Compare commits
5 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
4346acb651
|
|||
|
6bb4e56607
|
|||
|
1f51ea539c
|
|||
|
3bc6afc318
|
|||
|
040dddf723
|
@@ -0,0 +1,31 @@
|
||||
# Changelog
|
||||
|
||||
All notable changes to this project will be documented in this file.
|
||||
|
||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/) but do not follows semantic versioning as it is useless in this type of project.
|
||||
|
||||
## [2.7.4-2] - 2026-07-26
|
||||
|
||||
### Added
|
||||
|
||||
* switch to s6-overlay (which is more suitable for containers than plain s6).
|
||||
* syslogd support via s6-overlay.
|
||||
|
||||
## [2.7.4-1] - 2026-07-26
|
||||
|
||||
### Added
|
||||
|
||||
* libcanlock support.
|
||||
* ssmtp for sending mails.
|
||||
|
||||
### Changed
|
||||
|
||||
* Little image optimisation - compile everything and cleanup sources in one command. Saves ~10 megabytes 😅.
|
||||
|
||||
## [2.7.4] - 2026-07-24
|
||||
|
||||
Initial container release with inn 2.7.4 built with perl/python/sqlite support.
|
||||
|
||||
[2.7.4-2]: https://code.pztrn.name/containers/inn2/compare/2.7.4-1...2.7.4-2
|
||||
[2.7.4-1]: https://code.pztrn.name/containers/inn2/compare/2.7.4...2.7.4-1
|
||||
[2.7.4]: https://code.pztrn.name/containers/inn2/releases/tag/2.7.4
|
||||
+19
-17
@@ -4,7 +4,9 @@ ENV PERL_MM_USE_DEFAULT=1
|
||||
RUN apk add --no-cache \
|
||||
bison \
|
||||
build-base \
|
||||
bzip2 \
|
||||
curl \
|
||||
flex \
|
||||
gawk \
|
||||
gd-dev \
|
||||
gnupg \
|
||||
@@ -17,42 +19,42 @@ RUN apk add --no-cache \
|
||||
perl-utils \
|
||||
python3 \
|
||||
python3-dev \
|
||||
s6 \
|
||||
s6-overlay \
|
||||
s6-overlay-syslogd \
|
||||
shadow \
|
||||
sqlite-dev \
|
||||
ssmtp \
|
||||
tar \
|
||||
zlib-dev && \
|
||||
cpan -T GD MIME::Parser && \
|
||||
rm -rf /root/.cpan
|
||||
|
||||
|
||||
ARG VERSION=2.7.4
|
||||
RUN curl -sL https://github.com/InterNetNews/inn/releases/download/${VERSION}/inn-${VERSION}.tar.gz | tar xz
|
||||
|
||||
WORKDIR /inn-${VERSION}
|
||||
RUN ./configure --prefix=/inn2 --with-zlib --with-openssl --with-sqlite --with-krb5 --with-perl --with-python && \
|
||||
# Build everything in one command and cleanup sources so container will eat less space.
|
||||
RUN mkdir /src && cd /src && \
|
||||
# libcanlock
|
||||
curl -sL https://micha.freeshell.org/libcanlock/src/libcanlock-3.3.3.tar.bz2 | tar xj && cd libcanlock-3.3.3 && ./configure && make && make install && \
|
||||
# inn2
|
||||
cd /src && curl -sL https://github.com/InterNetNews/inn/releases/download/2.7.4/inn-2.7.4.tar.gz | tar xz && cd inn-2.7.4 && \
|
||||
./configure --prefix=/inn2 --with-zlib --with-openssl --with-sqlite --with-krb5 --with-perl --with-python --with-canlock && \
|
||||
make && \
|
||||
sed -i 's/#domain:/domain: news.localhost/' site/inn.conf && \
|
||||
make install
|
||||
|
||||
RUN sed -i 's/#\(tlscapath:\)/\1/' /inn2/etc/inn.conf && \
|
||||
make install && \
|
||||
sed -i 's/#\(tlscapath:\)/\1/' /inn2/etc/inn.conf && \
|
||||
sed -i 's/#\(tlscertfile:\)/\1/' /inn2/etc/inn.conf && \
|
||||
sed -i 's/#\(tlskeyfile:\)/\1/' /inn2/etc/inn.conf && \
|
||||
mv /inn2/etc /inn2/etc-default && \
|
||||
mv /inn2/db /inn2/db-default && \
|
||||
mv /inn2/spool /inn2/spool-default
|
||||
mv /inn2/spool /inn2/spool-default && \
|
||||
rm -rf /src
|
||||
|
||||
COPY configuration /etc
|
||||
COPY start-innd.sh /start-innd
|
||||
COPY etc /etc
|
||||
|
||||
RUN groupmod -g 600 news && usermod -u 600 -g 600 -d /inn2 news && chown -R news:news /inn2 && chown -R news:news /etc/s6
|
||||
RUN groupmod -g 600 news && usermod -u 600 -g 600 -d /inn2 news && chown -R news:news /inn2 && chown -R news:news /etc/cont-init.d /etc/services.d
|
||||
|
||||
WORKDIR /inn2
|
||||
ENV PATH=/inn2/bin:$PATH
|
||||
ENV PERL_MM_USE_DEFAULT=1
|
||||
USER news
|
||||
EXPOSE 119
|
||||
EXPOSE 563
|
||||
VOLUME [ "/inn2/db", "/inn2/spool", "/inn2/log" ]
|
||||
|
||||
CMD ["/usr/bin/s6-svscan", "/etc/s6"]
|
||||
ENTRYPOINT [ "/init" ]
|
||||
|
||||
@@ -8,7 +8,7 @@ This container is based on [greenbender's image](https://github.com/greenbender/
|
||||
|
||||
Configuration files are described on [inn official site](https://www.eyrie.org/~eagle/software/inn/) (select proper version from right sidebar).
|
||||
|
||||
Using this container with compose:
|
||||
Using this container with compose is simple:
|
||||
|
||||
```yaml
|
||||
---
|
||||
@@ -26,29 +26,86 @@ services:
|
||||
- "./data/run:/inn2/run"
|
||||
- "./data/spool:/inn2/spool"
|
||||
- "./data/tmp:/inn2/tmp"
|
||||
- "./data/syslog:/var/log"
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 65535
|
||||
hard: 65535
|
||||
```
|
||||
|
||||
It is recommended to use macvlan/ipvlan network for container so real user IP will flow within inn2 as by default it will be docker's network gateway for compose project. For that compose file will looks like:
|
||||
|
||||
```yaml
|
||||
---
|
||||
services:
|
||||
inn:
|
||||
image: "code.pztrn.name/containers/inn2:2.7.4"
|
||||
restart: always
|
||||
volumes:
|
||||
- "./data/db:/inn2/db"
|
||||
- "./data/etc:/inn2/etc"
|
||||
- "./data/log:/inn2/log"
|
||||
- "./data/run:/inn2/run"
|
||||
- "./data/spool:/inn2/spool"
|
||||
- "./data/tmp:/inn2/tmp"
|
||||
- "./data/syslog:/var/log"
|
||||
networks:
|
||||
inn2-ipvlan:
|
||||
ipv4_address: 192.168.168.168 # ip address from real LAN.
|
||||
ipv6_address: fd00:0:1:2::168 # ip address from real LAN.
|
||||
ulimits:
|
||||
nofile:
|
||||
soft: 65535
|
||||
hard: 65535
|
||||
|
||||
networks:
|
||||
inn2-ipvlan:
|
||||
driver: ipvlan
|
||||
driver_opts:
|
||||
parent: ens18 # put your real interface name here.
|
||||
ipvlan_mode: l2
|
||||
ipam:
|
||||
config:
|
||||
- subnet: 192.168.168.160/27 # put real LAN subnet here.
|
||||
gateway: 192.168.168.161 # put real LAN gateway here.
|
||||
ip_range: 192.168.168.168/32 # ip address from real LAN.
|
||||
- subnet: fd00:0:1:2::/64 # put real LAN subnet here.
|
||||
gateway: fd00:0:1:2::1 # put real LAN gateway here.
|
||||
ip_range: fd00:0:1:2::168/128 # ip address from real LAN.
|
||||
enable_ipv6: true
|
||||
```
|
||||
|
||||
Note that this code is built to support dual-stack (IPv4+IPv6). You should either:
|
||||
|
||||
1. Remove IPv6 things if not using it.
|
||||
2. Set up SNAT6 for outgoing connections to work (on host or router).
|
||||
3. Add globally routable address to IPAM config and network definition in container.
|
||||
|
||||
## Cronjobs
|
||||
|
||||
There is a section in documentation about cron jobs you should configure. This docker image currently isn't supporting these, so configure it separately with lines like:
|
||||
This Docker image come with a recommended in documentation set of cronjobs. To customize it copy `etc/crontabs/news` file, make neccessary changes and mount it to container in `/etc/crontabs/news`.
|
||||
|
||||
If you want to use cron outside of your container:
|
||||
|
||||
```shell
|
||||
0 3 * * * docker compose run inn news.daily expireover lowmark
|
||||
0 3 * * * docker compose run inn news.daily expireover lowmark delayrm
|
||||
```
|
||||
|
||||
## Sending emails
|
||||
|
||||
As this container has no postfix installed (why do you might ever need it here?) you can use [ssmtp](https://wiki.debian.org/sSMTP) which installed in container to get mails sent over SMTP.
|
||||
|
||||
## Versioning
|
||||
|
||||
Image versioning follows official inn2 versions with additional optional version postfix added to indicate image fixes for particular version.
|
||||
|
||||
Examples:
|
||||
|
||||
* 2.7.4-3 - inn version 2.7.4 and 3 additional fixes applied to container.
|
||||
* 2.7.4-3 - inn version 2.7.4 and 3 additional fixes applied to container or inn's dependencies.
|
||||
* 2.7.6 - inn version 2.7.6 without additional container fixes.
|
||||
|
||||
All notable changes to container and it's building process are noted in [CHANGELOG.md](CHANGELOG.md).
|
||||
|
||||
## Data directories and permissions
|
||||
|
||||
Configuration is kept in `/inn2/etc`, mount it in your local filesystem. Entrypoint script will copy default configuration for you if missing.
|
||||
@@ -62,3 +119,14 @@ inn2 is launched as UID/GID 600 in container, so chown directories properly acco
|
||||
|
||||
* If you're not using userns isolation - use `chown 600:600`.
|
||||
* If you're using it - use `600 + id from /etc/subuid`, e.g. if you're using default Docker remapping this could be `chown 100600:100600`.
|
||||
|
||||
## Logs
|
||||
|
||||
Logs are split in two destinations:
|
||||
|
||||
* `/inn2/log` - default INN logs destination.
|
||||
* `/var/log` - syslog logs.
|
||||
|
||||
As INN might log in both of them you should mount a directory for each.
|
||||
|
||||
For syslog logs it is a known bug that logs isn't written in `/var/log/innd` or `/var/log/nnrpd`, take a look at `/var/log/syslogd/everything/current` for logs with `news` topic. This might be fixed somewhere soon.
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
for file in /etc/s6/*/finish; do
|
||||
$file
|
||||
done
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
kill "$(cat /inn2/run/innd.pid)"
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/execlineb -P
|
||||
|
||||
/start-innd
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/sh
|
||||
|
||||
kill "$(cat /inn2/run/nnrpd-563.pid)"
|
||||
@@ -1,3 +0,0 @@
|
||||
#!/bin/execlineb -P
|
||||
|
||||
nnrpd -D -f -p 563 -S
|
||||
Executable
+9
@@ -0,0 +1,9 @@
|
||||
#!/bin/sh -e
|
||||
|
||||
mkdir -p /var/log/innd
|
||||
chown -R 65534:65534 /var/log/innd
|
||||
chmod 02755 /var/log/innd
|
||||
|
||||
mkdir -p /var/log/nnrpd
|
||||
chown -R 65534:65534 /var/log/nnrpd
|
||||
chmod 02755 /var/log/nnrpd
|
||||
Executable
+5
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
if [ ! -f "/inn2/etc/inn.conf" ]; then
|
||||
cp -r /inn2/etc-default/* /inn2/etc
|
||||
fi
|
||||
Executable
+5
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
if [ ! -f "/inn2/db/history" ]; then
|
||||
cp -r /inn2/db-default/* /inn2/db
|
||||
fi
|
||||
Executable
+5
@@ -0,0 +1,5 @@
|
||||
#!/bin/sh
|
||||
|
||||
if [ ! -d "/inn2/spool/articles" ]; then
|
||||
cp -r /inn2/spool-default/* /inn2/spool
|
||||
fi
|
||||
Executable
+3
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
|
||||
chown news:news /etc/crontabs/news
|
||||
@@ -0,0 +1,5 @@
|
||||
# min hour day month weekday command
|
||||
0 5 * * * cd /inn2; /inn2/bin/news.daily expireover lowmark delayrm
|
||||
15 * * * * cd /inn2; /inn2/bin/rnews -U
|
||||
0 4 * * * cd /inn2; /inn2/bin/ctlinnd -t 120 -s reload incoming.conf 'flush cache'
|
||||
*/10 * * * * cd /inn2; /inn2/bin/nntpsend
|
||||
Executable
+3
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
|
||||
/usr/sbin/crond -f
|
||||
Executable
+3
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
|
||||
exec logutil-service /var/log/innd
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/bin/sh
|
||||
|
||||
exec 2>&1
|
||||
exec s6-setuidgid news /inn2/bin/innd -f
|
||||
Executable
+3
@@ -0,0 +1,3 @@
|
||||
#!/bin/sh
|
||||
|
||||
exec logutil-service /var/log/nnrpd
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/bin/sh
|
||||
|
||||
exec 2>&1
|
||||
exec s6-setuidgid news nnrpd -D -f -p 563 -S
|
||||
+1
-1
@@ -12,6 +12,6 @@ if [ ! -d "/inn2/spool/articles" ]; then
|
||||
cp -r /inn2/spool-default/* /inn2/spool
|
||||
fi
|
||||
|
||||
cd /inn2
|
||||
cd /inn2 || exit 1
|
||||
|
||||
/inn2/bin/innd -f
|
||||
|
||||
Reference in New Issue
Block a user