feat: add NetBox Cloudron package (Infrastructure) [#648]
Official-image wrapper of netboxcommunity/netbox v4.6.10 (netbox-docker 5.0.2, Granian), digest-pinned. OIDC via python-social-auth wired to the platform provider; RQ worker backgrounded behind a web-port gate; addon waits cover the 30s upstream DB timeout. Full-stack verified: migrations, Granian, worker, login page + SSO button. 16/~57. Detail + verification: https://projects.knownelement.com/issues/648#note-4976
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
# NetBox Cloudron Package
|
||||
#
|
||||
# NetBox is an open-source IPAM / DCIM web application (Django): circuits,
|
||||
# devices, racks, IP address management, prefixes, VLANs, virtualization,
|
||||
# with a REST + GraphQL API. PostgreSQL for storage, Redis for caching and
|
||||
# background tasks (RQ webhooks/scripts/jobs).
|
||||
#
|
||||
# Upstream: https://github.com/netbox-community/netbox (Apache-2.0), v4.6.10
|
||||
# - Built/published by the separate netbox-docker repo; v4.6.10 images
|
||||
# come from netbox-docker 5.0.2 (tag alias v4.6.10-5.0.2, pushed
|
||||
# 2026-09-02). 5.x serves HTTP via Granian on port 8080 (nginx-unit is
|
||||
# gone since 4.0), runs as user netbox (uid 999, gid 0), and the
|
||||
# default container is WEB-ONLY: upstream compose runs the RQ worker
|
||||
# as a separate service. Cloudron is one-container-per-app, so
|
||||
# start.sh backgrounds `manage.py rqworker` (gated on the web port so
|
||||
# it only starts once the entrypoint's migrations have finished).
|
||||
# - The image configuration is env-driven (netbox-docker
|
||||
# configuration/configuration.py): DB_*, REDIS[_CACHE]_*, SECRET_KEY,
|
||||
# ALLOWED_HOSTS, CSRF_TRUSTED_ORIGINS, REMOTE_AUTH_BACKEND +
|
||||
# SOCIAL_AUTH_OIDC_* all map straight onto Cloudron addon/platform env.
|
||||
# - docker-entrypoint.sh waits for the DB, migrates, and creates the
|
||||
# superuser unless SKIP_SUPERUSER=true (our default; the README covers
|
||||
# creating the admin via the Cloudron terminal).
|
||||
#
|
||||
# Authentication: NATIVE OIDC (preferred). NetBox 4.6 uses python-social-
|
||||
# auth directly: REMOTE_AUTH_BACKEND=OpenIdConnectAuth + the
|
||||
# SOCIAL_AUTH_OIDC_{OIDC_ENDPOINT,KEY,SECRET} trio, wired in start.sh from
|
||||
# the Cloudron platform provider (CLOUDRON_OIDC_*). The local Django login
|
||||
# form remains available alongside SSO for admin bootstrap; SSO-registered
|
||||
# users arrive with no privileges (README).
|
||||
#
|
||||
# Pattern: official-image wrapper. Image pinned by tag AND digest (amd64
|
||||
# manifest digest of the v4.6.10 tag, from docker manifest inspect — the
|
||||
# Hub API's index digest is NOT usable as tag@digest, see JOURNAL #668).
|
||||
FROM netboxcommunity/netbox:v4.6.10@sha256:5ee780bdc63b5a5f7ad5073e05e265f74d1a1c52ca0057facc9e4279fcfdb8cc
|
||||
|
||||
# Persistence rebinds must happen at BUILD time: the container runs as the
|
||||
# unprivileged netbox user (999) and could not replace these directories
|
||||
# later. Symlink targets are created by start.sh under /app/data.
|
||||
USER root
|
||||
RUN rm -rf /opt/netbox/netbox/media /opt/netbox/netbox/reports /opt/netbox/netbox/scripts \
|
||||
&& ln -s /app/data/media /opt/netbox/netbox/media \
|
||||
&& ln -s /app/data/reports /opt/netbox/netbox/reports \
|
||||
&& ln -s /app/data/scripts /opt/netbox/netbox/scripts
|
||||
|
||||
# start.sh (runs as the netbox user): persists the SECRET_KEY, maps the
|
||||
# Cloudron addon/platform env onto the image's env-driven configuration,
|
||||
# backgrounds the RQ worker, then execs the upstream entrypoint chain
|
||||
# (docker-entrypoint.sh launch-netbox.sh) under tini.
|
||||
# Made executable on the host, not at build time (Cloudron builds hit
|
||||
# permission errors on RUN chmod).
|
||||
COPY start.sh /app/start.sh
|
||||
|
||||
# Granian binds :: (dual-stack) on 8080; Cloudron proxies TLS here.
|
||||
EXPOSE 8080
|
||||
|
||||
USER 999:0
|
||||
|
||||
# Keep upstream's tini as PID 1; start.sh execs the upstream CMD chain.
|
||||
ENTRYPOINT ["/usr/bin/tini", "--", "/bin/bash", "/app/start.sh"]
|
||||
Reference in New Issue
Block a user