diff --git a/code-server-lsio/.env.example b/code-server-lsio/.env.example index fd360c9..e8df0b3 100644 --- a/code-server-lsio/.env.example +++ b/code-server-lsio/.env.example @@ -2,8 +2,7 @@ # # cp .env.example .env -# Web UI login password. MUST NOT be blank -- the LinuxServer image serves -# code-server without authentication when PASSWORD is empty. +# Web UI login password. Required. # Also used for SUDO_PASSWORD inside the container. # Generate one with: openssl rand -base64 24 PASSWORD= diff --git a/code-server-lsio/README.md b/code-server-lsio/README.md index 6ad4d34..564bad9 100644 --- a/code-server-lsio/README.md +++ b/code-server-lsio/README.md @@ -16,9 +16,9 @@ to. Containers started from inside are siblings on the host, not children -- bind mounts in them resolve against host paths, so a path under `/config` will not exist unless the same path exists on the host. -The socket is owned by the host's `docker` group, which the `abc` user inside -the container is not a member of; run `docker` under `sudo` (the `SUDO_PASSWORD` -is the same `PASSWORD`) or add the group by hand. Handing a container the +The socket is owned by the host's `docker` group. At startup the mod reads the +socket's GID, creates a group with it if none exists and adds `abc` to it, so +`docker` works without `sudo`. Handing a container the socket is equivalent to giving it root on the host — that is accepted here because this is a single-user dev box. @@ -33,12 +33,16 @@ separate rootless daemon. | Variable | Purpose | | --- | --- | | `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows. | -| `PASSWORD` | Web UI login, also the in-container sudo password. **A blank value disables authentication entirely.** | +| `PASSWORD` | Web UI login, also the in-container sudo password. Required. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | | `PWA_APPNAME` | Optional. Name of the installed web app; defaults to `code-server`. | Generate a password with `openssl rand -base64 24`. +The compose file refuses to start when `PASSWORD` is unset or blank. The image +itself would start anyway and serve code-server with no authentication, on a +container that holds the Docker socket. + `SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the `HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable diff --git a/code-server-lsio/compose.yml b/code-server-lsio/compose.yml index fe0c4e4..d6a9279 100644 --- a/code-server-lsio/compose.yml +++ b/code-server-lsio/compose.yml @@ -6,7 +6,7 @@ services: environment: - PUID=1000 - PGID=1000 - - PASSWORD=${PASSWORD} + - PASSWORD=${PASSWORD:?required} - SUDO_PASSWORD=${PASSWORD} - 'DOCKER_MODS=linuxserver/mods:universal-package-install|linuxserver/mods:universal-docker|linuxserver/mods:code-server-golang|linuxserver/mods:code-server-nodejs|linuxserver/mods:code-server-npmglobal|linuxserver/mods:code-server-python3|linuxserver/mods:code-server-zsh' - INSTALL_PACKAGES=bubblewrap|gh|git|glab|unzip|zip