diff --git a/configs/README.md b/configs/README.md index ce67cd3..1fff7ba 100644 --- a/configs/README.md +++ b/configs/README.md @@ -10,11 +10,15 @@ Directories are named to match **live podman container names** where possible. | `taler-exchange-ansible/` | **`taler-hacktivism-exchange-ansible`** | `taler-hacktivism-exchange-ansible:landing` | | `bank-landing/` `exchange-landing/` `merchant-landing/` | nginx landing snippets | ports 9013–9015 | | `koopa-*` apps | `koopa-castopod`, `koopa-bonfire`, … | compose mirrors | -| `tops/` | `koopa-tops-ng1` … `ng3` | `nginx:1.27-alpine` | +| `tops/` | `koopa-tops-ng1` … `ng3` | `nginxinc/nginx-unprivileged:1.27-alpine` (non-root, :8080) | | `caddy/` `firewalld/` `systemd/` | host services | | -| `tor/` | **`koopa-tor-relay`** (podman host net) | `localhost/koopa-tor-relay:latest` | -| `nym/` | **`koopa-nym`** (nym.com nym-node) | `localhost/koopa-nym:latest` | -| `paivana/` | **`koopa-paivana`** (+ upstream) | `localhost/koopa-paivana:latest` | +| `tor/` | **`koopa-tor-relay`** (podman host net) | `localhost/koopa-tor-relay:latest` (**non-root** uid 1000) | +| `nym/` | **`koopa-nym`** (nym.com nym-node) | `localhost/koopa-nym:latest` (**non-root** uid 1000) | +| `paivana/` | **`koopa-paivana`** (+ upstream) | `localhost/koopa-paivana:latest` (**non-root**); upstream unprivileged nginx | +| `forgejo/` | **`koopa-forgejo`** | rootless image + `user: 1000` + `userns keep-id` | +| `prime/` | jellyfin / qbittorrent | linuxserver **PUID/PGID=1000** | + +**Container process privilege policy:** service processes must not run as root inside the container when we control the image/compose. Pattern: uid/gid **1000** + rootless podman **`userns_mode: keep-id`** (see forgejo/nym/tor/paivana). Official DB images already drop to `postgres`/`redis`/`mysql`. Exceptions: **`taler-exchange-ansible`** (lab image with root SSH — not production service), third-party app images without a rootless variant (bonfire/castopod — track upstream). **Authoritative running inventory:** `host/overview/LIVE.md`. diff --git a/configs/tops/README.md b/configs/tops/README.md index 2fbc439..6bcea08 100644 --- a/configs/tops/README.md +++ b/configs/tops/README.md @@ -4,7 +4,7 @@ |------|--------| | Live | `/home/hernani/koopa-tops/` | | Containers | `koopa-tops-ng1`, `koopa-tops-ng2`, `koopa-tops-ng3` | -| Image | `docker.io/library/nginx:1.27-alpine` | +| Image | `docker.io/nginxinc/nginx-unprivileged:1.27-alpine` (non-root, container port **8080**) | | Compose | `compose.yml` (this dir) | | Secrets | none | diff --git a/configs/tops/compose.yml b/configs/tops/compose.yml index 60da5c1..89800de 100644 --- a/configs/tops/compose.yml +++ b/configs/tops/compose.yml @@ -2,13 +2,14 @@ # Live: /home/hernani/koopa-tops/ # Usage: cd ~/koopa-tops && podman compose -f deploy/compose.yml up -d +# nginxinc/nginx-unprivileged: process is non-root; listens on 8080 (not 80). services: tops-ng1: - image: docker.io/library/nginx:1.27-alpine + image: docker.io/nginxinc/nginx-unprivileged:1.27-alpine container_name: koopa-tops-ng1 restart: unless-stopped ports: - - "9090:80" + - "9090:8080" volumes: - ../ng1:/usr/share/nginx/html:ro labels: @@ -17,17 +18,17 @@ services: org.hacktivism.site: tops.ng1.hacktivism.ch org.hacktivism.managed_by: koopa-admin healthcheck: - test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/"] + test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/"] interval: 30s timeout: 5s retries: 3 tops-ng2: - image: docker.io/library/nginx:1.27-alpine + image: docker.io/nginxinc/nginx-unprivileged:1.27-alpine container_name: koopa-tops-ng2 restart: unless-stopped ports: - - "9091:80" + - "9091:8080" volumes: - ../ng2:/usr/share/nginx/html:ro labels: @@ -36,17 +37,17 @@ services: org.hacktivism.site: tops.ng2.hacktivism.ch org.hacktivism.managed_by: koopa-admin healthcheck: - test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/"] + test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/"] interval: 30s timeout: 5s retries: 3 tops-ng3: - image: docker.io/library/nginx:1.27-alpine + image: docker.io/nginxinc/nginx-unprivileged:1.27-alpine container_name: koopa-tops-ng3 restart: unless-stopped ports: - - "9092:80" + - "9092:8080" volumes: - ../ng3:/usr/share/nginx/html:ro labels: @@ -55,7 +56,7 @@ services: org.hacktivism.site: tops.ng3.hacktivism.ch org.hacktivism.managed_by: koopa-admin healthcheck: - test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1/"] + test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/"] interval: 30s timeout: 5s retries: 3