Sign inSign up

imocence/nginx-modsecuity

By imocence

•Updated almost 3 years ago

waf build nginx-modsecuity

Image
0

443

imocence/nginx-modsecuity repository overview

#Use Dockerfile file content

FROM imocence/alpine:3.15

COPY entrypoint.sh /usr/bin/

WORKDIR /opt

EXPOSE 80 443

VOLUME ["/opt/conf.d", "/opt/html", "/opt/logs"]

RUN apk add --no-cache build-base automake autoconf libtool gcc git linux-headers zlib-dev pcre-dev openssl-dev geoip-dev pcre geoip libstdc++ \
&& cd /opt && git clone --depth=1 https://github.com/ssdeep-project/ssdeep.git \
&& cd /opt/ssdeep && autoreconf -i && ./configure && make && make install && make clean \
&& cd /opt && git clone --depth=1 -b v3/master https://github.com/SpiderLabs/ModSecurity.git && cd /opt/ModSecurity \
&& git submodule init && git submodule update && ./build.sh && ./configure && make && make install && make clean \
&& cp modsecurity.conf-recommended /usr/local/modsecurity/modsecurity.conf && cp unicode.mapping /usr/local/modsecurity/ \
&& cd /opt && git clone --depth=1 https://github.com/SpiderLabs/ModSecurity-nginx.git \
&& cd /opt && N_VER=1.25.2 && wget -c http://nginx.org/download/nginx-$N_VER.tar.gz && tar zxf nginx-*.tar.gz && mv nginx-$N_VER nginx \
&& cd /opt/nginx && ./configure --prefix=/etc/nginx --sbin-path=/usr/sbin/nginx --modules-path=/etc/nginx/modules \
--conf-path=/etc/nginx/nginx.conf --error-log-path=/opt/logs/error.log --http-log-path=/opt/logs/access.log --with-compat \
--add-dynamic-module=/opt/ModSecurity-nginx --with-http_gzip_static_module --with-http_auth_request_module \
--with-http_geoip_module --with-http_gunzip_module --with-http_random_index_module --with-http_realip_module \
--with-http_slice_module --with-http_ssl_module --with-http_sub_module --with-http_stub_status_module \
--with-http_v2_module --with-http_secure_link_module --with-stream --with-stream_ssl_module --with-stream_ssl_preread_module \
--with-stream_realip_module --with-stream_geoip_module --with-http_dav_module && make && make install \
&& make modules && cp objs/ngx_http_modsecurity_module.so /etc/nginx/modules/ \
&& cd /opt && git clone https://github.com/SpiderLabs/owasp-modsecurity-crs.git && cd owasp-modsecurity-crs \
&& cp -r rules/ /usr/local/modsecurity/ && cp crs-setup.conf.example /usr/local/modsecurity/crs-setup.conf \
&& cd /usr/local/modsecurity/rules && mv REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf.example REQUEST-900-EXCLUSION-RULES-BEFORE-CRS.conf \
&& mv RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf.example RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf \
&& apk del --purge build-base automake autoconf libtool gcc git linux-headers pcre-dev zlib-dev openssl-dev geoip-dev \
&& rm -rf /opt/*.tar.gz /opt/ssdeep /opt/ModSecurity /opt/ModSecurity-nginx /opt/owasp-modsecurity-crs /opt/nginx /tmp/* /var/cache/apk/* \
&& sed -i -E 's/events\s*\{/include \/opt\/conf.d\/*.conf;\n\nevents {/g' /etc/nginx/nginx.conf \
&& sed -i '1i\load_module /etc/nginx/modules/ngx_http_modsecurity_module.so;' /etc/nginx/nginx.conf \
&& sed -i '8i\SecRuleEngine On\ninclude crs-setup.conf\ninclude rules/*.conf' /usr/local/modsecurity/modsecurity.conf \
&& sed -i '21i\    modsecurity on;\n    modsecurity_rules_file /usr/local/modsecurity/modsecurity.conf;\n' /etc/nginx/nginx.conf \
&& sed -i "s!/var/log/modsec_audit.log!/opt/logs/modsec_audit.log!g" /usr/local/modsecurity/modsecurity.conf \
&& sed -i "s!#gzip!gzip!g" /etc/nginx/nginx.conf && chmod +x /usr/bin/entrypoint.sh 

ENTRYPOINT ["/usr/bin/entrypoint.sh"]

#Use docker-compose.yml file content

version: '2'
services:
  web:
    image: imocence/nginx-modsecuity:v3.0.10
    container_name: modsec
    network_mode: bridge
    ports:
      - "0.0.0.0:9292:80"
    volumes:
      - ./conf.d/:/opt/conf.d/
      - ./html/:/opt/html/
      - ./logs/:/opt/logs/
    restart: unless-stopped

Tag summary

Content type

Image

Digest

sha256:e56d53bcf…

Size

75.7 MB

Last updated

almost 3 years ago

docker pull imocence/nginx-modsecuity