Skip to content

Commit 11c61c1

Browse files
renovate[bot]Zoey2936
authored andcommitted
update alpine/php logs/enable ssl_early_data
Signed-off-by: Zoey <[email protected]>
1 parent 740d4c7 commit 11c61c1

File tree

6 files changed

+13
-6
lines changed

6 files changed

+13
-6
lines changed

Caddy.Dockerfile

+1-1
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
FROM caddy:2.7.6 as caddy
22

3-
FROM alpine:3.19.0
3+
FROM alpine:3.19.1
44
RUN apk add --no-cache ca-certificates tzdata
55
COPY --from=caddy /usr/bin/caddy /usr/bin/caddy
66
COPY Caddyfile /etc/caddy/Caddyfile

Dockerfile

+5-5
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM --platform="$BUILDPLATFORM" alpine:3.19.0 as frontend
1+
FROM --platform="$BUILDPLATFORM" alpine:3.19.1 as frontend
22
COPY frontend /build/frontend
33
COPY global/certbot-dns-plugins.json /build/frontend/certbot-dns-plugins.json
44
ARG NODE_ENV=production \
@@ -12,7 +12,7 @@ COPY darkmode.css /build/frontend/dist/css/darkmode.css
1212
COPY security.txt /build/frontend/dist/.well-known/security.txt
1313

1414

15-
FROM --platform="$BUILDPLATFORM" alpine:3.19.0 as backend
15+
FROM --platform="$BUILDPLATFORM" alpine:3.19.1 as backend
1616
SHELL ["/bin/ash", "-eo", "pipefail", "-c"]
1717
COPY backend /build/backend
1818
COPY global/certbot-dns-plugins.json /build/backend/certbot-dns-plugins.json
@@ -30,7 +30,7 @@ RUN apk add --no-cache ca-certificates nodejs-current yarn && \
3030
yarn cache clean --all
3131

3232

33-
FROM --platform="$BUILDPLATFORM" alpine:3.19.0 as crowdsec
33+
FROM --platform="$BUILDPLATFORM" alpine:3.19.1 as crowdsec
3434

3535
ARG CSNB_VER=v1.0.6-rc5
3636

@@ -48,13 +48,13 @@ RUN apk add --no-cache ca-certificates git build-base && \
4848
sed -i "s|BAN_TEMPLATE_PATH=.*|BAN_TEMPLATE_PATH=/data/etc/crowdsec/ban.html|g" /src/crowdsec-nginx-bouncer/lua-mod/config_example.conf && \
4949
sed -i "s|CAPTCHA_TEMPLATE_PATH=.*|CAPTCHA_TEMPLATE_PATH=/data/etc/crowdsec/captcha.html|g" /src/crowdsec-nginx-bouncer/lua-mod/config_example.conf
5050

51-
FROM zoeyvid/nginx-quic:243
51+
FROM zoeyvid/nginx-quic:247
5252
SHELL ["/bin/ash", "-eo", "pipefail", "-c"]
5353

5454
ARG CRS_VER=v4.0/dev
5555

5656
COPY rootfs /
57-
COPY --from=zoeyvid/certbot-docker:19 /usr/local /usr/local
57+
COPY --from=zoeyvid/certbot-docker:20 /usr/local /usr/local
5858
COPY --from=zoeyvid/curl-quic:364 /usr/local/bin/curl /usr/local/bin/curl
5959

6060
RUN apk add --no-cache ca-certificates tzdata tini \

rootfs/usr/local/bin/start.sh

+3
Original file line numberDiff line numberDiff line change
@@ -278,6 +278,7 @@ if [ "$PHP81" = "true" ]; then
278278
mkdir -vp /data/php
279279
cp -vrnT /etc/php81 /data/php/81
280280
sed -i "s|listen =.*|listen = /run/php81.sock|" /data/php/81/php-fpm.d/www.conf
281+
sed -i "s|;error_log =|error_log = /proc/self/fd/2|g" /data/php/81/php-fpm.conf
281282
sed -i "s|include=.*|include=/data/php/81/php-fpm.d/*.conf|g" /data/php/81/php-fpm.conf
282283

283284
elif [ "$FULLCLEAN" = "true" ]; then
@@ -310,6 +311,7 @@ if [ "$PHP82" = "true" ]; then
310311
mkdir -vp /data/php
311312
cp -vrnT /etc/php82 /data/php/82
312313
sed -i "s|listen =.*|listen = /run/php82.sock|" /data/php/82/php-fpm.d/www.conf
314+
sed -i "s|;error_log =|error_log = /proc/self/fd/2|g" /data/php/82/php-fpm.conf
313315
sed -i "s|include=.*|include=/data/php/82/php-fpm.d/*.conf|g" /data/php/82/php-fpm.conf
314316

315317
elif [ "$FULLCLEAN" = "true" ]; then
@@ -342,6 +344,7 @@ if [ "$PHP83" = "true" ]; then
342344
mkdir -vp /data/php
343345
cp -vrnT /etc/php83 /data/php/83
344346
sed -i "s|listen =.*|listen = /run/php83.sock|" /data/php/83/php-fpm.d/www.conf
347+
sed -i "s|;error_log =|error_log = /proc/self/fd/2|g" /data/php/83/php-fpm.conf
345348
sed -i "s|include=.*|include=/data/php/83/php-fpm.d/*.conf|g" /data/php/83/php-fpm.conf
346349

347350
elif [ "$FULLCLEAN" = "true" ]; then

rootfs/usr/local/nginx/conf/conf.d/include/proxy-location.conf

+1
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ proxy_set_header X-Real-IP $remote_addr;
66
proxy_set_header Accept-Encoding "";
77
proxy_set_header Host $host;
88

9+
proxy_set_header Early-Data $ssl_early_data;
910
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
1011
proxy_ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA;
1112

rootfs/usr/local/nginx/conf/conf.d/include/proxy.conf

+1
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ proxy_set_header X-Real-IP $remote_addr;
66
proxy_set_header Accept-Encoding "";
77
proxy_set_header Host $host;
88

9+
proxy_set_header Early-Data $ssl_early_data;
910
proxy_ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3;
1011
proxy_ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384:DHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES256-SHA256:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:DES-CBC3-SHA;
1112

rootfs/usr/local/nginx/conf/conf.d/include/tls-ciphers.conf

+2
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
ssl_early_data on;
2+
13
ssl_stapling on;
24
ssl_stapling_verify on;
35

0 commit comments

Comments
 (0)