openvidu/openvidu-server/docker/openvidu-coturn/Dockerfile

31 lines
1.5 KiB
Docker
Raw Normal View History

# SECURITY UPDATE: Updated from Alpine-based coturn:4.7.0-r2-alpine to Debian-based coturn:latest
# Provides better security patch management and resolves vulnerabilities in libgnutls, libssl, libpq
FROM coturn/coturn:latest
2020-03-24 12:08:36 +01:00
USER root
2020-03-24 12:08:36 +01:00
# SECURITY UPDATE: Update existing packages with security patches
# Fixes vulnerabilities in system packages while maintaining compatibility
# Fallback mechanism ensures build continues even if repositories are temporarily unavailable
RUN apt update && apt -y upgrade --with-new-pkgs && apt clean && rm -rf /var/lib/apt/lists/* || \
# Fallback if repositories are unreachable - skip updates but continue build
echo "Repository access failed, continuing with existing packages"
2020-03-24 12:08:36 +01:00
# Override detect-external-ip.sh script
COPY ./detect-external-ip.sh /usr/local/bin/detect-external-ip.sh
COPY ./docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
COPY ./discover-internal-ip.sh /usr/local/bin/discover-internal-ip.sh
2020-03-24 12:08:36 +01:00
RUN chmod +x /usr/local/bin/detect-external-ip.sh \
/usr/local/bin/docker-entrypoint.sh \
/usr/local/bin/discover-internal-ip.sh && \
sed -i 's/\r$//' /usr/local/bin/detect-external-ip.sh \
/usr/local/bin/docker-entrypoint.sh \
/usr/local/bin/discover-internal-ip.sh && \
chown -R nobody:nogroup /var/lib/coturn/ && \
touch /turnserver.conf && chown nobody:nogroup /turnserver.conf
USER nobody:nogroup
ENTRYPOINT ["docker-entrypoint.sh"]
CMD ["--log-file=stdout", "--external-ip=$(detect-external-ip)"]