Rootless container for deploying FreshRSS on Kubernetes.
6.1K

This repository provides a rootless Docker image for FreshRSS, a self-hosted RSS feed aggregator that allows you to collect and read news and articles from various sources in one place. FreshRSS is lightweight, customizable, and supports multiple users.
Our rootless Docker image is specifically designed to run securely in Kubernetes clusters without granting root privileges. It includes FreshRSS, running on NGINX and PHP-FPM, optimized for secure, rootless operation.
Security is a critical concern in containerized environments. Running containers with root privileges can pose significant security risks, such as privilege escalation and unauthorized access. By utilizing a rootless Docker image, you enhance the security of your Kubernetes cluster by ensuring that the application operates with the least privileges necessary. This image differs from the original project image by enabling rootless execution, making it more suitable for environments where security is a priority.
TZ environment variable.This container uses the user "freshrss" with UID 2000 and GID 2000 for running all his processes.
Necessary Volumes:
/opt/freshrss/data /tmp Optional Volumes:
/opt/freshrss/extensions Europe/Zurich).The following environment variables from the original Docker image are not supported in this rootless version:
FRESHRSS_INSTALLFRESHRSS_USERPlease use the installation assistant provided by FreshRSS for setup.
You can override the configuration using config maps by mounting them to:
/opt/freshrss/data/config.custom.php/opt/freshrss/data/config-user.custom.phpCreate a freshrss-deployment.yaml file with the following content:
apiVersion: apps/v1
kind: Deployment
metadata:
name: freshrss
spec:
replicas: 1
selector:
matchLabels:
app: freshrss
template:
metadata:
labels:
app: freshrss
spec:
securityContext:
runAsUser: 2000
runAsGroup: 2000
fsGroup: 2000
containers:
- name: freshrss
image: ghcr.io/erhardtconsulting/freshrss
env:
- name: TZ
value: "Europe/Zurich"
volumeMounts:
- name: data
mountPath: /opt/freshrss/data
- name: tmp-tmpfs
mountPath: /tmp
volumes:
- name: data
persistentVolumeClaim:
claimName: freshrss-data
- name: tmp-tmpfs
emptyDir:
medium: Memory
Apply the deployment:
kubectl apply -f freshrss-deployment.yaml
See docker-compose.yaml.
Start the container:
docker-compose up -d
For issues related to the container itself, please open an issue in this repository. For issues concerning the FreshRSS application, refer to the original FreshRSS repository.
Erhardt Consulting GmbH is not affiliated with the FreshRSS project or its contributors. This rootless Docker image is provided "as is" to facilitate the deployment of FreshRSS in Kubernetes clusters without root privileges. All images are provided without warranty of any kind.
Please report any issues unrelated to containerization directly to the FreshRSS project. The code for the container configuration is provided under the terms of the MIT License. Note that this license does not apply to the application code within the containers, which may be distributed under different, possibly more restrictive licenses. Users are responsible for complying with the licenses of the underlying applications.
Content type
Image
Digest
sha256:4e4b7476c…
Size
236.1 MB
Last updated
3 days ago
docker pull erhardtconsulting/freshrss