Sign inSign up

clcavanaugh/ya-vsftpd

By clcavanaugh

•Updated 5 days ago

Yet Another VSFTPD Docker image

Image
Networking
Integration & delivery
Web servers
0

4.8K

clcavanaugh/ya-vsftpd repository overview

⁠Contents

⁠Features

Docker Pulls

  • Ubuntu LTS image based
  • Support for adding multiple virtual users with separate passwords and home directories
    • Scripted user creation via the exposed add-ftpuser.sh
    • Added option to block new user creation after startup
    • Added multiuser backup of the hash db file
  • The most recent version and the latest tagged image now receive weekly updates every tuesday morning
  • [TO DO] Scripted User deletion
  • [TO DO] Centralized logging integration outside of Docker.
  • [TO DO] Create more secure password management, or potentially LDAP/Vault integration
  • [TO DO] Image size reduction, and further automation...

⁠Installation

⁠Notes

Core vsftpd changes should nearly all be in the env file. If you the ftp.env file exists alongside the docker-compose.yml or the docker-run.sh script as described below, it should pick up the changes you made to the variables within. Note that i've allocated thirty PASV ports on the container side, to avoid conflicts

I've also included a script within the container to add users after the first run, that can be hit by running docker exec -i -t <container-name> /usr/bin/add-ftpuser.sh, note that it can take arguments such as -u <user>, -p <pass>, or -v to trigger output of any supplied info to stdout. You can also leave the password blank to get a secure prompt to enter the password, note that the -v command will show this secured input to stdout as well.

Note that I've added an envvar of SINGLE_USER, and added that to the default .env file described below. If the Variable is set, it will prevent the adduser.sh script from being used while the container runs. If SINGLE_USER is not set, a new feature of the add-ftpuser.sh script, is a backup iof the hash db to the ROOT_DIR to enable users and their logins to be persistent or restored. Note: I'm working on updating the scripts to check for this db file, so at present it is just a backup with a manual restore process.

⁠Docker run
#!/bin/bash

docker run -d \
  --env-file ftp.env \
  --volume ${ROOT_DIR}/data/:/home/vsftpd/ \
  --volume ${ROOT_DIR}/logs/:/var/log/vsftpd/ \
  -p "20:20" \
  -p "21:21" \
  -p 21100-21130:${PASV_MIN_PORT}-${PASV_MAX_PORT}" \
  --name vsftpd \
  clcavanaugh/ya-vsftpd:latest
⁠Docker compose
# FTP Container
services:
  ftp:
    env_file: ./ftp.env
    tty: true
    container_name: ftp
    image: clcavanaugh/ya-vsftpd:latest
    restart: unless-stopped
    volumes:
      - ${ROOT_DIR}/data/:/home/vsftpd/
      - ${ROOT_DIR}/logs/:/var/log/vsftpd/
    ports:
      - 20:20
      - 21:21
      - 21100-21130:${PASV_MIN_PORT}-${PASV_MAX_PORT}

⁠Docker .env file
FTP_USER=ftpusers
FTP_PASS=MakeABetterPassword
PASV_ADDRESS=ftp.example.com
PASV_ADDRESS_RESOLVE=YES
PASV_MIN_PORT=21100
PASV_MAX_PORT=21130
USER_ID=4040
GROUP_ID=4040
ROOT_DIR=/srv/ftp
SINGLE_USER=True

⁠Env Variables

⁠FTP_USER

Default: **String** Default is set to ftpuser if not changed when creating the container.

⁠FTP_PASS

Default: **Random** Randomly generated 16 char AlphaNumeric password if not changed when creating the container. Password is output in the logs on first startup.

⁠PASV_ADDRESS

Default: **IPv4** Default value is pulled from the host's IP if the value is not set when creating the container. If you provide a fqdn/hostname, ensure PASV_ADDR_RESOLVE is left at its default (YES)

⁠PASV_ADDR_RESOLVE

Default: YES Formatted for the vsftpd.conf file, this enables the resolution of the hostname entered in PASV_ADDRESS.

⁠PASV_ENABLE

Default: YES Formatted for the vsftpd.conf file, this enables Passive mode for the server.

⁠PASV_MIN_PORT

Default:21100 This can be set to start at any port number. This sets the lowest port that the Container will listen at for the Passive ftp server connectivity. For higher compatability, and a lower danger of collisions, set it to a port in the Private Port range: 49152-65535

⁠PASV_MAX_PORT

Default: 21130 This can be set to start at any port number. This sets the highest port that the Container will listen at for the Passive ftp server connectivity. For higher compatability, and a lower danger of collisions, set it to a port in the Private Port range: 49152-65535

⁠XFERLOG_STD_FORMAT

Default: NO I've left this in as logging upgrades are in my goals, and XFERLOG_ENABLE is enabled in the vsftpd.conf file

⁠LOG_STDOUT

Default: **Boolean** If left unset, this will not output logging to STDOUT; if Set, Standard output will be redirected to /var/log/vsftpd/vsftpd.log

⁠FILE_OPEN_MODE

Default: 0666 I chose the default above, as fairly safe base access for a ftp server, feel free to adjust as you see fit in that same format.

⁠LOCAL_UMASK

Default: 077 I chose this Umask to lock down access to the files between virtual users by default. If it is too strict, feel free to adjust it to 022 or 011 if you aren't that concerned with virtual users accessing each other's files.

⁠PASV_PROMISCUOUS

Default: NO Left this at the Service Default. Change it if you know what you are doing.

⁠PORT_PROMISCUOUS

Default: NO Left this at the Service Default. Change it if you know what you are doing.

⁠USER_ID

Default: 3010 Arbitrary number higher than standard UID's tend to go, feel free to adjust it to fit the UID you select to run your container, or root, if you are using root to run your containers (hint: please dont).

⁠GROUP_ID

Default: 3010 Arbitrary number higher than standard GID's tend to go, feel free to adjust it to fit the GID you select to run your container, or root, if you are using root to run your containers (hint: please dont).

⁠SINGLE_USER

Default: **Boolean** I added this Option to help an administrator lock down the container to a single virtual user if they preferred, effectively removing the add_ftpuser.sh script, and preventing both ftpuser password changes outside of editing the .env file and rebuilding the docker container. Theoretically this may make it a touch easier to scale, and track. This also prevents the Hash DB that stores usernames and passwords of virtual users from getting backed up to the root ftp home (wherever you mount the /home/vsftpd Volume).

Tag summary

Content type

Image

Digest

sha256:781f84564…

Size

85.9 MB

Last updated

5 days ago

docker pull clcavanaugh/ya-vsftpd