Merge main into hardening-fixes

This commit is contained in:
Adam Outler
2025-10-23 21:19:30 -04:00
46 changed files with 30 additions and 17 deletions
Regular → Executable
+1 -1
View File
@@ -18,7 +18,7 @@
# It reduces the chance of system hijacking and operates with all modern security protocols in place as is # It reduces the chance of system hijacking and operates with all modern security protocols in place as is
# expected from a security appliance. # expected from a security appliance.
# #
# This file can be built with `docker compose -f docker-compose.yml up --build --force-recreate` # This file can be built with `docker-compose -f docker-compose.yml up --build --force-recreate`
FROM alpine:3.22 AS builder FROM alpine:3.22 AS builder
Regular → Executable
View File
+1 -1
View File
@@ -15,7 +15,7 @@
# It reduces the chance of system hijacking and operates with all modern security protocols in place as is # It reduces the chance of system hijacking and operates with all modern security protocols in place as is
# expected from a security appliance. # expected from a security appliance.
# #
# This file can be built with `docker compose -f docker-compose.yml up --build --force-recreate` # This file can be built with `docker-compose -f docker-compose.yml up --build --force-recreate`
FROM alpine:3.22 AS builder FROM alpine:3.22 AS builder
Regular → Executable
View File
Regular → Executable
View File
+28 -15
View File
@@ -15,13 +15,13 @@ services:
- NET_BIND_SERVICE # Required to bind to privileged ports (nbtscan) - NET_BIND_SERVICE # Required to bind to privileged ports (nbtscan)
volumes: volumes:
- type: volume - type: bind
source: netalertx_config source: ${APP_DATA_LOCATION}/netalertx/config
target: /app/config target: /app/config
read_only: false read_only: false
- type: volume - type: bind
source: netalertx_db source: ${APP_DATA_LOCATION}/netalertx/db
target: /app/db target: /app/db
read_only: false read_only: false
@@ -30,15 +30,26 @@ services:
target: /etc/localtime target: /etc/localtime
read_only: true read_only: true
# Retain logs - comment out tmpfs /app/log if you want to retain logs between container restarts
# - /path/on/host/log:/app/log
# Optional logs
# - type: bind
# source: ${LOGS_LOCATION}
# target: /app/log
# read_only: false
# Optional development mounts
- type: bind
source: ${DEV_LOCATION}
target: /app/front/plugins/custom
read_only: false
# Use a custom Enterprise-configured nginx config for ldap or other settings # Use a custom Enterprise-configured nginx config for ldap or other settings
# - /custom-enterprise.conf:/services/config/nginx/conf.active/netalertx.conf:ro # - /custom-enterprise.conf:/services/config/nginx/conf.active/netalertx.conf:ro
# Test your plugin on the production container # Test your plugin on the production container
# - /path/on/host:/app/front/plugins/custom # - /path/on/host:/app/front/plugins/custom
# Retain logs - comment out tmpfs /app/log if you want to retain logs between container restarts
# - /path/on/host/log:/app/log
# Tempfs mounts for writable directories in a read-only container and improve system performance # Tempfs mounts for writable directories in a read-only container and improve system performance
tmpfs: tmpfs:
# Speed up logging. This can be commented out to retain logs between container restarts # Speed up logging. This can be commented out to retain logs between container restarts
@@ -52,11 +63,13 @@ services:
# /tmp is required by php for session save this should be reworked to /services/run/tmp # /tmp is required by php for session save this should be reworked to /services/run/tmp
- "/tmp:uid=20211,gid=20211,mode=1700,rw,noexec,nosuid,nodev,async,noatime,nodiratime" - "/tmp:uid=20211,gid=20211,mode=1700,rw,noexec,nosuid,nodev,async,noatime,nodiratime"
environment: environment:
LISTEN_ADDR: 0.0.0.0 # Listen for connections on all interfaces LISTEN_ADDR: 0.0.0.0 # Listen for connections on all interfaces
PORT: 20211 # Application port PORT: ${PORT} # Application port
GRAPHQL_PORT: 20212 # GraphQL API port ALWAYS_FRESH_INSTALL: ${ALWAYS_FRESH_INSTALL} # Set to true to reset your config and database on each container start
ALWAYS_FRESH_INSTALL: false # Set to true to reset your config and database on each container start NETALERTX_DEBUG: 0 # 0=kill all services and restart if any dies. 1 keeps running dead services.
NETALERTX_DEBUG: 0 # 0=kill all services and restart if any dies. 1 keeps running dead services. TZ: ${TZ} # Timezone, e.g. Europe/Paris
# APP_CONF_OVERRIDE={"SCAN_SUBNETS":"['192.168.1.0/24 --interface=eth1']","GRAPHQL_PORT":"20223","UI_theme":"Light"} # (optional) app.conf settings override
# LOADED_PLUGINS=["DHCPLSS","PIHOLE","ASUSWRT","FREEBOX"] # (optional) default plugins to load
# Resource limits to prevent resource exhaustion # Resource limits to prevent resource exhaustion
mem_limit: 2048m # Maximum memory usage mem_limit: 2048m # Maximum memory usage
@@ -72,7 +85,7 @@ services:
# Always restart the container unless explicitly stopped # Always restart the container unless explicitly stopped
restart: unless-stopped restart: unless-stopped
volumes: # volumes:
netalertx_config: # netalertx_config:
netalertx_db: # netalertx_db:
Regular → Executable
View File
Regular → Executable
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
View File
Regular → Executable
View File
Regular → Executable
View File