From 03a2016f2334032b990a28a5a36c6d4c00322daf Mon Sep 17 00:00:00 2001 From: tiennm99 Date: Tue, 6 Oct 2026 13:39:26 +0700 Subject: [PATCH] fix(code-server-lsio): require PASSWORD and correct the Docker group note --- code-server-lsio/.env.example | 3 +-- code-server-lsio/README.md | 12 ++++++++---- code-server-lsio/compose.yml | 2 +- 3 files changed, 10 insertions(+), 7 deletions(-) diff --git a/code-server-lsio/.env.example b/code-server-lsio/.env.example index fd360c9..e8df0b3 100644 --- a/code-server-lsio/.env.example +++ b/code-server-lsio/.env.example @@ -2,8 +2,7 @@ # # cp .env.example .env -# Web UI login password. MUST NOT be blank -- the LinuxServer image serves -# code-server without authentication when PASSWORD is empty. +# Web UI login password. Required. # Also used for SUDO_PASSWORD inside the container. # Generate one with: openssl rand -base64 24 PASSWORD= diff --git a/code-server-lsio/README.md b/code-server-lsio/README.md index 6ad4d34..564bad9 100644 --- a/code-server-lsio/README.md +++ b/code-server-lsio/README.md @@ -16,9 +16,9 @@ to. Containers started from inside are siblings on the host, not children -- bind mounts in them resolve against host paths, so a path under `/config` will not exist unless the same path exists on the host. -The socket is owned by the host's `docker` group, which the `abc` user inside -the container is not a member of; run `docker` under `sudo` (the `SUDO_PASSWORD` -is the same `PASSWORD`) or add the group by hand. Handing a container the +The socket is owned by the host's `docker` group. At startup the mod reads the +socket's GID, creates a group with it if none exists and adds `abc` to it, so +`docker` works without `sudo`. Handing a container the socket is equivalent to giving it root on the host — that is accepted here because this is a single-user dev box. @@ -33,12 +33,16 @@ separate rootless daemon. | Variable | Purpose | | --- | --- | | `SERVICE_HOSTNAME` | Container hostname, and the name the shell prompt shows. | -| `PASSWORD` | Web UI login, also the in-container sudo password. **A blank value disables authentication entirely.** | +| `PASSWORD` | Web UI login, also the in-container sudo password. Required. | | `GIT_NAME` / `GIT_EMAIL` | Git author and committer identity | | `PWA_APPNAME` | Optional. Name of the installed web app; defaults to `code-server`. | Generate a password with `openssl rand -base64 24`. +The compose file refuses to start when `PASSWORD` is unset or blank. The image +itself would start anyway and serve code-server with no authentication, on a +container that holds the Docker socket. + `SERVICE_HOSTNAME` is used twice: as the container's `hostname:` and as the `HOST` variable inside it. Coolify injects `HOST=0.0.0.0` into every compose app, and zsh seeds `$HOST` and the `%m`/`%M` prompt escapes from that variable diff --git a/code-server-lsio/compose.yml b/code-server-lsio/compose.yml index fe0c4e4..d6a9279 100644 --- a/code-server-lsio/compose.yml +++ b/code-server-lsio/compose.yml @@ -6,7 +6,7 @@ services: environment: - PUID=1000 - PGID=1000 - - PASSWORD=${PASSWORD} + - PASSWORD=${PASSWORD:?required} - SUDO_PASSWORD=${PASSWORD} - 'DOCKER_MODS=linuxserver/mods:universal-package-install|linuxserver/mods:universal-docker|linuxserver/mods:code-server-golang|linuxserver/mods:code-server-nodejs|linuxserver/mods:code-server-npmglobal|linuxserver/mods:code-server-python3|linuxserver/mods:code-server-zsh' - INSTALL_PACKAGES=bubblewrap|gh|git|glab|unzip|zip