Files
KNEL-TSYSDevStack-SupportSt…/Package-Workspace/Infrastructure/netbox/Dockerfile
T
mrcharles cead1523ad feat: add NetBox Cloudron package (Infrastructure) [#648]
Official-image wrapper of netboxcommunity/netbox v4.6.10
(netbox-docker 5.0.2, Granian), digest-pinned. OIDC via
python-social-auth wired to the platform provider; RQ worker
backgrounded behind a web-port gate; addon waits cover the 30s
upstream DB timeout. Full-stack verified: migrations, Granian,
worker, login page + SSO button. 16/~57.

Detail + verification: https://projects.knownelement.com/issues/648#note-4976
2026-09-06 06:26:54 -05:00

61 lines
3.2 KiB
Docker

# NetBox Cloudron Package
#
# NetBox is an open-source IPAM / DCIM web application (Django): circuits,
# devices, racks, IP address management, prefixes, VLANs, virtualization,
# with a REST + GraphQL API. PostgreSQL for storage, Redis for caching and
# background tasks (RQ webhooks/scripts/jobs).
#
# Upstream: https://github.com/netbox-community/netbox (Apache-2.0), v4.6.10
# - Built/published by the separate netbox-docker repo; v4.6.10 images
# come from netbox-docker 5.0.2 (tag alias v4.6.10-5.0.2, pushed
# 2026-09-02). 5.x serves HTTP via Granian on port 8080 (nginx-unit is
# gone since 4.0), runs as user netbox (uid 999, gid 0), and the
# default container is WEB-ONLY: upstream compose runs the RQ worker
# as a separate service. Cloudron is one-container-per-app, so
# start.sh backgrounds `manage.py rqworker` (gated on the web port so
# it only starts once the entrypoint's migrations have finished).
# - The image configuration is env-driven (netbox-docker
# configuration/configuration.py): DB_*, REDIS[_CACHE]_*, SECRET_KEY,
# ALLOWED_HOSTS, CSRF_TRUSTED_ORIGINS, REMOTE_AUTH_BACKEND +
# SOCIAL_AUTH_OIDC_* all map straight onto Cloudron addon/platform env.
# - docker-entrypoint.sh waits for the DB, migrates, and creates the
# superuser unless SKIP_SUPERUSER=true (our default; the README covers
# creating the admin via the Cloudron terminal).
#
# Authentication: NATIVE OIDC (preferred). NetBox 4.6 uses python-social-
# auth directly: REMOTE_AUTH_BACKEND=OpenIdConnectAuth + the
# SOCIAL_AUTH_OIDC_{OIDC_ENDPOINT,KEY,SECRET} trio, wired in start.sh from
# the Cloudron platform provider (CLOUDRON_OIDC_*). The local Django login
# form remains available alongside SSO for admin bootstrap; SSO-registered
# users arrive with no privileges (README).
#
# Pattern: official-image wrapper. Image pinned by tag AND digest (amd64
# manifest digest of the v4.6.10 tag, from docker manifest inspect — the
# Hub API's index digest is NOT usable as tag@digest, see JOURNAL #668).
FROM netboxcommunity/netbox:v4.6.10@sha256:5ee780bdc63b5a5f7ad5073e05e265f74d1a1c52ca0057facc9e4279fcfdb8cc
# Persistence rebinds must happen at BUILD time: the container runs as the
# unprivileged netbox user (999) and could not replace these directories
# later. Symlink targets are created by start.sh under /app/data.
USER root
RUN rm -rf /opt/netbox/netbox/media /opt/netbox/netbox/reports /opt/netbox/netbox/scripts \
&& ln -s /app/data/media /opt/netbox/netbox/media \
&& ln -s /app/data/reports /opt/netbox/netbox/reports \
&& ln -s /app/data/scripts /opt/netbox/netbox/scripts
# start.sh (runs as the netbox user): persists the SECRET_KEY, maps the
# Cloudron addon/platform env onto the image's env-driven configuration,
# backgrounds the RQ worker, then execs the upstream entrypoint chain
# (docker-entrypoint.sh launch-netbox.sh) under tini.
# Made executable on the host, not at build time (Cloudron builds hit
# permission errors on RUN chmod).
COPY start.sh /app/start.sh
# Granian binds :: (dual-stack) on 8080; Cloudron proxies TLS here.
EXPOSE 8080
USER 999:0
# Keep upstream's tini as PID 1; start.sh execs the upstream CMD chain.
ENTRYPOINT ["/usr/bin/tini", "--", "/bin/bash", "/app/start.sh"]