Sign inSign up

timlegge/docker-foswiki

By timlegge

•Updated 7 months ago

foswiki docker image based on michael34435/docker-foswiki

Image
6

10K+

timlegge/docker-foswiki repository overview

⁠docker-foswiki, with Solr and NatSkin, multi-instances and Traefik ready

⁠Table of Contents

⁠Security

v1.32 fixes CVE-2023-7101

⁠Git Repo

The git repo is available at https://github.com/timlegge/docker-foswiki⁠

⁠Persistent Volumes

The "docker run" commands below do not enable persistent volumes you need to add: '-v foswiki_www:/var/www/foswiki:z' to the command line. This will create a volume named foswiki_www which contains /var/www/foswiki the ':z' is related to selinux and may be required for permission issues.

⁠Production usage

You should use a docker-compose file (examples in the git repo.). The examples can be used or modified based on your requirements.

⁠Support

Log an issue on github https://github.com/timlegge/docker-foswiki/issues⁠ or start a discussion https://github.com/timlegge/docker-foswiki/discussions⁠

⁠Security Notice

Foswiki 2.1.8 (included in v1.31 and above) includes 9 critical security related fixes. You will need to upgrade any existing docker-foswiki installation as noted below.

⁠Upgrade for latest Foswiki Version

The container now includes Foswiki-2.1.8. However if you are using it with persistent volumes as recommended you will not get the latest version simply by grabbing the latest container.

The steps below will walk you through it:

  1. Download the upgrade: https://github.com/foswiki/distro/releases/download/FoswikiRelease02x01x08/Foswiki-upgrade-2.1.8.tgz⁠
  2. Copy it to your docker volume (eg. /var/lib/docker/volumes/foswiki_foswiki_www/_data/)
  3. docker exec -it docker-foswiki /bin/bash
  4. cd /var/www/foswiki
  5. tar --strip-components=1 -zxf /path/to/Foswiki-upgrade-2.1.8.tgz
  6. cd tools
  7. ./configure --save

See https://foswiki.org/Download/FoswikiRelease02x01x08⁠ for more details

⁠Why I created this dockerfile?

I finally got tired of the dependancy issues of Foswiki on RedHat so I modified michael34435/docker-foswiki. The goal of this release is to have a stable version that runs foswiki with all the perl modules required for foswiki to run almost any Plugin. It is served by nginx. Alpinelinux minimizes the size of the container, the total size for this image is 400MB.

Three variations of the docker-compose file are available in order to have a complete Foswiki + Solr faceted search application : a simple one, a pre-configured one for multiple instances and a Traefik⁠ ready one.

⁠First run

To start the image :

docker run -idt -p 80:80 timlegge/docker-foswiki

Once started, open http://localhost in your browser. The user running the command is in the docker group otherwise sudo is required.

⁠Resetting the Admin Password
  1. cd [where the project has been cloned]
  2. docker exec -it docker-foswiki /bin/bash
  3. cd /var/www/foswiki/
  4. tools/configure -save -set {Password}='MyPassword'

⁠Foswiki and Solr run

The first compose file provides a Foswiki + Solr multi-container application. Start it with :

cp docker-compose.1-simple.yml docker-compose.yml
docker-compose up -d

Once started, open http://localhost:8765 in your browser.

The Solr container is set up on an private Docker network.

⁠Foswiki and Solr with https

The second compose file provides a Foswiki + Solr multi-container application that enables HTTPS. Start it with :

cp docker-compose.2-simple-https.yml docker-compose.yml
docker-compose up -d

Once started, open https://localhost:8443 in your browser.

⁠Replacing the certificate and key files distributed here

DO NOT use the certificates included here in a production environment (or really any environment). They are here to simply allow the start up of a fully functional https configuration. Simply run the following commands to replace the certificates with your own self-signed certificaes:

Note that this produces an unencrypted key file. This is needed to start the nginx web server without providing the password to decrypt the file. Take appropriate measure to secure the file as needed for the security of your installation.

openssl req -x509 -newkey rsa:4096 -nodes -keyout https/docker-foswiki.key -out https/docker-foswiki.crt -days 365

Generating a RSA private key
........................................................................................................................................................................++++
.................................................++++
writing new private key to 'https/docker-foswiki.key'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]: US
State or Province Name (full name) [Some-State]: NY
Locality Name (eg, city) []: New York
Organization Name (eg, company) [Internet Widgits Pty Ltd]: Docker Foswiki
Organizational Unit Name (eg, section) []: Security
Common Name (e.g. server FQDN or YOUR name) []:docker-foswiki.local
Email Address []:
⁠Using the docker-foswiki.local server name

You can define docker-foswiki.local in your host file to match the certificate name and nginx configuration. Change the server name in https/nginx.default.conf to the server name you wish to use.

The Solr container is set up on an private Docker network.

⁠Solr Configuration

⁠Solr WebSearch, WebChanges and WikiUsers

See: https://foswiki.org/Extensions/SolrPlugin#Using_Solr_for_WebSearch_44_WebChanges_and_Main.WikiUsers⁠

⁠Automatic Indexing

The Docker container includes iwatch which automatically indexes files that have changed. Everything is set up but you can review https://foswiki.org/Extensions/SolrPlugin#Realtime_indexing⁠

⁠Running multiple instances

If multiple instances of Foswiki are needed, each one has to have its own folder, at same level as this repo :

  • somepath/docker-foswiki/ : this repo
  • somepath/instance1/ : folder for first Foswiki instance
  • somepath/instance2/ : folder for second Foswiki instance
  • and so on

Use the second compose file :

cd somepath/docker-foswiki/
cp docker-compose.3-multipleInstances.yml docker-compose.yml

Under each instance folder, simply copy the .env file :

cd somepath/instance1
cp ../docker-foswiki/.env .

And edit it :

  • do not change COMPOSE_FILE
  • change COMPOSE_PROJECT_NAME to this instance name, Docker will use it to prefix the containers name of this instance
  • change EXTERNAL_PORT so that each instance uses a different port number, for instance 8761, 8762 and so on
  • change TZ to your time zone
  • ACME is only used with Traefik, see below

Start each instance under its own folder with :

cd somepath/instance1
docker-compose up -d

⁠Running multiple instances with Traefik

If you use Traefik as a reverse proxy for multiple instances, use the third compose file :

cd somepath/docker-foswiki/
cp docker-compose.4-Traefik.yml docker-compose.yml

This compose file has all the labels required to work with your running Traefik container.

In the .env file, change the ACME variable to the certResolver name you have declared within Traefik.

After each instance starts, check the Traefik dashboard to verify it has been registered correctly.

⁠Volumes

See the volume declaration in the docker-compose.yml file :

  • 4 volumes are created, for Foswiki data and Solr
  • the :z after the volume declaration is necessary with selinux on RedHat to set the permissions correctly
  • the volumes are located by default under /var/lib/docker/volumes/

The third compose file is configured so that the actual volumes data is located under its instance folder. To activate this run the following before starting your instance :

cd somepath/instance1
mkdir volumes
mkdir volumes/foswiki_www
mkdir volumes/solr_configsets
mkdir volumes/solr_foswiki
mkdir volumes/solr_logs

⁠Image content

⁠Included Foswiki Contribs
  • CopyContrib
  • DBCacheContrib
  • FarscrollContrib
  • InfiniteScrollContrib
  • JQAutoColorContrib
  • JQMomentContrib
  • JQPhotoSwipeContrib
  • JQSelect2Contrib
  • JQSerialPagerContrib
  • JQTwistyContrib
  • JSTreeContrib
  • LdapContrib
  • OpenIDLoginContrib
  • SamlLoginContrib
  • StringifierContrib
  • WebFontsContrib
  • XSendFileContrib
⁠Included Foswiki Plugins
  • AttachContentPlugin
  • AutoRedirectPlugin
  • AutoTemplatePlugin
  • BreadCrumbsPlugin
  • CaptchaPlugin
  • ClassificationPlugin
  • DBCachePlugin
  • DiffPlugin
  • DigestPlugin
  • DocumentViewerPlugin
  • EditChapterPlugin
  • FilterPlugin
  • FlexFormPlugin
  • FlexWebListPlugin
  • GraphvizPlugin
  • GridLayoutPlugin
  • ImageGalleryPlugin
  • ImagePlugin
  • JQDataTablesPlugin
  • LdapNgPlugin
  • LikePlugin
  • ListyPlugin
  • MediaElementPlugin
  • MetaCommentPlugin
  • MetaDataPlugin
  • MimeIconPlugin
  • MoreFormfieldsPlugin
  • MultiLingualPlugin
  • NatSkinPlugin
  • NewUserPlugin
  • PageOptimizerPlugin
  • PubLinkFixupPlugin
  • RedDotPlugin
  • RenderPlugin
  • SecurityHeadersPlugin
  • SolrPlugin
  • TagCloudPlugin
  • TopicInteractionPlugin
  • TopicTitlePlugin
  • WebLinkPlugin
  • WorkflowPlugin
⁠Included Foswiki Skins
  • NatSkin
⁠Included Alpine Packages

The following base modules are installed to support Foswiki or the required Perl modules below.

RepoApplicationAlpine Package
mainBashbash
mainCommon-CA-certificatesca-certificates
mainGraphVisgraphviz
mainGrepgrep
mainmailcapmailcap
mainGNU-makemake
mainLynx Texte Browserlynx
mainmusl-LibCmusl
mainnginx-Web-Servernginx
mainopenSSLopenssl
mainPerl5perl
mainpoppler-utilspoppler-utils
mainTimezone-Datatzdata
mainunzipunzip
mainwgetwget
mainzipzip
communityImageMagickimagemagick
communityPerlMagickimagemagick-perlmagick
testingodt2txtodt2txt

A lot of perl modules required by Foswiki and many of its expensions are included in this Docker file as native alpine packages:

RepoPerl ModuleAlpine Package
mainApache-LogFormat-Compilerperl-apache-logformat-compiler
mainArchive-Zipperl-archive-zip
mainAuthen-SASLperl-authen-sasl
mainCGIperl-cgi
mainCache-Cacheperl-cache-cache
mainCrypt-Eksblowfishperl-crypt-eksblowfish
mainCrypt-OpenSSL-RSAperl-crypt-openssl-rsa
mainCrypt-OpenSSL-Randomperl-crypt-openssl-random
mainCrypt-X509perl-crypt-x509
mainDBD-Pgperl-dbd-pg
mainDBD-SQLiteperl-dbd-sqlite
mainDBD-mysqlperl-dbd-mysql
mainDBIperl-dbi
mainDB_Fileperl-db_file
mainDateTimeperl-datetime
mainDigest-SHA1perl-digest-sha1
mainEncodeperl-encode
mainErrorperl-error
mainFCGIperl-fcgi
mainFCGI-ProcManagerperl-fcgi-procmanager
mainFile-Copy-Recursive-$pkgverperl-file-copy-recursive
mainFile-Removeperl-file-remove
mainFile-Slurpperl-file-slurp
mainFile-Whichperl-file-which
mainGDperl-gd
mainHTML-Treeperl-html-tree
mainIO-Socket-INET6perl-io-socket-inet6
mainJSONperl-json
mainMIME-Base64perl-mime-base64
mainModule-Installperl-module-install
mainModule-Pluggableperl-module-pluggable
mainPath-Tinyperl-path-tiny
mainStream-Bufferedperl-stream-buffered
mainTest-LeakTraceperl-test-leaktrace
mainText-Soundexperl-text-soundex
mainType-Tinyperl-type-tiny
mainXML-Parserperl-xml-parser
mainYAML-Tinyperl-yaml-tiny
mainlibwww-perlperl-libwww
mainFilesys-Notify-Simpleperl-filesys-notify-simple
mainHash-MultiValueperl-hash-multivalue
mainLocale-Maketext-Lexiconperl-locale-maketext-lexicon
mainURIperl-uri
mainperl-ldapperl-ldap
mainCGI-Sessionperl-cgi-session
mainClass-Accessorperl-class-accessor
communityAlgorithm-Diffperl-algorithm-diff
communityAlgorithm-Diff-XSperl-algorithm-diff-xs
communityAuthCASperl-authcas
communityBerkeleyDBperl-db
communityCHIperl-chi
communityCrypt-PasswdMD5perl-crypt-passwdmd5
communityCrypt-SMIMEperl-crypt-smime
communityConvert-PEMperl-convert-pem
communityCrypt-OpenSSL-Bignumperl-crypt-openssl-bignum
communityCrypt-OpenSSL-DSAperl-crypt-openssl-dsa
communityCrypt-OpenSSL-VerifyX509perl-crypt-openssl-verifyx509
communityCrypt-OpenSSL-X509perl-crypt-openssl-x509
communityDancerperl-dancer
communityDB_File-Lockperl-db_file-lock
communityDateTime-Format-XSDperl-datetime-format-xsd
communityDevel-OverloadInfoperl-devel-overloadinfo
communityDigest-Perl-MD5perl-digest-perl-md5
communtiyEmail-Address-XSperl-email-address-xs
communityEmail-MIMEperl-email-mime
communityHash-Merge-Simpleperl-hash-merge-simple
communityImage-Infoperl-image-info
communityJSON-XSperl-json-xs
communityGSSAPIperl-gssapi
communityLocale-Codesperl-locale-codes
communityLocale-Msgfmtperl-locale-msgfmt
communityLWP-Protocol-httpsperl-lwp-protocol-https
communityMooperl-moo
communityMooX-Types-MooseLikeperl-moox-types-mooselike
communityMooseperl-moose
communityMooseXperl-moosex
communityMooseX-Typesperl-moosex-types
communityMooseX-Types-Commonperl-moosex-types-common
communityMooseX-Types-DateTimeperl-moosex-types-datetime
communityMooseX-Types-URIperl-moosex-types-uri
communitySpreadsheet-ParseExcelperl-spreadsheet-parseexcel
communitySpreadsheet-XLSXperl-spreadsheet-xlsx
communitySub-Exporter-ForMethodsperl-sub-exporter-formethods
communityWWW-Mechanizeperl-www-mechanize
communityXML-CanonicalizeXMLperl-xml-canonicalizexml
communityXML-Easyperl-xml-easy
communityXML-Generatorperl-xml-generator
communityXML-Tidyperl-xml-tidy
communityXML-Writerperl-xml-writer
communityXML-XPathperl-xml-xpath
communityYAMLperl-yaml
testingCrypt-JWTperl-crypt-jwt
testingCrypt-Randomperl-crypt-random
testinglibapreq2perl-libapreq2
testingSerealperl-sereal
timleggeNet-SAML2perl-net-saml2

⁠Use the image

⁠How to Build

You can build the docker image yourself from the git clone. Simply do the following in the git directory:

docker build --no-cache -t docker-foswiki .

Building the docker image requires parts of the build process to get access to the internet so if you have a proxy server you will need to follow the directions below to pass the proxy settings to the bulid prodess

docker build --no-cache  --build-arg https_proxy=http://proxy.example.com:8080 --build-arg http_proxy=http://proxy.example.com:8080 --build-arg HTTPS_PROXY=http://proxy.example.com:8080 --build-arg HTTP_PROXY=http://proxy.example.com:8080 -t docker-foswiki .

Unfortunately as the build use's wget, perl LWP and apk from AlpineLinux all four environment variables are necessary as each uses a different case or protocol to download the proper files.

⁠How to run the Build
docker run --name docker-foswiki -d  -p 80:80 docker-foswiki
⁠How to access the running container as root
docker exec -it docker-foswiki /bin/sh
⁠How to stop the container
docker stop docker-foswiki
⁠How to remove the container
docker rm docker-foswiki
⁠How to publish image to Docker Hub
docker login
docker tag docker-foswiki $DOCKER_ID_USER/docker-foswiki
docker push  $DOCKER_ID_USER/docker-foswiki

⁠About Caprover

This docker image is used by CapRover⁠ for their one-click app integration, see README-CAPROVER.md file.

⁠License

MIT

Tag summary

Content type

Image

Digest

sha256:8292e053c…

Size

149.4 MB

Last updated

7 months ago

docker pull timlegge/docker-foswiki