mirror of
https://github.com/alexbelgium/hassio-addons.git
synced 2026-08-12 16:12:29 +02:00
* feat(portainer_be): add Portainer Business Edition add-on Adds a new `portainer_be` add-on based on the existing Portainer (CE) add-on, requested in #873. Business Edition has no public GitHub release tarball like CE, so the binary and web assets are pulled from the official multi-arch `portainer/portainer-ee` image via a multi-stage build and placed under /opt/portainer, mirroring CE's layout exactly. All runtime scripts, nginx/ingress config, options schema, SSL and password handling are unchanged from CE, so behaviour is identical apart from the edition. Users obtain a free (up to 3 nodes) Business Edition license key by registering with Portainer and enter it in the web UI on first launch. - config.yaml: slug portainer_be, BE image name, BE description/name - Dockerfile: multi-stage COPY from portainer/portainer-ee (no CE tarball) - updater.json: dockerhub source tracking portainer/portainer-ee - apparmor.txt: unique profile name (portainer_be_addon) - CHANGELOG/README/DOCS: BE-specific, documents the license-key step Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(portainer_be): address PR review feedback - nginx finish: move shebang to byte 0 (leading blank line prevented S6 from recognising the interpreter, so the finish hook could fail to tear down the supervision tree) [Codex P2] - ingress: tighten CSP to `frame-ancestors 'self'` to match the adjacent X-Frame-Options SAMEORIGIN; HA ingress embeds same-origin so the panel keeps working [CodeRabbit] - README: correct login note (password is the configured option value, never printed to logs); drop MD012 consecutive blank lines [CodeRabbit] - DOCS: fix "environement" -> "environment" typo [CodeRabbit] Skipped: nginx SSL "idempotency" finding — /etc/nginx lives in the read-only image layer and cont-init re-renders from the pristine template on every container start, so in-place sed edits never accumulate or need restoring. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * revert(portainer_be): keep CSP frame-ancestors * for ingress compatibility Reverts the frame-ancestors 'self' change from the previous commit. The wildcard is required for the Home Assistant ingress iframe to embed the Portainer UI; tightening it breaks the ingress panel. Matches the CE add-on. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
157 lines
5.1 KiB
Docker
157 lines
5.1 KiB
Docker
#============================#
|
|
# ALEXBELGIUM'S DOCKERFILE #
|
|
#============================#
|
|
# _.------.
|
|
# _.-` ('>.-`"""-.
|
|
# '.--'` _'` _ .--.)
|
|
# -' '-.-';` `
|
|
# ' - _.' ``'--.
|
|
# '---` .-'""`
|
|
# /`
|
|
#=== Home Assistant Addon ===#
|
|
|
|
#################
|
|
# 1 Build Image #
|
|
#################
|
|
|
|
ARG BUILD_FROM=ghcr.io/hassio-addons/base/amd64:11.0.0
|
|
# Portainer Business Edition (Enterprise) upstream version.
|
|
# Business Edition has no public release tarball like CE does; its binary and
|
|
# web assets ship only inside the official portainer/portainer-ee image, so we
|
|
# pull them from there. The image is multi-arch (amd64/arm64), so buildx picks
|
|
# the variant matching the target architecture automatically.
|
|
ARG BUILD_UPSTREAM="2.43.0"
|
|
FROM portainer/portainer-ee:${BUILD_UPSTREAM} AS portainer_be
|
|
|
|
ARG BUILD_FROM
|
|
FROM ${BUILD_FROM}
|
|
|
|
##################
|
|
# 2 Modify Image #
|
|
##################
|
|
|
|
# Set S6 wait time
|
|
ENV S6_CMD_WAIT_FOR_SERVICES=1 \
|
|
S6_CMD_WAIT_FOR_SERVICES_MAXTIME=0 \
|
|
S6_SERVICES_GRACETIME=0
|
|
|
|
|
|
# Set shell
|
|
SHELL ["/bin/bash", "-o", "pipefail", "-c"]
|
|
|
|
# Setup base
|
|
ARG BUILD_UPSTREAM
|
|
|
|
# Install the Portainer BE binary and its web assets, mirroring the CE add-on
|
|
# layout under /opt/portainer (the binary resolves ./public relative to itself,
|
|
# so keeping them side by side needs no --assets flag at runtime).
|
|
COPY --from=portainer_be /portainer /opt/portainer/portainer
|
|
COPY --from=portainer_be /public /opt/portainer/public
|
|
|
|
##################
|
|
# 3 Install apps #
|
|
##################
|
|
|
|
# Add rootfs
|
|
COPY rootfs/ /
|
|
RUN find . -type f \( -name "*.sh" -o -name "run" -o -name "finish" \) -print -exec chmod +x {} \;
|
|
|
|
# Uses /bin for compatibility purposes
|
|
# hadolint ignore=DL4005
|
|
RUN if [ ! -f /bin/sh ] && [ -f /usr/bin/sh ]; then ln -s /usr/bin/sh /bin/sh; fi && \
|
|
if [ ! -f /bin/bash ] && [ -f /usr/bin/bash ]; then ln -s /usr/bin/bash /bin/bash; fi
|
|
|
|
# Modules
|
|
ARG MODULES="00-banner.sh 01-custom_script.sh"
|
|
|
|
# Automatic modules download
|
|
COPY ha_automodules.sh /ha_automodules.sh
|
|
RUN chmod 744 /ha_automodules.sh && /ha_automodules.sh "$MODULES" && rm /ha_automodules.sh
|
|
|
|
# Manual apps
|
|
ENV PACKAGES="nginx"
|
|
|
|
# Automatic apps & bashio
|
|
COPY ha_autoapps.sh /ha_autoapps.sh
|
|
RUN chmod 744 /ha_autoapps.sh && /ha_autoapps.sh "$PACKAGES" && rm /ha_autoapps.sh
|
|
|
|
################
|
|
# 4 Entrypoint #
|
|
################
|
|
|
|
# Add entrypoint
|
|
ENV S6_STAGE2_HOOK=/ha_entrypoint.sh
|
|
COPY ha_entrypoint.sh /ha_entrypoint.sh
|
|
RUN chmod 777 /ha_entrypoint.sh
|
|
|
|
# Install bashio
|
|
COPY bashio-standalone.sh /usr/local/lib/bashio-standalone.sh
|
|
RUN chmod 0755 /usr/local/lib/bashio-standalone.sh
|
|
|
|
RUN chmod 777 /etc/services.d/*/*
|
|
#
|
|
#WORKDIR /
|
|
#ENTRYPOINT [ "/usr/bin/env" ]
|
|
#CMD [ "/ha_entrypoint.sh" ]
|
|
#SHELL ["/bin/bash", "-o", "pipefail", "-c"]
|
|
|
|
############
|
|
# 5 Labels #
|
|
############
|
|
|
|
ARG BUILD_ARCH
|
|
ARG BUILD_DATE
|
|
ARG BUILD_DESCRIPTION
|
|
ARG BUILD_NAME
|
|
ARG BUILD_REF
|
|
ARG BUILD_REPOSITORY
|
|
ARG BUILD_VERSION
|
|
ENV BUILD_VERSION="${BUILD_VERSION}"
|
|
LABEL \
|
|
io.hass.name="${BUILD_NAME}" \
|
|
io.hass.description="${BUILD_DESCRIPTION}" \
|
|
io.hass.arch="${BUILD_ARCH}" \
|
|
io.hass.type="addon" \
|
|
io.hass.version=${BUILD_VERSION} \
|
|
maintainer="alexbelgium (https://github.com/alexbelgium)" \
|
|
org.opencontainers.image.title="${BUILD_NAME}" \
|
|
org.opencontainers.image.description="${BUILD_DESCRIPTION}" \
|
|
org.opencontainers.image.vendor="Home Assistant Add-ons" \
|
|
org.opencontainers.image.authors="alexbelgium (https://github.com/alexbelgium)" \
|
|
org.opencontainers.image.licenses="MIT" \
|
|
org.opencontainers.image.url="https://github.com/alexbelgium" \
|
|
org.opencontainers.image.source="https://github.com/${BUILD_REPOSITORY}" \
|
|
org.opencontainers.image.documentation="https://github.com/${BUILD_REPOSITORY}/blob/main/README.md" \
|
|
org.opencontainers.image.created=${BUILD_DATE} \
|
|
org.opencontainers.image.revision=${BUILD_REF} \
|
|
org.opencontainers.image.version=${BUILD_VERSION}
|
|
|
|
#################
|
|
# 6 Healthcheck #
|
|
#################
|
|
|
|
# Avoid spamming logs
|
|
# hadolint ignore=SC2016
|
|
RUN \
|
|
# Handle Apache configuration
|
|
if [ -d /etc/apache2/sites-available ]; then \
|
|
for file in /etc/apache2/sites-*/*.conf; do \
|
|
sed -i '/<VirtualHost/a \ \n # Match requests with the custom User-Agent "HealthCheck" \n SetEnvIf User-Agent "HealthCheck" dontlog \n # Exclude matching requests from access logs \n CustomLog ${APACHE_LOG_DIR}/access.log combined env=!dontlog' "$file"; \
|
|
done; \
|
|
fi && \
|
|
\
|
|
# Handle Nginx configuration
|
|
if [ -f /etc/nginx/nginx.conf ]; then \
|
|
awk '/http \{/{print; print "map $http_user_agent $dontlog {\n default 0;\n \"~*HealthCheck\" 1;\n}\naccess_log /var/log/nginx/access.log combined if=$dontlog;"; next}1' /etc/nginx/nginx.conf > /etc/nginx/nginx.conf.new && \
|
|
mv /etc/nginx/nginx.conf.new /etc/nginx/nginx.conf; \
|
|
fi
|
|
|
|
ENV HEALTH_PORT="9000" \
|
|
HEALTH_URL="/api/system/status"
|
|
HEALTHCHECK \
|
|
--interval=5s \
|
|
--retries=5 \
|
|
--start-period=30s \
|
|
--timeout=25s \
|
|
CMD curl -A "HealthCheck: Docker/1.0" -s -f "http://127.0.0.1:${HEALTH_PORT}${HEALTH_URL}" &>/dev/null || exit 1
|