Meshcentral Alpine with MongoDB support
1.0K
Docker Version of the amazing MeshCentral software.
While easier to setup and get up and running, you should still peer through the very informative official guides:
This image make use of a specialized database solution (MongoDB).
The preferred method to get this image up and running is through the use of docker-compose (examples below).
By filling out some of the options in the environment variables in the docker compose you can define some initial meshcentral settings and have it up and ready in no time. If you'd like to include settings not supported by the docker-compose file, you can also edit the config.json to your liking (you should really check the User's Guide for this) and place it in the meshcentral-data folder before initializing the container.
Updating settings is also easy after having the container initialized if you change your mind or want to tweak things. Just edit meshcentral-data/config.json and restart the container.
docker-compose.yml example:
version: '3.7'
networks:
meshcentralNet:
ipam:
driver: default
config:
- subnet: ${SUBNET}.0/24
services:
meshcentral:
restart: always
container_name: meshcentral
image: johann8/alpine-meshcentral:${MC_VERSION}
# Only for Apache comment out
#ports:
#- 127.0.0.1:8084:443 #MeshCentral will moan and try everything not to use port 80, but you can also use it if you so desire, just change the config.json according to your needs
#- 8086:443
environment:
- TZ=${TZ}
- HOSTNAME=${HOSTNAME_MC}
- REVERSE_PROXY=${REVERSE_PROXY}
- REVERSE_PROXY_TLS_PORT=${REVERSE_PROXY_TLS_PORT}
- NODE_ENV=${NODE_ENV}
- USE_TRAEFIK=${USE_TRAEFIK}
- PORT=${PORT}
- USE_MONGODB=${USE_MONGODB}
- MONGO_URL=${MONGO_URL}
- MONGO_DB_NAME=${MONGO_DB_NAME}
- MONGO_MC_USERNAME=${MONGO_MC_USERNAME}
- MONGO_MC_USER_PASSWORD=${MONGO_MC_USER_PASSWORD}
- IFRAME=${IFRAME}
- ALLOW_NEW_ACCOUNTS=${ALLOW_NEW_ACCOUNTS}
- WEBRTC=${WEBRTC}
- LOCALSESSIONRECORDING=${LOCALSESSIONRECORDING}
- MINIFY=${MINIFY}
volumes:
# config.json and other important files live here. A must for data persistence
- "${DOCKERDIR}/data/mc/data:/opt/meshcentral/meshcentral-data"
# where file uploads for users live
- "${DOCKERDIR}/data/mc/user_files:/opt/meshcentral/meshcentral-files"
# location for the meshcentral-backups
- "${DOCKERDIR}/data/mc/backups:/opt/meshcentral/meshcentral-backups"
# location for site customization files
- "${DOCKERDIR}/data/mc/web:/opt/meshcentral/meshcentral-web"
env_file:
- .env
depends_on:
- mongodb
networks:
- meshcentralNet
# mongodb container for meshcentral
mongodb:
image: mongo:latest
container_name: mongodb
restart: "always"
environment:
- MONGO_INITDB_ROOT_USERNAME=${MONGO_INITDB_ROOT_USERNAME}
- MONGO_INITDB_ROOT_PASSWORD=${MONGO_INITDB_ROOT_PASSWORD}
volumes:
# mongodb data-directory - A must for data persistence
- "${DOCKERDIR}/data/mongodb/dbdata:/data/db"
env_file:
- .env
networks:
- meshcentralNet
docker-compose.override.yml example:
version: "3.7"
services:
meshcentral:
labels:
- "traefik.enable=true"
### ==== to https ====
- "traefik.http.routers.meshcentral-secure.entrypoints=websecure"
- "traefik.http.routers.meshcentral-secure.rule=Host(`$HOSTNAME0.$DOMAINNAME`)"
- "traefik.http.routers.meshcentral-secure.tls=true"
- "traefik.http.routers.meshcentral-secure.tls.certresolver=production" # für eigene Zertifikate
### ==== to service ====
- "traefik.http.routers.meshcentral-secure.service=meshcentral"
- "traefik.http.services.meshcentral.loadbalancer.server.port=${PORT}"
- "traefik.http.services.meshcentral.loadbalancer.passHostHeader=true"
- "traefik.docker.network=proxy"
### ==== redirect to authelia for secure login ====
- "traefik.http.routers.meshcentral-secure.middlewares=secHeaders@file,traefik-compress@file"
#- "traefik.http.routers.meshcentral-secure.middlewares=authelia@docker,rate-limit@file,secHeaders@file"
networks:
- proxy
networks:
proxy:
external: true
.env example:
#
### === SYSTEM ===
#
# your time zone
TZ="Europe/Berlin"
DOCKERDIR=/opt/meshcentral
#
### === Network ===
#
HOSTNAME_MC=mc.changeme.de
DOMAINNAME=changeme.de
HOSTNAME0=mc
PORT=4430
SUBNET=172.26.8
REVERSE_PROXY=${HOSTNAME_MC}
REVERSE_PROXY_TLS_PORT=443
#
### === APP Meshcentral ===
#
# Set MeshCentral to Produktion
NODE_ENV=production
# meshcentral version
MC_VERSION=latest
# RP traefik
USE_TRAEFIK="true"
# use mongodb
# generate password: pwgen -1cnsB 25 1
USE_MONGODB=true
MONGO_MC_USERNAME=meshuser
MONGO_MC_USER_PASSWORD=User-PW-ChangeMe135
MONGO_DB_NAME=meshcentral
# set already exist mongo connection string url here
MONGO_URL=
# or set following init params for new mongodb, use it with docker-compose file with mongodb version
# pwgen -1cnsB 30 1
MONGO_INITDB_ROOT_USERNAME=admin
MONGO_INITDB_ROOT_PASSWORD=Root-PW-ChangeMe579
#set to true if you wish to enable iframe support
IFRAME=false
#set to false if you want disable self-service creation of new accounts besides the first (admin)
ALLOW_NEW_ACCOUNTS=false
#set to true to enable WebRTC - per documentation it is not officially released with meshcentral, but is solid enough to work with. Use with caution
WEBRTC=true
# set to true to allow session recording
LOCALSESSIONRECORDING=false
# set to enable or disable minification of json, reduces traffic
MINIFY=true
If you do not wish to use the prebuilt image, you can also easily build it yourself. Just make sure to include config.json.template and startup.sh if you do not change the Dockerfile.
Content type
Image
Digest
sha256:07127e166…
Size
399.9 MB
Last updated
about 2 years ago
docker pull johann8/alpine-meshcentral