Files
finger/docker-compose.yml
T
pmb b1e7f5229b docs(docker): run as root under host networking to bind port 79
Host networking shares the host net namespace, so the host's
privileged-port rule applies and the image's non-root user cannot bind 79
-- the daemon fails to listen silently. Add user: "0:0" to the compose and
correct the earlier (wrong) claim that non-root bind still works. Note
setcap as the non-root alternative.
2026-06-15 16:54:47 -07:00

41 lines
1.6 KiB
YAML

version: '3.8'
services:
finger:
build: .
# IMPORTANT: host networking is what lets the daemon's abuse protection
# work. Under Docker's default bridge networking every external client is
# SNAT'd to the bridge gateway (a 172.16/12 address), so the daemon sees a
# single source IP for everyone -- the per-IP ban logic can't tell clients
# apart and (by design) treats that private address as untrackable, leaving
# banning inert. Host networking exposes the real client IP, so repeat
# offenders actually get blocked.
network_mode: host
# Under host networking the container shares the host net namespace, which
# uses the host's privileged-port rule -- so the image's non-root user
# (UID 1000) cannot bind port 79 and the daemon fails to listen silently.
# Run as root to bind it. (Alternative: setcap cap_net_bind_service on the
# binary in the image to keep it non-root.)
user: "0:0"
volumes:
- ./users:/var/finger/users
restart: unless-stopped
healthcheck:
test: ["CMD-SHELL", "nc -w 1 127.0.0.1 79 < /dev/null || exit 1"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
# Bridge-networking alternative (quick local testing only). NOTE: with this
# mode the daemon only ever sees the bridge gateway IP, so abuse protection
# is effectively disabled. Prefer host networking above for any public-facing
# deployment.
# finger:
# image: ghcr.io/waffle2k/finger:latest
# ports:
# - "79:79"
# volumes:
# - ./users:/var/finger/users
# restart: unless-stopped