Minimal alpine ProFTPD Docker-Image with Configuration-Template
Pkg Source: https://pkgs.alpinelinux.org/packages?name=proftpd
Example docker-compose snippet:
alpine_proftpd:
container_name: alpine_proftpd
image: h0tmann/alpine_proftpd:latest
hostname: alpine_proftpd
network_mode: host
logging:
options:
max-file: "3"
max-size: "128m"
compress: "true"
cap_add:
- NET_ADMIN # you can remove this capability if you dont have any firewall/iptables/nftables etc on your host
environment:
# System Variablen
- TZ=Europe/Berlin # German time it alays good 🇩🇪
- LANG=de_DE.UTF-8 # German locale it alays good 🇩🇪
# proFTPd App Variablen
- APP_UID=850 # UID which the app (proftpd) runs with (default is "850")
- APP_GID=850 # GID which the app (proftpd) runs with (default is "850")
- VIRT_USER=true # use virtual Users
# - LOG_ROTATE=false # default: "false" - if enabled ":/var/lof/proftpd/" (in the container) will be automatically rotated
# optionale proFTPd Variablen
- PUBLIC_IP=123.123.123.123 # default: "0.0.0.0" - Required in "network_mode: host"
# - FTP_PORT=21 # default: "21"
# - SFTP_PORT=22 # default: "22" (if any value is set SFTP will be activated - if unset it will not be activated)
# - PASSIVE_PORT_MIN=49152 # default: "49152" (depending on how many virtual servers you use you might want to limit this)
# - PASSIVE_PORT_MAX=65534 # default: "65534" (depending on how many virtual servers you use you might want to limit this)
# LIMITS
# - MAX_INSTANCES=500 # deault: "500" | http://www.proftpd.org/docs/modules/mod_core.html#MaxInstances
# - MAX_CLIENTS=400 "Sorry max %m users, try again" # deault: "400 "Sorry max %m users, try again"" | http://www.proftpd.org/docs/modules/mod_auth.html#MaxClients
# - MAX_CONNECTION_RATE=100 # deault: "64" | http://www.proftpd.org/docs/modules/mod_auth.html#MaxClients
#
# - ALLOW_OVERWRITE=on # on|off | http://www.proftpd.org/docs/modules/mod_xfer.html#AllowOverwrite
# - ROOT_LOGIN=off # on|off | http://www.proftpd.org/docs/modules/mod_auth.html#RootLogin
# - USE_REVERSE_DNS=on # on|off | http://www.proftpd.org/docs/modules/mod_core.html#UseReverseDNS
# - USE_FTP_USERS=off # deault: "off" | http://www.proftpd.org/docs/modules/mod_auth.html#UseFtpUsers
# - SFTP_AUTH_METHODS=publickey password # hostbased|keyboard-interactive|password|publickey http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPAuthMethods
# FTP SSL Einstellungen
# - ENABLE_FTP_SSL_TLS=false # default: false | if true will require "/etc/proftpd/ssl/cert.pem" & "/etc/proftpd/ssl/key.pem" (CA would be here: "/etc/proftpd/ssl/ca.pem")
# - FTP_TLS_PROTOCOL=ALL # default: "ALL" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSProtocol
# - FTP_TLS_CERT=cert.pem # default: "cert.pem" | Certificate filename in "/etc/proftpd/ssl/"
# - FTP_TLS_KEY=key.pem # default: "key.pem" | Key filename in "/etc/proftpd/ssl/"
# - FTP_TLS_OPTIONS=EnableDiags NoSessionReuseRequired AllowClientRenegotiations # default: "EnableDiags NoSessionReuseRequired AllowClientRenegotiations" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSOptions
# - FTP_TLS_VERIFY_CLIENT=off # default: "off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSVerifyClient
# - FTP_TLS_REQUIRED=off # default: "off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSRequired
# - FTP_TLS_RENEGOTIATE=required off # default: "required off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSRenegotiate
# LOG Einstellungen
# - ENABLE_LOGS=true # default: "true" [boolean]
# - LOG_WTMP=off # default: "off" | http://www.proftpd.org/docs/modules/mod_auth.html#WtmpLog
# - LOG_EXT_FILE=extended_sftp_read_write.log # default: "none" [filename string]
# - LOG_EXT_ATTR= # default: "" [filename string]
# - LOG_SFTP_FILE=sftp.log # default: "none" | http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPLog
# - LOG_TRANS_FILE=xfer.log # default: "xfer.log" | http://www.proftpd.org/docs/modules/mod_core.html#TransferLog
# - LOG_SSL_TLS_FILE=tls.log # default: "tls.log" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSLog
volumes:
- "/etc/timezone:/etc/timezone:ro" # sets "/etc/timezone" to the same as the host
- "./folder/host_keys/:/etc/ssh/:rw"
- "./folder/log/:/var/log/proftpd/:rw"
- "./folder/ssl/:/etc/proftpd/ssl/:rw"
- "./folder/conf.d/:/etc/proftpd/conf.d/:rw"
- "./folder/virtual/:/etc/proftpd/virtual/:rw"
- "./folder/authorized_keys/:/etc/proftpd/authorized_keys/:rw"
deploy:
resources:
limits:
memory: 512M # adjust to your needs
restart: unless-stopped
Note: you can also run this docker-compose with specific ports - but it is not recommended if you want to use FTP:
ports:
- 22:22
- 21:21
IPTABLES / NFTABLES:
On newer Systems you explizitely need to create the file /etc/modprobe.d/iptables.conf with this content:
options nf_conntrack_ftp ports=21
(change Port according to the Port you specified - on older Systems use options ip_conntrack_ftp ports=21)
Now run the command modprobe nf_conntrack_ftp or on older Systems modprobe ip_conntrack_ftp.
Highports now should open automatically and Passive Mode should work flawlessly.
Please keep in mind, that without network_mode: host, the rules in the config may need to be altered to have the wanted effect.
As all requests are comming through the docker-network your docker-container is in.
I personally recommend network_mode: host, as it also makes it way more easy to migrate from a plain installation to this dockerized version.
proFTPd needs public keys in the RFC4716-Format.
In ordert to convert to this format use this command:
ssh-keygen -e -f ~/.ssh/id_rsa.pub -m RFC4716 > ~/.ssh/id_rsa.rfc4716.pub
use the files:
/etc/proftpd/virtual/proftpd.group/etc/proftpd/virtual/proftpd.passwdmanually or with ftpasswd to create virtual Users.
Create the container and have fun!
Content type
Image
Digest
sha256:8a49b9436…
Size
31.3 MB
Last updated
about 2 years ago
docker pull h0tmann/alpine_proftpd_sqlite