mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-28 11:16:37 +08:00
chore: reduce docker runtime vulnerability surface
This commit is contained in:
+17
-11
@@ -4,11 +4,14 @@
|
|||||||
#
|
#
|
||||||
# Stage 1 (frontend) : Node 20 -> static SPA bundle
|
# Stage 1 (frontend) : Node 20 -> static SPA bundle
|
||||||
# Stage 2 (backend) : Go 1.25 -> single static binary (CGO_ENABLED=0)
|
# Stage 2 (backend) : Go 1.25 -> single static binary (CGO_ENABLED=0)
|
||||||
# Stage 3 (runtime) : Alpine 3.19 -> ffmpeg + tzdata + non-root user
|
# Stage 3 (runtime) : Alpine 3.23 -> ffmpeg + tzdata + non-root user
|
||||||
#
|
#
|
||||||
# Build:
|
# Build:
|
||||||
# docker buildx build --platform linux/amd64,linux/arm64 \
|
# docker buildx build --platform linux/amd64,linux/arm64 \
|
||||||
# -t mediastation-go:latest --push .
|
# -t mediastation-go:latest --push .
|
||||||
|
#
|
||||||
|
# Optional Intel VAAPI/QSV runtime packages:
|
||||||
|
# docker buildx build --build-arg WITH_VAAPI=true ...
|
||||||
# =============================================================================
|
# =============================================================================
|
||||||
|
|
||||||
# ---- Stage 1: frontend (always build on the host architecture) -------------
|
# ---- Stage 1: frontend (always build on the host architecture) -------------
|
||||||
@@ -32,20 +35,23 @@ RUN CGO_ENABLED=0 GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
|
|||||||
go build -trimpath -ldflags="-s -w" -o mediastation-go ./cmd/server
|
go build -trimpath -ldflags="-s -w" -o mediastation-go ./cmd/server
|
||||||
|
|
||||||
# ---- Stage 3: runtime ------------------------------------------------------
|
# ---- Stage 3: runtime ------------------------------------------------------
|
||||||
FROM alpine:3.19
|
FROM alpine:3.23
|
||||||
# ffmpeg plus optional VAAPI packages. Intel media driver is x86_64-only.
|
ARG WITH_VAAPI=false
|
||||||
# NVENC requires the proprietary NVIDIA Container Toolkit on the host —
|
# Default runtime keeps only the packages needed by normal deployments.
|
||||||
# no extra packages needed inside the image, only --gpus all on docker run.
|
# VAAPI/mesa drivers pull a large graphics dependency tree, so they are opt-in
|
||||||
|
# for users who explicitly build an Intel hardware-acceleration image.
|
||||||
|
# NVENC requires the proprietary NVIDIA Container Toolkit on the host only.
|
||||||
RUN apk add --no-cache \
|
RUN apk add --no-cache \
|
||||||
ffmpeg \
|
ffmpeg \
|
||||||
tzdata \
|
tzdata \
|
||||||
ca-certificates \
|
ca-certificates \
|
||||||
wget \
|
|
||||||
su-exec \
|
su-exec \
|
||||||
&& if [ "$(apk --print-arch)" = "x86_64" ]; then \
|
&& if [ "$WITH_VAAPI" = "true" ]; then \
|
||||||
apk add --no-cache intel-media-driver libva-utils mesa-va-gallium; \
|
if [ "$(apk --print-arch)" = "x86_64" ]; then \
|
||||||
else \
|
apk add --no-cache intel-media-driver libva-utils mesa-va-gallium; \
|
||||||
apk add --no-cache libva-utils mesa-va-gallium || true; \
|
else \
|
||||||
|
apk add --no-cache libva-utils mesa-va-gallium || true; \
|
||||||
|
fi; \
|
||||||
fi \
|
fi \
|
||||||
&& rm -rf /var/cache/apk/*
|
&& rm -rf /var/cache/apk/*
|
||||||
|
|
||||||
@@ -71,7 +77,7 @@ ENV MEDIASTATION_APP_PORT=8080 \
|
|||||||
EXPOSE 8080
|
EXPOSE 8080
|
||||||
|
|
||||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=15s --retries=3 \
|
||||||
CMD wget -q --spider http://127.0.0.1:8080/api/health || exit 1
|
CMD busybox wget -q --spider http://127.0.0.1:8080/api/health || exit 1
|
||||||
|
|
||||||
# Tiny entrypoint that lets us swap to a different UID/GID via PUID/PGID
|
# Tiny entrypoint that lets us swap to a different UID/GID via PUID/PGID
|
||||||
# (handy on NAS deployments where bind-mounted volumes belong to a non-root
|
# (handy on NAS deployments where bind-mounted volumes belong to a non-root
|
||||||
|
|||||||
@@ -657,6 +657,8 @@ MediaStationGo 不会把 `ffmpeg` 或 `ffprobe` 作为常驻守护进程启动
|
|||||||
|
|
||||||
默认 HLS 转码使用 NAS 友好的低负载策略:`MEDIASTATION_TRANSCODER_ENABLED=true` 是总开关,关闭后不会启动 ffmpeg 转码;`MEDIASTATION_TRANSCODER_HARDWARE_ACCEL=false` 是硬件加速总开关,只有开启后才会使用 `MEDIASTATION_TRANSCODER_ENCODER=nvenc/qsv/vaapi`;`MEDIASTATION_TRANSCODER_REALTIME=true` 按播放速度处理输入,`MEDIASTATION_TRANSCODER_THREADS=2` 限制软件编码线程,`MEDIASTATION_TRANSCODER_MAX_CONCURRENT=1` 限制同时转码数量,`MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS=120` 在播放器停止请求分片后自动结束 ffmpeg。
|
默认 HLS 转码使用 NAS 友好的低负载策略:`MEDIASTATION_TRANSCODER_ENABLED=true` 是总开关,关闭后不会启动 ffmpeg 转码;`MEDIASTATION_TRANSCODER_HARDWARE_ACCEL=false` 是硬件加速总开关,只有开启后才会使用 `MEDIASTATION_TRANSCODER_ENCODER=nvenc/qsv/vaapi`;`MEDIASTATION_TRANSCODER_REALTIME=true` 按播放速度处理输入,`MEDIASTATION_TRANSCODER_THREADS=2` 限制软件编码线程,`MEDIASTATION_TRANSCODER_MAX_CONCURRENT=1` 限制同时转码数量,`MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS=120` 在播放器停止请求分片后自动结束 ffmpeg。
|
||||||
|
|
||||||
|
默认 Docker 镜像使用精简运行层,不再内置 Intel VAAPI / mesa 驱动依赖,以降低 Docker Hub 漏洞扫描暴露面。需要自构建 Intel VAAPI/QSV 镜像时,可使用 `docker buildx build --build-arg WITH_VAAPI=true ...`;NVIDIA NVENC 仍主要依赖宿主机安装 NVIDIA Container Toolkit 并在运行容器时启用 GPU。
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## 🔍 刮削与元数据策略
|
## 🔍 刮削与元数据策略
|
||||||
|
|||||||
@@ -638,6 +638,8 @@ When playback stops, a transcode job is cancelled, or the service shuts down, th
|
|||||||
|
|
||||||
The default HLS profile is NAS-friendly: `MEDIASTATION_TRANSCODER_ENABLED=true` is the global switch, and disabling it prevents ffmpeg transcode jobs from starting; `MEDIASTATION_TRANSCODER_HARDWARE_ACCEL=false` is the hardware acceleration switch, and hardware encoders are used only when it is enabled together with `MEDIASTATION_TRANSCODER_ENCODER=nvenc/qsv/vaapi`; `MEDIASTATION_TRANSCODER_REALTIME=true` throttles input to playback speed, `MEDIASTATION_TRANSCODER_THREADS=2` caps software encoding threads, `MEDIASTATION_TRANSCODER_MAX_CONCURRENT=1` limits simultaneous transcodes, and `MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS=120` stops ffmpeg after the player stops requesting segments.
|
The default HLS profile is NAS-friendly: `MEDIASTATION_TRANSCODER_ENABLED=true` is the global switch, and disabling it prevents ffmpeg transcode jobs from starting; `MEDIASTATION_TRANSCODER_HARDWARE_ACCEL=false` is the hardware acceleration switch, and hardware encoders are used only when it is enabled together with `MEDIASTATION_TRANSCODER_ENCODER=nvenc/qsv/vaapi`; `MEDIASTATION_TRANSCODER_REALTIME=true` throttles input to playback speed, `MEDIASTATION_TRANSCODER_THREADS=2` caps software encoding threads, `MEDIASTATION_TRANSCODER_MAX_CONCURRENT=1` limits simultaneous transcodes, and `MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS=120` stops ffmpeg after the player stops requesting segments.
|
||||||
|
|
||||||
|
The default Docker image now uses a trimmed runtime layer and does not bundle Intel VAAPI / mesa driver packages by default, reducing the Docker Hub vulnerability-scan surface. If you need a custom Intel VAAPI/QSV image, build with `docker buildx build --build-arg WITH_VAAPI=true ...`; NVIDIA NVENC still mainly depends on NVIDIA Container Toolkit on the host and GPU access when the container runs.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## 🔍 Metadata Strategy
|
## 🔍 Metadata Strategy
|
||||||
|
|||||||
@@ -180,7 +180,7 @@ services:
|
|||||||
# gpus: all
|
# gpus: all
|
||||||
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8080/api/health || exit 1"]
|
test: ["CMD-SHELL", "busybox wget -qO- http://127.0.0.1:8080/api/health || exit 1"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|||||||
+1
-1
@@ -70,7 +70,7 @@ services:
|
|||||||
MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS: ${MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS:-120}
|
MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS: ${MEDIASTATION_TRANSCODER_IDLE_TIMEOUT_SECONDS:-120}
|
||||||
|
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "wget -qO- http://127.0.0.1:8080/api/health || exit 1"]
|
test: ["CMD-SHELL", "busybox wget -qO- http://127.0.0.1:8080/api/health || exit 1"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
timeout: 10s
|
timeout: 10s
|
||||||
retries: 5
|
retries: 5
|
||||||
|
|||||||
Reference in New Issue
Block a user