Production-ready rclone Docker image based on LinuxServer.io Alpine with S6 Overlay and security har
2.1K
š Deutsche Versionā | š¬š§ English Version
š³ Docker Hub: mildman1848/rcloneā
A production-ready Docker image for rcloneā based on the LinuxServer.io Alpine baseimage with enhanced security features, automatic secret management, full LinuxServer.io compliance, and CI/CD integration. rclone is a command-line program to manage files on cloud storage.
# Clone repository
git clone https://github.com/mildman1848/rclone.git
cd rclone
# Complete setup (environment + secrets)
make setup
# Start container
docker-compose up -d
# Clone repository
git clone https://github.com/mildman1848/rclone.git
cd rclone
# Configure environment
cp .env.example .env
# Adjust .env as needed
# Generate secure secrets
make secrets-generate
# Start container (docker-compose.override.yml provides security hardening)
docker-compose up -d
docker run -d \
--name rclone \
-p 5572:5572 \
-v /path/to/config:/config \
-v /path/to/data:/data \
-e PUID=1000 \
-e PGID=1000 \
-e TZ=Europe/Berlin \
--restart unless-stopped \
mildman1848/rclone:latest
# Show help
make help
# Complete setup
make setup # Initial setup (env + secrets)
make env-setup # Create environment from .env.example
make env-validate # Validate environment
# Secret Management (Enhanced)
make secrets-generate # Generate secure secrets (512-bit JWT, 256-bit API)
make secrets-rotate # Rotate secrets (with backup)
make secrets-clean # Clean up old secret backups
make secrets-info # Show secret status
# Build & Test (Enhanced with OCI Manifest Lists)
make build # Build image for current platform
make build-multiarch # Multi-architecture build (legacy)
make build-manifest # LinuxServer.io style manifest lists (recommended)
make inspect-manifest # Inspect manifest lists (multi-arch details)
make validate-manifest # Validate OCI manifest compliance
make test # Test container (with health checks)
make security-scan # Run comprehensive security scan (Trivy + CodeQL)
make trivy-scan # Run Trivy vulnerability scan only
make codeql-scan # Run CodeQL static code analysis
make validate # Validate Dockerfile
# Container Management
make start # Start container
make stop # Stop container
make restart # Restart container
make status # Show container status and health
make logs # Show container logs
make shell # Open shell in container
# Development
make dev # Start development container
# Release
make release # Complete release workflow
make push # Push image to registry
# Build image
docker build -t mildman1848/rclone:latest .
# With specific arguments
docker build \
--build-arg RCLONE_VERSION=v1.71.0 \
--build-arg BUILD_DATE=$(date -u +'%Y-%m-%dT%H:%M:%SZ') \
-t mildman1848/rclone:latest .
# Use production configuration with enhanced security
docker-compose -f docker-compose.yml -f docker-compose.production.yml up -d
# Or use the override file for automatic security hardening
docker-compose up -d # Automatically applies docker-compose.override.yml
Configuration is done via a .env file containing all environment variables:
# Create .env from template
cp .env.example .env
# Adjust values as needed
nano .env
The .env.example contains all available options with documentation and links to the official rclone documentation.
| Variable | Default | Description |
|---|---|---|
PUID | 1000 | User ID for file permissions |
PGID | 1000 | Group ID for file permissions |
TZ | Europe/Berlin | Timezone |
PORT | 5572 | Internal container port (rclone Web GUI) |
EXTERNAL_PORT | 5572 | External host port (rclone Web GUI) |
CONFIG_PATH | /config | Configuration path in container |
DATA_PATH | /data | Data path in container |
LOG_LEVEL | info | Log level (debug, info, warn, error) |
RCLONE_MODE | rcd | rclone operation mode (rcd/serve) |
RCLONE_CONFIG | /config/rclone/rclone.conf | rclone configuration file |
RCLONE_LOG_LEVEL | INFO | rclone log level (DEBUG, INFO, NOTICE, ERROR) |
š Full Documentation: See .env.exampleā for all available options
FILE__ Prefix (Recommended):
The image supports the LinuxServer.io standard FILE__ prefix for secure secret management:
# .env file - FILE__ prefix secrets for rclone
FILE__RCLONE_CONFIG_PASS=/run/secrets/rclone_config_pass
FILE__RCLONE_WEB_GUI_PASSWORD=/run/secrets/rclone_web_pass
FILE__RCLONE_PASSWORD=/run/secrets/rclone_password
# Docker Compose example
environment:
- FILE__RCLONE_CONFIG_PASS=/run/secrets/rclone_config_pass
- FILE__RCLONE_WEB_GUI_PASSWORD=/run/secrets/rclone_web_pass
Enhanced Secret Generation:
# Secure secret generation (improved algorithms)
make secrets-generate # 512-bit JWT, 256-bit API keys
# Secret rotation with backup
make secrets-rotate
# Check secret status
make secrets-info
Supported Secrets (rclone-specific):
| FILE__ Variable | Description | Security | Make Generated |
|---|---|---|---|
FILE__RCLONE_CONFIG_PASS | rclone config encryption password | ā High | ā |
FILE__RCLONE_WEB_GUI_PASSWORD | rclone Web GUI password | ā High | ā |
FILE__RCLONE_PASSWORD | rclone authentication password | ā High | ā |
FILE__SESSION_SECRET | Session secret (256-bit) | ā High | ā |
FILE__BACKUP_KEY | Backup encryption key | ā High | ā |
š LinuxServer.io Documentation: FILE__ Prefixā
| Container Path | Description |
|---|---|
/config | rclone configuration files, cache, and logs |
/data | Cloud storage mount points and data |
The container supports two primary operation modes:
RCLONE_MODE=rcdRCLONE_MODE=serve# rcd mode (Web GUI) - Default
RCLONE_MODE=rcd
# serve mode (File Server)
RCLONE_MODE=serve
RCLONE_SERVE_PROTOCOL=http # or webdav, ftp, sftp
The image uses S6 Overlay v3 with optimized services following LinuxServer.io standards:
init-branding ā init-mods-package-install ā init-custom-files ā init-secrets ā init-rclone-config ā rclone
Docker Mods Support:
# Single mod
DOCKER_MODS=linuxserver/mods:universal-cron
# Multiple mods (separated by |)
DOCKER_MODS=linuxserver/mods:universal-cron|linuxserver/mods:rclone-custom
Custom Scripts:
# Scripts in /custom-cont-init.d are executed before services
docker run -v ./my-scripts:/custom-cont-init.d:ro mildman1848/rclone
UMASK Support:
# Default: 022 (files: 644, directories: 755)
UMASK=022
š Available Mods: mods.linuxserver.ioā
š”ļø Security Policy: See our Security Policyā for reporting vulnerabilities and security guidelines
The image implements comprehensive security measures:
abc (UID 911)Latest Security Improvements (September 2025):
# Comprehensive security scan (Trivy + CodeQL)
make security-scan
# Individual scanning tools
make trivy-scan # Vulnerability scanning only
make codeql-scan # Static code analysis only
make security-scan-detailed # Detailed scan with exports
# Manual scanning
trivy image mildman1848/rclone:latest
trivy fs --format sarif --output trivy-results.sarif .
# Dockerfile validation
make validate
Implemented Security Features:
abc (UID 911)# 1. Use LinuxServer.io FILE__ secrets for rclone
FILE__RCLONE_CONFIG_PASS=/run/secrets/rclone_config_pass
FILE__RCLONE_WEB_GUI_PASSWORD=/run/secrets/rclone_web_pass
FILE__RCLONE_PASSWORD=/run/secrets/rclone_password
# 2. Set host user IDs (LinuxServer.io standard)
export PUID=$(id -u)
export PGID=$(id -g)
# 3. Use restrictive UMASK for production
export UMASK=027 # More secure than default 022
# 4. Secure secret generation
make secrets-generate
# 5. Validate configuration
make env-validate
# 6. Use specific image tags
docker run mildman1848/rclone:v1.71.0 # instead of :latest
# 7. Monitor container health
make status # Container status and health checks
# 8. Production deployment with maximum security
docker-compose -f docker-compose.yml -f docker-compose.production.yml up -d
# 9. Development with automatic security hardening
docker-compose up -d # Uses docker-compose.override.yml automatically
# 10. Use custom seccomp profile for syscall filtering
# Automatically applied in docker-compose.production.yml
OCI-compliant Multi-Architecture Support:
# Automatic platform detection (Docker pulls the right image)
docker pull mildman1848/rclone:latest
# Platform-specific tags (LinuxServer.io style)
docker pull mildman1848/rclone:amd64-latest # Intel/AMD 64-bit
docker pull mildman1848/rclone:arm64-latest # ARM 64-bit (Apple M1, Pi 4)
# Inspect manifest lists
make inspect-manifest
docker manifest inspect mildman1848/rclone:latest
Technical Details:
Manifest Structure:
{
"schemaVersion": 2,
"mediaType": "application/vnd.docker.distribution.manifest.list.v2+json",
"manifests": [
{
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"platform": { "architecture": "amd64", "os": "linux" }
},
{
"mediaType": "application/vnd.docker.distribution.manifest.v2+json",
"platform": { "architecture": "arm64", "os": "linux" }
}
]
}
# Fully compatible with LinuxServer.io standards
# ā
S6 Overlay v3
# ā
FILE__ Prefix Secrets
# ā
DOCKER_MODS Support
# ā
Custom Scripts (/custom-cont-init.d)
# ā
UMASK Support
# ā
PUID/PGID Management
# ā
Custom Branding (LinuxServer.io compliant)
# ā
OCI Manifest Lists (2024 Pipeline Standard)
The container shows a custom ASCII-art branding for "Mildman1848" at startup:
āāāā āāāāāāāāāā āāāāāāā āāāā āāāā āāāāāā āāāā āāā āāā āāāāāā āāā āāā āāāāāā
āāāāā āāāāāāāāāāā āāāāāāāāāāāāā āāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāā āāāāāāāāāāā
āāāāāāāāāāāāāāāāā āāā āāāāāāāāāāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā
āāāāāāāāāāāāāāāāā āāā āāāāāāāāāāāāāāāāāāāāāāāāāāāāāāāā āāāāāāāāāāāāāāāāāāāāāāāāāāā
āāā āāā āāāāāāāāāāāāāāāāāāāāāāāāā āāā āāāāāā āāāāāā āāāāāā āāāāāāāāāāā āāāāāāāāāāā
āāā āāāāāāāāāāāāāāāāāāāāā āāā āāāāāā āāāāāā āāāāā āāā āāāāāā āāā āāāāāā
Branding Features:
ā ļø Note: This container is NOT officially supported by LinuxServer.io
The image includes automatic health checks:
# Check status
docker inspect --format='{{.State.Health.Status}}' rclone
# Show logs
docker logs rclone
Built-in Monitoring:
rclone Web GUI (rcd mode):
Prometheus Metrics (Optional):
rclone can export Prometheus metrics when configured with --rc-enable-metrics. See rclone documentationā for details.
# Enable Prometheus metrics
RCLONE_RC_ENABLE_METRICS=true
# Access metrics at http://localhost:5572/metrics
| File | Purpose | Usage |
|---|---|---|
docker-compose.yml | Base configuration | Standard deployment |
docker-compose.override.yml | Security hardening | Automatically applied |
docker-compose.production.yml | Production config | docker-compose -f docker-compose.yml -f docker-compose.production.yml up -d |
seccomp-profile.json | Syscall filtering | Enhanced security (production) |
.env.example | Environment template | Copy to .env and customize |
# Adjust PUID/PGID to host user
export PUID=$(id -u)
export PGID=$(id -g)
docker-compose up -d
# Or set in .env
echo "PUID=$(id -u)" >> .env
echo "PGID=$(id -g)" >> .env
# Change port in .env
echo "EXTERNAL_PORT=13379" >> .env
# Or directly in docker-compose.yml
ports:
- "13379:5572"
# 1. Check logs
make logs
# 2. Health check status
docker inspect --format='{{.State.Health.Status}}' rclone
# 3. Validate environment
make env-validate
# 4. Debug shell
make shell
# Use LinuxServer.io FILE__ secrets
echo "FILE__JWT_SECRET=/run/secrets/jwt_secret" >> .env
# Generate legacy secrets
make secrets-generate
# Check secret status
make secrets-info
# Manual FILE__ secret creation
mkdir -p secrets
openssl rand -base64 64 > secrets/jwt_secret.txt
echo "FILE__JWT_SECRET=$(pwd)/secrets/jwt_secret.txt" >> .env
# Development container with debug logging
echo "LOG_LEVEL=debug" >> .env
echo "DEBUG_MODE=true" >> .env
echo "VERBOSE_LOGGING=true" >> .env
make dev
# Shell access
make shell
# Container inspection
docker exec -it rclone /bin/bash
Fork & Clone
git clone https://github.com/yourusername/rclone.git
cd rclone
Setup Development Environment
make setup
make dev
Make Changes & Test
make validate # Dockerfile linting
make build # Build image
make test # Run tests
make security-scan # Security check
Submit PR
š”ļø Security Issues: Please read our Security Policyā before reporting security vulnerabilities
The project uses GitHub Actions for:
The project includes automated monitoring of upstream dependencies:
Monitoring Schedule: Monday and Thursday at 6 AM UTC
See UPSTREAM_AUTOMATION_EVALUATION.mdā for detailed implementation strategy.
For GHCR (GitHub Container Registry) support:
write:packages and read:packages scopesGHCR_TOKENAll other workflows work without additional setup.
This project is licensed under the MIT License. See LICENSEā for details.
Content type
Image
Digest
sha256:94f691858ā¦
Size
33.3 MB
Last updated
about 1 year ago
docker pull mildman1848/rclone