diff --git a/.env.example b/.env.example index 0480851..94bc866 100644 --- a/.env.example +++ b/.env.example @@ -1,7 +1,2 @@ # Speedtest configuration CRON_SCHEDULE=*/30 * * * * - -# User permissions (defaults to current user) -# Set these to match your host user to ensure proper file permissions -UID=1000 -GID=1000 diff --git a/Dockerfile b/Dockerfile index 611cc7d..efd38ea 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,4 +1,4 @@ -FROM nginx:stable-alpine-slim +FROM nginxinc/nginx-unprivileged:alpine-slim # Install required packages RUN apk add --no-cache \ @@ -35,25 +35,17 @@ COPY generate_html.sh /app/ COPY entrypoint.sh /app/ RUN chmod +x /app/*.sh && chmod 777 /app -# Create nginx config that works with non-root user -RUN mkdir -p /tmp/nginx && chmod 777 /tmp/nginx && \ - sed -i 's/listen 80;/listen 8080;/g' /etc/nginx/conf.d/default.conf && \ - sed -i 's/listen \[::\]:80;/listen [::]:8080;/g' /etc/nginx/conf.d/default.conf && \ - sed -i 's/user nginx;/# user nginx;/g' /etc/nginx/nginx.conf && \ - sed -i '/pid/d' /etc/nginx/nginx.conf && \ - sed -i 's|root /usr/share/nginx/html|root /app/html|g' /etc/nginx/conf.d/default.conf && \ - echo 'client_body_temp_path /tmp/nginx/client_temp;' >> /etc/nginx/nginx.conf && \ - echo 'proxy_temp_path /tmp/nginx/proxy_temp;' >> /etc/nginx/nginx.conf && \ - echo 'fastcgi_temp_path /tmp/nginx/fastcgi_temp;' >> /etc/nginx/nginx.conf && \ - echo 'uwsgi_temp_path /tmp/nginx/uwsgi_temp;' >> /etc/nginx/nginx.conf && \ - echo 'scgi_temp_path /tmp/nginx/scgi_temp;' >> /etc/nginx/nginx.conf +# Configure nginx to serve from our html directory +USER root +RUN sed -i 's|root /usr/share/nginx/html|root /app/html|g' /etc/nginx/conf.d/default.conf +USER nginx # Environment variables with defaults ENV CRON_SCHEDULE="*/30 * * * *" ENV DATA_FILE="/data/speedtest.csv" ENV HTML_FILE="/app/html/index.html" -# Expose web port +# Expose web port (nginx-unprivileged uses 8080 by default) EXPOSE 8080 # Volume for persistent data diff --git a/README.md b/README.md index 25b76a5..89a1a4d 100644 --- a/README.md +++ b/README.md @@ -35,22 +35,6 @@ docker run -d \ | Environment Variable | Default | Description | |---------------------|---------|-------------| | `CRON_SCHEDULE` | `*/30 * * * *` | Cron expression for test frequency | -| `UID` | `1000` | User ID to run as (match host user) | -| `GID` | `1000` | Group ID to run as (match host user) | - -### Running as Current User - -To run the container with your current user's permissions: - -```bash -# Option 1: Set in .env file -echo "UID=$(id -u)" >> .env -echo "GID=$(id -g)" >> .env -docker-compose up -d - -# Option 2: Pass directly on command line -UID=$(id -u) GID=$(id -g) docker-compose up -d -``` ### Cron Schedule Examples @@ -75,11 +59,12 @@ docker build -t speedtest . ## Architecture -- **Base image**: `nginx:stable-alpine-slim` (~12MB) +- **Base image**: `nginxinc/nginx-unprivileged:alpine-slim` (~20MB) - **Speedtest**: Ookla's official CLI - **Scheduling**: dcron (cron daemon) - **Graphs**: Plotly.js (loaded from CDN) renders CSV data client-side -- **Image size**: ~25MB total (vs 648MB for Python-based image) +- **Security**: Runs as non-root user by default +- **Image size**: ~35MB total (vs 648MB for Python-based image) ## Viewing Logs diff --git a/docker-compose.yml b/docker-compose.yml index b821ca4..658ba4f 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -4,7 +4,6 @@ services: speedtest: build: . container_name: speedtest - user: "${UID:-1000}:${GID:-1000}" ports: - "${HTTP_PORT:-8080}:8080" volumes: