30 lines
1.0 KiB
Docker
30 lines
1.0 KiB
Docker
# Example Dockerfile for running the service in a Linux container.
|
|
# Password setting works via Kerberos (kinit + ldapmodify -Y GSSAPI):
|
|
# - openldap-clients provides ldapmodify
|
|
# - cyrus-sasl-gssapiv2 provides the SASL GSSAPI plugin used by ldapmodify
|
|
# - krb5 provides kinit / kdestroy (there is no krb5-client
|
|
# package in Alpine v3.24 — the tools are in krb5)
|
|
#
|
|
# /etc/krb5.conf is regenerated from .env at every start by
|
|
# scripts/generate-krb5-conf.js (the static file below is only a fallback).
|
|
# Make sure the container environment does NOT contain
|
|
# LDAP_USE_POWERSHELL_PASSWORD=true (remove it from the .env you mount).
|
|
|
|
FROM node:22-alpine
|
|
|
|
WORKDIR /app
|
|
|
|
RUN apk add --no-cache git build-base python3 \
|
|
openldap-clients cyrus-sasl-gssapiv2 krb5
|
|
|
|
COPY config/krb5.conf /etc/krb5.conf
|
|
|
|
COPY package*.json ./
|
|
RUN npm ci --omit=dev
|
|
|
|
COPY . .
|
|
|
|
EXPOSE 8080
|
|
|
|
# Regenerate /etc/krb5.conf from .env at every start, then launch the server
|
|
CMD ["sh", "-c", "node scripts/generate-krb5-conf.js && node server.js"] |