mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-08-20 20:07:20 +02:00
* feat(portainer_be): add Portainer Business Edition add-on Adds a new `portainer_be` add-on based on the existing Portainer (CE) add-on, requested in #873. Business Edition has no public GitHub release tarball like CE, so the binary and web assets are pulled from the official multi-arch `portainer/portainer-ee` image via a multi-stage build and placed under /opt/portainer, mirroring CE's layout exactly. All runtime scripts, nginx/ingress config, options schema, SSL and password handling are unchanged from CE, so behaviour is identical apart from the edition. Users obtain a free (up to 3 nodes) Business Edition license key by registering with Portainer and enter it in the web UI on first launch. - config.yaml: slug portainer_be, BE image name, BE description/name - Dockerfile: multi-stage COPY from portainer/portainer-ee (no CE tarball) - updater.json: dockerhub source tracking portainer/portainer-ee - apparmor.txt: unique profile name (portainer_be_addon) - CHANGELOG/README/DOCS: BE-specific, documents the license-key step Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(portainer_be): address PR review feedback - nginx finish: move shebang to byte 0 (leading blank line prevented S6 from recognising the interpreter, so the finish hook could fail to tear down the supervision tree) [Codex P2] - ingress: tighten CSP to `frame-ancestors 'self'` to match the adjacent X-Frame-Options SAMEORIGIN; HA ingress embeds same-origin so the panel keeps working [CodeRabbit] - README: correct login note (password is the configured option value, never printed to logs); drop MD012 consecutive blank lines [CodeRabbit] - DOCS: fix "environement" -> "environment" typo [CodeRabbit] Skipped: nginx SSL "idempotency" finding — /etc/nginx lives in the read-only image layer and cont-init re-renders from the pristine template on every container start, so in-place sed edits never accumulate or need restoring. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * revert(portainer_be): keep CSP frame-ancestors * for ingress compatibility Reverts the frame-ancestors 'self' change from the previous commit. The wildcard is required for the Home Assistant ingress iframe to embed the Portainer UI; tightening it breaks the ingress panel. Matches the CE add-on. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
63 lines
1.2 KiB
Plaintext
63 lines
1.2 KiB
Plaintext
#include <tunables/global>
|
|
|
|
profile portainer_be_addon flags=(attach_disconnected,mediate_deleted) {
|
|
#include <abstractions/base>
|
|
|
|
capability chown,
|
|
capability dac_override,
|
|
capability fowner,
|
|
capability setgid,
|
|
capability setuid,
|
|
capability sys_chroot,
|
|
file,
|
|
signal,
|
|
mount,
|
|
umount,
|
|
remount,
|
|
network udp,
|
|
network tcp,
|
|
network dgram,
|
|
network stream,
|
|
network inet,
|
|
network inet6,
|
|
network netlink raw,
|
|
network unix dgram,
|
|
|
|
|
|
# S6-Overlay
|
|
/init ix,
|
|
/run/{s6,s6-rc*,service}/** ix,
|
|
/package/** ix,
|
|
/command/** ix,
|
|
/run/{,**} rwk,
|
|
/dev/tty rw,
|
|
/bin/** ix,
|
|
/usr/bin/** ix,
|
|
/usr/lib/bashio/** ix,
|
|
/etc/s6/** rix,
|
|
/run/s6/** rix,
|
|
/etc/services.d/** rwix,
|
|
/etc/cont-init.d/** rwix,
|
|
/etc/cont-finish.d/** rwix,
|
|
/init rix,
|
|
/var/run/** mrwkl,
|
|
/var/run/ mrwkl,
|
|
/dev/i2c-1 mrwkl,
|
|
/dev/fuse mrwkl,
|
|
/dev/sda1 mrwkl,
|
|
/dev/sdb1 mrwkl,
|
|
/dev/nvme0 mrwkl,
|
|
/dev/nvme1 mrwkl,
|
|
/dev/mmcblk0p1 mrwkl,
|
|
|
|
# Data access
|
|
/data/** rw,
|
|
|
|
# suppress ptrace denials when using 'docker ps' or using 'ps' inside a container
|
|
ptrace (trace,read) peer=docker-default,
|
|
|
|
# docker daemon confinement requires explict allow rule for signal
|
|
signal (receive) set=(kill,term) peer=/usr/bin/docker,
|
|
|
|
}
|