
echo ''; \
echo 'RewriteEngine On'; \
echo 'RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]'; \
echo 'RewriteBase /'; \
echo 'RewriteRule ^index\.php$ - [L]'; \
echo 'RewriteCond %{REQUEST_FILENAME} !-f'; \
echo 'RewriteCond %{REQUEST_FILENAME} !-d'; \
echo 'RewriteRule . /[Link] [L]'; \
echo ''; \
echo '# END WordPress'; \
} > /usr/src/wordpress/.htaccess; \
\
chown -R www-data:www-data /usr/src/wordpress; \
# pre-create wp-content (and single-level children) for folks who want to bind-
mount themes, etc so permissions are pre-created properly instead of root:root
# wp-content/cache:
[Link]
mkdir wp-content; \
for dir in /usr/src/wordpress/wp-content/*/ cache; do \
dir="$(basename "${dir%/}")"; \
mkdir "wp-content/$dir"; \
done; \
chown -R www-data:www-data wp-content; \
chmod -R 1777 wp-content

VOLUME /var/www/html

COPY --chown=www-data:www-data [Link] /usr/src/wordpress/


COPY [Link] /usr/local/bin/

ENTRYPOINT ["[Link]"]
CMD ["apache2-foreground"]

Common questions

Powered by AI

The Dockerfile sets error logging settings to enhance application debugging while maintaining security. It configures `log_errors` to `On` and `error_log` to write to `/dev/stderr`. It ensures that `display_errors` and `display_startup_errors` are `Off`, preventing PHP errors from being exposed to end-users, which is crucial for security. Instead, errors are logged with `log_errors_max_len` set to 1024, and repeated error logging is managed with `ignore_repeated_errors` set to `On` and `ignore_repeated_source` set to `Off`. These settings help in systematically capturing detailed error information while avoiding information disclosure vulnerabilities .

Installing specific PHP extensions like `gd`, `intl`, and `imagick` is crucial for the functioning of web applications that rely on image processing, internationalization, and graphics support. `gd` is used for manipulating images in various formats, `intl` provides internationalization capabilities, such as language translation and date formatting, and `imagick` offers a powerful library for complex image manipulations using the ImageMagick library. These extensions ensure that the PHP environment can support a wide range of functionalities essential for modern web applications, especially those using content management systems like WordPress .

The `docker-php-ext-configure` and `docker-php-ext-install` commands manage PHP extension setup and installation within the Docker environment. `docker-php-ext-configure` is used to modify the build configuration of PHP extensions, such as enabling specific features or linking to necessary libraries, before they are compiled. This customization ensures the extensions are optimized for the application's requirements. Then, `docker-php-ext-install` compiles and installs the specified extensions, making them available to the PHP environment. This structured approach allows for the automation and consistency of extension management within a Dockerized PHP application .

Validating the SHA checksum of downloaded files such as `wordpress.tar.gz` ensures that the file has not been altered or corrupted in transit, which is a critical security measure. By confirming that the calculated SHA checksum matches the expected value, it verifies the authenticity of the downloaded file as it comes from a trusted source. This process helps protect against potential security threats such as man-in-the-middle attacks or corrupted files, ensuring that the build process relies on genuine and intact software components .

Ghostscript is installed in the Dockerfile to facilitate rendering PDF previews. It serves as a versatile PostScript and PDF interpreter capable of converting PDFs to images or processing images for viewing and printing. By including Ghostscript, the Dockerfile ensures that the web application can handle tasks like generating thumbnail previews of PDF documents, which enhances the user's ability to interact with PDF content directly in the application without needing additional client-side plugins .

Modifying the Apache LogFormat directives to replace all instances of `%h` with `%a` changes the way source IP addresses are logged. `%h` logs the IP address of the client machine making the request, while `%a` logs the address of the client provided by the `X-Forwarded-For` header when a reverse proxy is used. This change ensures correct logging of the original client IP address rather than the proxy server address, which is crucial for analyzing traffic patterns, identifying malicious requests, and complying with policies that require accurate user data logging .

Using `a2enmod rewrite` enables URL rewriting, allowing for more user-friendly and search engine-optimized URLs by transforming request URLs into specific paths internally. `a2enmod expires` enables the `mod_expires` module, which sets the `Expires` and `Cache-Control` headers to control browser caching policies. This reduces server load and improves performance by allowing browsers to cache static content. Both modules provide greater flexibility and control over website behavior and performance, contributing to better SEO and user experience .

Not managing dynamic library outputs in Dockerfiles properly can lead to several issues, such as cluttered or full disk space due to unhandled temporary files and unnecessary outputs being logged, which can obscure important log details and increase processing times. Misbehaving extensions could output debug information or errors to stdout, confusing the data flow essential for application logic or causing disruptions in API interaction. Best practices in filtering and redirecting these outputs prevent such issues, ensuring the environment remains clean, efficient, and is easier to debug and maintain .

The Dockerfile configures Apache to handle forwarded headers using the `a2enmod remoteip` command, which enables the `mod_remoteip` module. This is followed by configuring `RemoteIPInternalProxy` directives with reserved IP ranges like `10.0.0.0/8` and `192.168.0.0/16`. These settings instruct Apache to replace the client IP address in the logs with the IP address specified in the `X-Forwarded-For` header, ensuring accurate logging and security compliance when the server is behind a proxy .

The `run set -eux` command is used to configure the shell environment to be more transparent and error-prone during the Docker build process. The `-e` option tells the shell to exit immediately if a command exits with a non-zero status, which helps in identifying errors early. The `-u` option treats unset variables as an error and exits immediately, preventing misuse or incorrect use of environment variables. Lastly, the `-x` option prints each command before executing it, providing a detailed log of what is happening, which aids in debugging. Overall, these settings help ensure the build is robust and failures are caught promptly.

You might also like