Sign inSign up

h0tmann/alpine_proftpd_sqlite

By h0tmann

•Updated about 2 years ago
Archived

Image
0

2.8K

h0tmann/alpine_proftpd_sqlite repository overview

⁠Alpine ProFTPD

Minimal alpine ProFTPD Docker-Image with Configuration-Template

Pkg Source: https://pkgs.alpinelinux.org/packages?name=proftpd⁠

Example docker-compose snippet:

  alpine_proftpd:
    container_name: alpine_proftpd
    image: h0tmann/alpine_proftpd:latest
    hostname: alpine_proftpd
    network_mode: host
    logging:
      options:
        max-file: "3"
        max-size: "128m"
        compress: "true"
    cap_add:
      - NET_ADMIN                                       # you can remove this capability if you dont have any firewall/iptables/nftables etc on your host
    environment:
      # System Variablen
      - TZ=Europe/Berlin                                # German time it alays good 🇩🇪
      - LANG=de_DE.UTF-8                                # German locale it alays good 🇩🇪
      # proFTPd App Variablen
      - APP_UID=850                                     # UID which the app (proftpd) runs with (default is "850")
      - APP_GID=850                                     # GID which the app (proftpd) runs with (default is "850")
      - VIRT_USER=true                                  # use virtual Users
#      - LOG_ROTATE=false                                # default: "false" - if enabled ":/var/lof/proftpd/" (in the container) will be automatically rotated
      # optionale proFTPd Variablen
      - PUBLIC_IP=123.123.123.123                       # default: "0.0.0.0" - Required in "network_mode: host" 
#      - FTP_PORT=21                                     # default: "21"
#      - SFTP_PORT=22                                    # default: "22" (if any value is set SFTP will be activated - if unset it will not be activated)
#      - PASSIVE_PORT_MIN=49152                          # default: "49152"  (depending on how many virtual servers you use you might want to limit this)
#      - PASSIVE_PORT_MAX=65534                          # default: "65534"  (depending on how many virtual servers you use you might want to limit this)
      # LIMITS
#      - MAX_INSTANCES=500                               # deault: "500" | http://www.proftpd.org/docs/modules/mod_core.html#MaxInstances
#      - MAX_CLIENTS=400 "Sorry max %m users, try again" # deault: "400 "Sorry max %m users, try again"" | http://www.proftpd.org/docs/modules/mod_auth.html#MaxClients
#      - MAX_CONNECTION_RATE=100                         # deault: "64" | http://www.proftpd.org/docs/modules/mod_auth.html#MaxClients
      # 
#      - ALLOW_OVERWRITE=on                              # on|off        | http://www.proftpd.org/docs/modules/mod_xfer.html#AllowOverwrite
#      - ROOT_LOGIN=off                                  # on|off        | http://www.proftpd.org/docs/modules/mod_auth.html#RootLogin
#      - USE_REVERSE_DNS=on                              # on|off        | http://www.proftpd.org/docs/modules/mod_core.html#UseReverseDNS
#      - USE_FTP_USERS=off                               # deault: "off" | http://www.proftpd.org/docs/modules/mod_auth.html#UseFtpUsers
#      - SFTP_AUTH_METHODS=publickey password            # hostbased|keyboard-interactive|password|publickey    http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPAuthMethods
      # FTP SSL Einstellungen
#      - ENABLE_FTP_SSL_TLS=false                        # default: false | if true will require "/etc/proftpd/ssl/cert.pem" & "/etc/proftpd/ssl/key.pem" (CA would be here: "/etc/proftpd/ssl/ca.pem")
#      - FTP_TLS_PROTOCOL=ALL                            # default: "ALL" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSProtocol
#      - FTP_TLS_CERT=cert.pem                           # default: "cert.pem" | Certificate filename in "/etc/proftpd/ssl/"
#      - FTP_TLS_KEY=key.pem                             # default: "key.pem" | Key filename in "/etc/proftpd/ssl/"
#      - FTP_TLS_OPTIONS=EnableDiags NoSessionReuseRequired AllowClientRenegotiations # default: "EnableDiags NoSessionReuseRequired AllowClientRenegotiations" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSOptions
#      - FTP_TLS_VERIFY_CLIENT=off                       # default: "off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSVerifyClient
#      - FTP_TLS_REQUIRED=off                            # default: "off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSRequired
#      - FTP_TLS_RENEGOTIATE=required off                # default: "required off" | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSRenegotiate
      # LOG Einstellungen
#      - ENABLE_LOGS=true                                # default: "true" [boolean]
#      - LOG_WTMP=off                                    # default: "off" | http://www.proftpd.org/docs/modules/mod_auth.html#WtmpLog
#      - LOG_EXT_FILE=extended_sftp_read_write.log       # default: "none" [filename string]
#      - LOG_EXT_ATTR=                                   # default: "" [filename string]
#      - LOG_SFTP_FILE=sftp.log                          # default: "none" | http://www.proftpd.org/docs/contrib/mod_sftp.html#SFTPLog
#      - LOG_TRANS_FILE=xfer.log                         # default: "xfer.log" | http://www.proftpd.org/docs/modules/mod_core.html#TransferLog
#      - LOG_SSL_TLS_FILE=tls.log                        # default: "tls.log"  | http://www.proftpd.org/docs/contrib/mod_tls.html#TLSLog
    volumes:
      - "/etc/timezone:/etc/timezone:ro"                # sets "/etc/timezone" to the same as the host
      - "./folder/host_keys/:/etc/ssh/:rw"
      - "./folder/log/:/var/log/proftpd/:rw"
      - "./folder/ssl/:/etc/proftpd/ssl/:rw"
      - "./folder/conf.d/:/etc/proftpd/conf.d/:rw"
      - "./folder/virtual/:/etc/proftpd/virtual/:rw"
      - "./folder/authorized_keys/:/etc/proftpd/authorized_keys/:rw"
    deploy:
      resources:
        limits:
          memory: 512M                                  # adjust to your needs
    restart: unless-stopped

Note: you can also run this docker-compose with specific ports - but it is not recommended if you want to use FTP:

    ports:
      - 22:22
      - 21:21

IPTABLES / NFTABLES:

On newer Systems you explizitely need to create the file /etc/modprobe.d/iptables.conf with this content:

options nf_conntrack_ftp ports=21

(change Port according to the Port you specified - on older Systems use options ip_conntrack_ftp ports=21) Now run the command modprobe nf_conntrack_ftp or on older Systems modprobe ip_conntrack_ftp. Highports now should open automatically and Passive Mode should work flawlessly.

Please keep in mind, that without network_mode: host, the rules in the config may need to be altered to have the wanted effect. As all requests are comming through the docker-network your docker-container is in. I personally recommend network_mode: host, as it also makes it way more easy to migrate from a plain installation to this dockerized version.

proFTPd needs public keys in the RFC4716-Format. In ordert to convert to this format use this command:

ssh-keygen -e -f ~/.ssh/id_rsa.pub -m RFC4716 > ~/.ssh/id_rsa.rfc4716.pub
⁠Virtual Users

use the files:

  • /etc/proftpd/virtual/proftpd.group
  • /etc/proftpd/virtual/proftpd.passwd

manually or with ftpasswd⁠ to create virtual Users.

Create the container and have fun!

Tag summary

Content type

Image

Digest

sha256:8a49b9436…

Size

31.3 MB

Last updated

about 2 years ago

docker pull h0tmann/alpine_proftpd_sqlite