mirror of
https://github.com/phpmyadmin/docker.git
synced 2026-08-24 10:13:22 -05:00
Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
5d89c078f2 | ||
|
|
216be795f7 | ||
|
|
5043535036 | ||
|
|
22f2d4a373 | ||
|
|
ab37078704 | ||
|
|
9fca4e0022 | ||
|
|
240506356c | ||
|
|
04de4ca2ba | ||
|
|
ea2d5dc8fd | ||
|
|
bb0fd043c3 | ||
|
|
812039a7de | ||
|
|
577a94fda6 | ||
|
|
ec0d6a5c3a | ||
|
|
788475217f | ||
|
|
2b712de361 | ||
|
|
9c06d07727 | ||
|
|
a0e0282c91 | ||
|
|
e1fe998378 | ||
|
|
12b0f347cb | ||
|
|
f79c7073ab | ||
|
|
0109a4fbdd | ||
|
|
a0e2d0f499 | ||
|
|
4cbf9ef735 | ||
|
|
6a4843e99d | ||
|
|
998a6d85ab | ||
|
|
8831312555 | ||
|
|
928a52ebcb | ||
|
|
752da8f2d9 | ||
|
|
88b594a77f | ||
|
|
2d6be82ec6 | ||
|
|
e3f29d8d2e | ||
|
|
2335c3151b | ||
|
|
6a687794c6 | ||
|
|
6d69b7796b | ||
|
|
6070d87f73 | ||
|
|
50b7203dbf | ||
|
|
aa656af9c5 | ||
|
|
79a51154c1 | ||
|
|
215f36692f | ||
|
|
3e0bcce10e | ||
|
|
272944cc5a | ||
|
|
6517adbfe3 | ||
|
|
30db079919 | ||
|
|
da4b8f273a | ||
|
|
692333aa2d | ||
|
|
8674356a6d | ||
|
|
a5b42082a8 | ||
|
|
3c0561bd6e | ||
|
|
636af2024a | ||
|
|
1c138c510c | ||
|
|
813fcf8410 | ||
|
|
d10b78cde4 | ||
|
|
644a36f7a0 | ||
|
|
2d43a62d20 | ||
|
|
328b498f51 | ||
|
|
b3cb5de98e | ||
|
|
87e2c6a325 | ||
|
|
87bbb8dd8f | ||
|
|
ab6a09ad9f | ||
|
|
37b7cff908 | ||
|
|
adf9118a38 | ||
|
|
a6c091bd8c | ||
|
|
d455a71d95 | ||
|
|
948bf2d147 | ||
|
|
e1da7554b4 | ||
|
|
a31c702cd5 | ||
|
|
7432be89e0 | ||
|
|
67f9b75357 | ||
|
|
9a7991c3f2 | ||
|
|
271a3e6a3e | ||
|
|
6d73dc8728 | ||
|
|
e68cbb87af | ||
|
|
5ee9a9ced5 | ||
|
|
2cb9a6214e | ||
|
|
4a5875f495 | ||
|
|
5239485cfc | ||
|
|
f650628a76 | ||
|
|
dbfffe50c7 | ||
|
|
fb5c1a2104 | ||
|
|
7967e63883 | ||
|
|
0730e5188e | ||
|
|
47a3db45ad | ||
|
|
f8edb1ca87 | ||
|
|
a03d55e76a | ||
|
|
0006406e35 | ||
|
|
7f5a48b7c3 | ||
|
|
bb70a46858 | ||
|
|
88f6d787d0 | ||
|
|
a1772debe4 | ||
|
|
b0305371a4 | ||
|
|
1241428f99 | ||
|
|
fa108dc809 | ||
|
|
d1f327e462 | ||
|
|
c59f287b98 | ||
|
|
a5fd64c9fb | ||
|
|
e6f53b6f8e | ||
|
|
71d54acc93 | ||
|
|
c3e03b7429 | ||
|
|
83bd66d27f | ||
|
|
1effd43182 | ||
|
|
908e79d246 | ||
|
|
010de91f3c | ||
|
|
7e5dd3b39d | ||
|
|
9b09f1ae4c | ||
|
|
80ce7025ac | ||
|
|
0c1b04d2fc | ||
|
|
031d27ad30 | ||
|
|
905cae841e | ||
|
|
0ed2e6651b | ||
|
|
df4d08c1a8 | ||
|
|
0c9a5f06d5 | ||
|
|
918d2639a9 | ||
|
|
3f1f550631 | ||
|
|
9b6fb4229f | ||
|
|
8b33eefd53 | ||
|
|
095161cdb1 | ||
|
|
b936b8ebd1 | ||
|
|
5ab888d0d4 | ||
|
|
fee52fdd0b | ||
|
|
3c16423f78 | ||
|
|
0b7054a449 | ||
|
|
6718899e83 | ||
|
|
aa6481613d | ||
|
|
0f9d9d2630 | ||
|
|
336ba22d89 | ||
|
|
545fcca480 | ||
|
|
3c859c0511 | ||
|
|
347512bfc4 | ||
|
|
d621982217 | ||
|
|
cc19f8ada1 | ||
|
|
c0cd783445 | ||
|
|
326191915b | ||
|
|
cddd8dda1b | ||
|
|
a9851bbd0c | ||
|
|
b057ee3d89 | ||
|
|
90bc75ac92 | ||
|
|
026ddf5c11 | ||
|
|
2b79d71002 | ||
|
|
4dd05de348 | ||
|
|
7c28533a32 | ||
|
|
056d2b51fd | ||
|
|
030928a01e | ||
|
|
a73a82a790 | ||
|
|
0f4250dc7f | ||
|
|
17b7a91289 | ||
|
|
886f7ae6e3 | ||
|
|
1655371fb0 | ||
|
|
60c187d10d | ||
|
|
3dafd123f8 | ||
|
|
e8ade8e3b1 | ||
|
|
12e6fdf738 | ||
|
|
935605b8d0 | ||
|
|
4482d47ca7 |
@@ -1,23 +0,0 @@
|
||||
# Configuration for probot-stale - https://github.com/probot/stale
|
||||
|
||||
# Number of days of inactivity before an Issue or Pull Request becomes stale
|
||||
daysUntilStale: 60
|
||||
# Number of days of inactivity before a stale Issue or Pull Request is closed
|
||||
daysUntilClose: 7
|
||||
# Issues or Pull Requests with these labels will never be considered stale. Set to `[]` to disable
|
||||
exemptLabels:
|
||||
- pinned
|
||||
- security
|
||||
# Label to use when marking as stale
|
||||
staleLabel: wontfix
|
||||
# Comment to post when marking as stale. Set to `false` to disable
|
||||
markComment: >
|
||||
This issue has been automatically marked as stale because it has not had
|
||||
recent activity. It will be closed if no further activity occurs. Thank you
|
||||
for your contributions.
|
||||
# Comment to post when removing the stale label. Set to `false` to disable
|
||||
unmarkComment: false
|
||||
# Comment to post when closing a stale Issue or Pull Request. Set to `false` to disable
|
||||
closeComment: false
|
||||
# Limit to only `issues` or `pulls`
|
||||
only: pulls
|
||||
@@ -1,5 +1,8 @@
|
||||
name: GitHub CI
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
@@ -18,14 +21,14 @@ jobs:
|
||||
outputs:
|
||||
strategy: ${{ steps.generate-jobs.outputs.strategy }}
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- uses: actions/checkout@v4
|
||||
- uses: docker-library/bashbrew@v0.1.12
|
||||
- id: generate-jobs
|
||||
name: Generate Jobs
|
||||
run: |
|
||||
git clone --depth 1 https://github.com/docker-library/bashbrew.git -b master ~/bashbrew
|
||||
strategy="$(~/bashbrew/scripts/github-actions/generate.sh)"
|
||||
strategy="$(GITHUB_REPOSITORY=phpmyadmin "$BASHBREW_SCRIPTS/github-actions/generate.sh")"
|
||||
echo "strategy=$strategy" >> "$GITHUB_OUTPUT"
|
||||
jq . <<<"$strategy" # sanity check / debugging aid
|
||||
echo "::set-output name=strategy::$strategy"
|
||||
|
||||
test:
|
||||
needs: generate-jobs
|
||||
@@ -33,7 +36,7 @@ jobs:
|
||||
name: ${{ matrix.name }}
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- uses: actions/checkout@v4
|
||||
- name: Prepare Environment
|
||||
run: ${{ matrix.runs.prepare }}
|
||||
- name: Pull Dependencies
|
||||
|
||||
@@ -1,26 +1,40 @@
|
||||
name: Internal test suite
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
push:
|
||||
|
||||
jobs:
|
||||
test-apache-container:
|
||||
name: Test on database ${{ matrix.database-image }}
|
||||
name: Test (${{ matrix.configuration }}) on database ${{ matrix.database-image }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
database-image: ["mariadb:10.4", "mysql:5.7", "mariadb:latest", "mysql:latest"]
|
||||
database-image: ["mariadb:10.6", "mariadb:10.11", "mariadb:latest", "mysql:5.7", "mysql:latest"]
|
||||
configuration: ["default", "one-host", "one-socket-host", "config-mount-dir", "fs-import-export", "different-apache-port", "run-as-www-data", "one-ssl-host"]
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- uses: actions/checkout@v4
|
||||
- name: Generate the testing keys
|
||||
if: ${{ contains(matrix.configuration, 'one-ssl-host') }}
|
||||
run: ./testing/generate-keys.sh
|
||||
- name: Switch to MySQL compatible ENVs
|
||||
if: ${{ contains(matrix.database-image, 'mysql') }}
|
||||
working-directory: ./testing/docker-compose/
|
||||
run: sed -i 's/MARIADB_ROOT_PASSWORD/MYSQL_ROOT_PASSWORD/' ./docker-compose.testing-${{ matrix.configuration }}.yml
|
||||
- name: Switch to MySQL compatible healthcheck
|
||||
if: ${{ contains(matrix.database-image, 'mysql') }}
|
||||
working-directory: ./testing/docker-compose/
|
||||
run: sed -i 's/mariadb-admin/mysqladmin/' ./docker-compose.testing-${{ matrix.configuration }}.yml
|
||||
- name: Build images
|
||||
run: docker-compose -f docker-compose.testing.yml build
|
||||
- name: Run normal tests
|
||||
run: docker-compose -f docker-compose.testing.yml up --build --abort-on-container-exit --exit-code-from=sut
|
||||
working-directory: ./testing/
|
||||
run: docker compose -f ./docker-compose/docker-compose.testing-${{ matrix.configuration }}.yml build
|
||||
- name: Run ${{ matrix.configuration }} tests
|
||||
working-directory: ./testing/
|
||||
run: docker compose -f ./docker-compose/docker-compose.testing-${{ matrix.configuration }}.yml up --build --abort-on-container-exit --exit-code-from=sut
|
||||
env:
|
||||
DB: ${{ matrix.database-image }}
|
||||
- name: Run one host tests
|
||||
run: docker-compose -f docker-compose.testing-one-host.yml up --build --abort-on-container-exit --exit-code-from=sut
|
||||
env:
|
||||
DB: ${{ matrix.database-image }}
|
||||
+2
-1
@@ -3,4 +3,5 @@ __pycache__
|
||||
.pytest_cache
|
||||
.vscode
|
||||
.history
|
||||
.venv
|
||||
.venv
|
||||
testing/*.pem
|
||||
|
||||
@@ -0,0 +1,93 @@
|
||||
# Changelog
|
||||
|
||||
All notable changes to this project will be documented in this file.
|
||||
|
||||
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).
|
||||
|
||||
## [5.2.2] - 2025-01-21
|
||||
|
||||
- Add `TZ` env var to change PHP `date.timezone` (#133)
|
||||
- Update to PHP 8.2 (#411)
|
||||
- Add back a `/sessions` volume for sessions persistence (#399)
|
||||
- Support adding custom configurations in `/etc/phpmyadmin/conf.d` (#401)
|
||||
- Fix for Debian 12 issue (#416) that caused libraries for extensions to be uninstalled
|
||||
- Add extension `bcmath` for 2nd factor authentication (#415)
|
||||
- Refactor `update.sh` (#408)
|
||||
- Enable remoteip mod for Apache (#434)
|
||||
- Add support for `PMA_SSL` and `PMA_SSLS` to enable SSL connection (#441)
|
||||
- Fixed looping through `$sockets` using the same index variable `$i` interferes with the last server id (#186)
|
||||
- Add support for `PMA_SSL_VERIFY` and `PMA_SSL_VERIFIES` (#448)
|
||||
- Add support for `PMA_SSL_CA` and `PMA_SSL_CAS` (#448)
|
||||
- Add support for `PMA_SSL_CERT` and `PMA_SSL_CERTS` (#448)
|
||||
- Add support for `PMA_SSL_KEY` and `PMA_SSL_KEYS` (#448)
|
||||
- Also add `PMA_SSL_DIR` to define the dir where SSL files are generated for `_BASE64` prefixed variables
|
||||
- Support `PMA_SSL_CA_BASE64` and `PMA_SSL_CAS_BASE64` as variables that contain the file contents (#448)
|
||||
- Support `PMA_SSL_KEY_BASE64` and `PMA_SSL_KEYS_BASE64` as variables that contain the file contents (#448)
|
||||
- Support `PMA_SSL_CERT_BASE64` and `PMA_SSL_CERTS_BASE64` as variables that contain the file contents (#448)
|
||||
|
||||
## [5.2.1] - 2023-02-08
|
||||
|
||||
- Move docker-compose test files into a folder
|
||||
- Fix the section about E2E tests in `README.md`
|
||||
- Support docker secrets from file for `PMA_USER` (#372)
|
||||
- Support docker secrets from file for `PMA_CONTROLUSER` (#372)
|
||||
- Support docker secrets from file for `PMA_CONTROLHOST` (#372)
|
||||
- Allow a different Apache port with `APACHE_PORT` (#340)
|
||||
- Add support for ENVs `PMA_UPLOADDIR` and `PMA_SAVEDIR` (#384)
|
||||
- Fixed a bug with `APACHE_PORT` ENV on container restart (#381)
|
||||
- Update to PHP 8.1 (#393)
|
||||
- Add support for ENV `TZ`
|
||||
|
||||
## [5.1.4] - 2022-05-11
|
||||
|
||||
- Fix incorrect image tag name in `README.md`
|
||||
|
||||
## [5.1.2] - 2022-01-22
|
||||
|
||||
- Fix GPG keyservers in Dockerfiles
|
||||
- Remove microbadger badges, it closed
|
||||
- Improve the README file
|
||||
- Fix add back composer.json and remove non needed source files (#345)
|
||||
- Update to PHP 8.0 (#325)
|
||||
|
||||
## [5.1.1] - 2021-06-04
|
||||
|
||||
- Improve documentation
|
||||
|
||||
## [5.1.0] - 2021-02-24
|
||||
|
||||
- Set ini setting `max_input_vars = 10000`
|
||||
- Add support for ENV `PMA_QUERYHISTORYMAX`
|
||||
- Add support for ENV `MAX_EXECUTION_TIME`
|
||||
- Add support for ENV `MEMORY_LIMIT`
|
||||
- Move to GitHub actions
|
||||
- Re-work the test system
|
||||
- Support docker secrets from file for `PMA_CONTROLPASS`
|
||||
- Generate phpmyadmin-misc.ini from ENVs
|
||||
|
||||
## [4.9.{6,7}] - 2020-10-{10,16} and [5.0.{3,4}] - 2020-10-{10,16}
|
||||
|
||||
- Add `tzdata` package
|
||||
- Extract downloaded files directly to web root `/var/www/html/` (#277)
|
||||
- Add SHA checksum when downloading a version
|
||||
- Improved `UPLOAD_LIMIT` documentation
|
||||
- Update documentation from `phpmyadmin/phpmyadmin` to `phpmyadmin`
|
||||
- `phpmyadmin` is now the official image in the Docker official library
|
||||
|
||||
## [5.0.2] - 2020-03-21
|
||||
|
||||
- Add org.opencontainers.image.* labels
|
||||
- Apply some feedback from docker-library team to Dockerfiles
|
||||
|
||||
## [4.9.3] - 2020-01-02 and [5.0.0] - 2019-12-26
|
||||
|
||||
- Add support for ENV `HIDE_PHP_VERSION` to set ini setting `expose_php = Off`
|
||||
- Add support for ENV `UPLOAD_LIMIT` to set `upload_max_filesize` and `post_max_size` ini settings
|
||||
- Add support for ENVs `PMA_CONFIG_BASE64` and `PMA_USER_CONFIG_BASE64` (#192)
|
||||
- Support docker secrets from files for `PMA_PASSWORD`, `MYSQL_ROOT_PASSWORD` and `MYSQL_PASSWORD`
|
||||
- Support docker secrets from files for `PMA_HOSTS` and `PMA_HOST`
|
||||
|
||||
## [4.9.2-2] - 2020-12-20
|
||||
|
||||
- Update to PHP 7.4 (#257)
|
||||
- Drop ini setting `opcache.enable_cli=1`
|
||||
+35
-17
@@ -1,9 +1,10 @@
|
||||
FROM php:7.4-%%VARIANT%%
|
||||
FROM php:%%PHP_VERSION%%-%%VARIANT%%
|
||||
|
||||
# docker-entrypoint.sh dependencies
|
||||
# install and docker-entrypoint.sh dependencies
|
||||
RUN apk add --no-cache \
|
||||
bash \
|
||||
tzdata
|
||||
tzdata \
|
||||
gnupg
|
||||
|
||||
# Install dependencies
|
||||
RUN set -ex; \
|
||||
@@ -25,6 +26,7 @@ RUN set -ex; \
|
||||
mysqli \
|
||||
opcache \
|
||||
zip \
|
||||
bcmath \
|
||||
; \
|
||||
\
|
||||
runDeps="$( \
|
||||
@@ -33,15 +35,25 @@ RUN set -ex; \
|
||||
| sort -u \
|
||||
| awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' \
|
||||
)"; \
|
||||
apk add --virtual .phpmyadmin-phpexts-rundeps $runDeps; \
|
||||
apk add --no-network --virtual .phpmyadmin-phpexts-rundeps $runDeps; \
|
||||
apk del --no-network .build-deps
|
||||
|
||||
# set recommended PHP.ini settings
|
||||
# see https://secure.php.net/manual/en/opcache.installation.php
|
||||
ENV PMA_SSL_DIR /etc/phpmyadmin/ssl
|
||||
ENV MAX_EXECUTION_TIME 600
|
||||
ENV MEMORY_LIMIT 512M
|
||||
ENV UPLOAD_LIMIT 2048K
|
||||
ENV TZ UTC
|
||||
ENV SESSION_SAVE_PATH /sessions
|
||||
RUN set -ex; \
|
||||
mkdir $SESSION_SAVE_PATH; \
|
||||
mkdir -p $PMA_SSL_DIR; \
|
||||
chmod 1777 $SESSION_SAVE_PATH; \
|
||||
chmod 755 $PMA_SSL_DIR; \
|
||||
chown www-data:www-data /etc/phpmyadmin; \
|
||||
chown www-data:www-data $PMA_SSL_DIR; \
|
||||
chown www-data:www-data $SESSION_SAVE_PATH; \
|
||||
\
|
||||
{ \
|
||||
echo 'opcache.memory_consumption=128'; \
|
||||
@@ -63,8 +75,12 @@ RUN set -ex; \
|
||||
echo 'memory_limit=${MEMORY_LIMIT}'; \
|
||||
echo 'post_max_size=${UPLOAD_LIMIT}'; \
|
||||
echo 'upload_max_filesize=${UPLOAD_LIMIT}'; \
|
||||
echo 'date.timezone=${TZ}'; \
|
||||
echo 'session.save_path=${SESSION_SAVE_PATH}'; \
|
||||
} > $PHP_INI_DIR/conf.d/phpmyadmin-misc.ini
|
||||
|
||||
USER www-data:www-data
|
||||
|
||||
# Calculate download URL
|
||||
ENV VERSION %%VERSION%%
|
||||
ENV SHA256 %%SHA256%%
|
||||
@@ -82,35 +98,37 @@ LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
|
||||
# Download tarball, verify it using gpg and extract
|
||||
RUN set -ex; \
|
||||
apk add --no-cache --virtual .fetch-deps \
|
||||
gnupg \
|
||||
; \
|
||||
\
|
||||
export GNUPGHOME="$(mktemp -d)"; \
|
||||
export GPGKEY="3D06A59ECE730EB71B511C17CE752F178259BD92"; \
|
||||
export GPGKEY="%%GPG_KEY%%"; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz $URL; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz.asc $URL.asc; \
|
||||
echo "$SHA256 *phpMyAdmin.tar.xz" | sha256sum -c -; \
|
||||
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver ipv4.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.gnupg.net --recv-keys "$GPGKEY" \
|
||||
gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver pgp.mit.edu --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY"; \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.openpgp.org --recv-keys "$GPGKEY"; \
|
||||
gpg --batch --verify phpMyAdmin.tar.xz.asc phpMyAdmin.tar.xz; \
|
||||
tar -xf phpMyAdmin.tar.xz -C /var/www/html --strip-components=1; \
|
||||
mkdir -p /var/www/html/tmp; \
|
||||
chown www-data:www-data /var/www/html/tmp; \
|
||||
gpgconf --kill all; \
|
||||
rm -r "$GNUPGHOME" phpMyAdmin.tar.xz phpMyAdmin.tar.xz.asc; \
|
||||
rm -rf /var/www/html/setup/ /var/www/html/examples/ /var/www/html/test/ /var/www/html/po/ /var/www/html/composer.json /var/www/html/RELEASE-DATE-$VERSION; \
|
||||
sed -i "s@define('CONFIG_DIR'.*@define('CONFIG_DIR', '/etc/phpmyadmin/');@" /var/www/html/libraries/vendor_config.php; \
|
||||
apk del --no-network .fetch-deps
|
||||
rm -r -v /var/www/html/setup/ /var/www/html/examples/ /var/www/html/js/src/ /var/www/html/babel.config.json /var/www/html/doc/html/_sources/ /var/www/html/RELEASE-DATE-$VERSION /var/www/html/CONTRIBUTING.md; \
|
||||
grep -q -F "'configFile' => ROOT_PATH . 'config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
sed -i "s@'configFile' => .*@'configFile' => '/etc/phpmyadmin/config.inc.php',@" /var/www/html/libraries/vendor_config.php; \
|
||||
grep -q -F "'configFile' => '/etc/phpmyadmin/config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
php -l /var/www/html/libraries/vendor_config.php; \
|
||||
find /var/www/html -type d -exec chmod 555 {} \;; \
|
||||
find /var/www/html -type f -exec chmod 444 {} \;; \
|
||||
chmod 1777 /var/www/html/tmp;
|
||||
|
||||
# Copy configuration
|
||||
COPY config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data helpers.php /etc/phpmyadmin/helpers.php
|
||||
|
||||
# Copy main script
|
||||
COPY docker-entrypoint.sh /docker-entrypoint.sh
|
||||
|
||||
USER root
|
||||
ENTRYPOINT [ "/docker-entrypoint.sh" ]
|
||||
CMD ["%%CMD%%"]
|
||||
|
||||
+53
-27
@@ -1,11 +1,16 @@
|
||||
FROM php:7.4-%%VARIANT%%
|
||||
FROM php:%%PHP_VERSION%%-%%VARIANT%%
|
||||
|
||||
# Install dependencies
|
||||
RUN set -ex; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
libbz2-dev \
|
||||
libfreetype6-dev \
|
||||
@@ -23,27 +28,52 @@ RUN set -ex; \
|
||||
mysqli \
|
||||
opcache \
|
||||
zip \
|
||||
bcmath \
|
||||
; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
ldd "$(php -r 'echo ini_get("extension_dir");')"/*.so \
|
||||
| awk '/=>/ { print $3 }' \
|
||||
extdir="$(php -r 'echo ini_get("extension_dir");')"; \
|
||||
ldd "$extdir"/*.so \
|
||||
| awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); print so }' \
|
||||
| sort -u \
|
||||
| xargs -r dpkg-query -S \
|
||||
| cut -d: -f1 \
|
||||
| sort -u \
|
||||
| xargs -rt apt-mark manual; \
|
||||
\
|
||||
# start: Apache specific build
|
||||
a2enmod remoteip; \
|
||||
# end: Apache specific build
|
||||
\
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
ldd "$extdir"/*.so | grep -qzv "=> not found" || (echo "Sanity check failed: missing libraries:"; ldd "$extdir"/*.so | grep " => not found"; exit 1); \
|
||||
ldd "$extdir"/*.so | grep -q "libzip.so.* => .*/libzip.so.*" || (echo "Sanity check failed: libzip.so is not referenced"; ldd "$extdir"/*.so; exit 1); \
|
||||
err="$(php --version 3>&1 1>&2 2>&3)"; \
|
||||
[ -z "$err" ] || (echo "Sanity check failed: php returned errors; $err"; exit 1;); \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# set recommended PHP.ini settings
|
||||
# see https://secure.php.net/manual/en/opcache.installation.php
|
||||
ENV PMA_SSL_DIR /etc/phpmyadmin/ssl
|
||||
ENV MAX_EXECUTION_TIME 600
|
||||
ENV MEMORY_LIMIT 512M
|
||||
ENV UPLOAD_LIMIT 2048K
|
||||
ENV TZ UTC
|
||||
ENV SESSION_SAVE_PATH /sessions
|
||||
RUN set -ex; \
|
||||
mkdir $SESSION_SAVE_PATH; \
|
||||
mkdir -p $PMA_SSL_DIR; \
|
||||
chmod 1777 $SESSION_SAVE_PATH; \
|
||||
chmod 755 $PMA_SSL_DIR; \
|
||||
chown www-data:www-data /etc/phpmyadmin; \
|
||||
chown www-data:www-data $PMA_SSL_DIR; \
|
||||
chown www-data:www-data $SESSION_SAVE_PATH; \
|
||||
\
|
||||
{ \
|
||||
echo 'opcache.memory_consumption=128'; \
|
||||
@@ -65,8 +95,12 @@ RUN set -ex; \
|
||||
echo 'memory_limit=${MEMORY_LIMIT}'; \
|
||||
echo 'post_max_size=${UPLOAD_LIMIT}'; \
|
||||
echo 'upload_max_filesize=${UPLOAD_LIMIT}'; \
|
||||
echo 'date.timezone=${TZ}'; \
|
||||
echo 'session.save_path=${SESSION_SAVE_PATH}'; \
|
||||
} > $PHP_INI_DIR/conf.d/phpmyadmin-misc.ini
|
||||
|
||||
USER www-data:www-data
|
||||
|
||||
# Calculate download URL
|
||||
ENV VERSION %%VERSION%%
|
||||
ENV SHA256 %%SHA256%%
|
||||
@@ -84,44 +118,36 @@ LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
|
||||
# Download tarball, verify it using gpg and extract
|
||||
RUN set -ex; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
export GNUPGHOME="$(mktemp -d)"; \
|
||||
export GPGKEY="3D06A59ECE730EB71B511C17CE752F178259BD92"; \
|
||||
export GPGKEY="%%GPG_KEY%%"; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz $URL; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz.asc $URL.asc; \
|
||||
echo "$SHA256 *phpMyAdmin.tar.xz" | sha256sum -c -; \
|
||||
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver ipv4.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.gnupg.net --recv-keys "$GPGKEY" \
|
||||
gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver pgp.mit.edu --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY"; \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.openpgp.org --recv-keys "$GPGKEY"; \
|
||||
gpg --batch --verify phpMyAdmin.tar.xz.asc phpMyAdmin.tar.xz; \
|
||||
tar -xf phpMyAdmin.tar.xz -C /var/www/html --strip-components=1; \
|
||||
mkdir -p /var/www/html/tmp; \
|
||||
chown www-data:www-data /var/www/html/tmp; \
|
||||
gpgconf --kill all; \
|
||||
rm -r "$GNUPGHOME" phpMyAdmin.tar.xz phpMyAdmin.tar.xz.asc; \
|
||||
rm -rf /var/www/html/setup/ /var/www/html/examples/ /var/www/html/test/ /var/www/html/po/ /var/www/html/composer.json /var/www/html/RELEASE-DATE-$VERSION; \
|
||||
sed -i "s@define('CONFIG_DIR'.*@define('CONFIG_DIR', '/etc/phpmyadmin/');@" /var/www/html/libraries/vendor_config.php; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
rm -r -v /var/www/html/setup/ /var/www/html/examples/ /var/www/html/js/src/ /var/www/html/babel.config.json /var/www/html/doc/html/_sources/ /var/www/html/RELEASE-DATE-$VERSION /var/www/html/CONTRIBUTING.md; \
|
||||
grep -q -F "'configFile' => ROOT_PATH . 'config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
sed -i "s@'configFile' => .*@'configFile' => '/etc/phpmyadmin/config.inc.php',@" /var/www/html/libraries/vendor_config.php; \
|
||||
grep -q -F "'configFile' => '/etc/phpmyadmin/config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
php -l /var/www/html/libraries/vendor_config.php; \
|
||||
find /var/www/html -type d -exec chmod 555 {} \;; \
|
||||
find /var/www/html -type f -exec chmod 444 {} \;; \
|
||||
chmod 1777 /var/www/html/tmp;
|
||||
|
||||
# Copy configuration
|
||||
COPY config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data helpers.php /etc/phpmyadmin/helpers.php
|
||||
|
||||
# Copy main script
|
||||
COPY docker-entrypoint.sh /docker-entrypoint.sh
|
||||
|
||||
USER root
|
||||
ENTRYPOINT [ "/docker-entrypoint.sh" ]
|
||||
CMD ["%%CMD%%"]
|
||||
|
||||
@@ -16,21 +16,24 @@ build-fpm-alpine:
|
||||
docker build ${DOCKER_FLAGS} -t ${DOCKER_REPO}:testing-fpm-alpine fpm-alpine
|
||||
|
||||
run:
|
||||
docker-compose -f docker-compose.testing.yml up -d
|
||||
docker compose -f ./testing/docker-compose/docker-compose.testing-default.yml up -d
|
||||
|
||||
run-tests:
|
||||
docker-compose exec phpmyadmin /test-docker.sh phpmyadmin_testing 80 phpmyadmin_testing_db
|
||||
testing-%:
|
||||
docker compose -p "phpmyadmin_$@" -f ./testing/docker-compose/docker-compose.$@.yml up --build --abort-on-container-exit --exit-code-from=sut
|
||||
docker compose -p "phpmyadmin_$@" -f ./testing/docker-compose/docker-compose.$@.yml down
|
||||
|
||||
run-tests: testing-default testing-one-host testing-one-socket-host testing-config-mount-dir testing-fs-import-export testing-different-apache-port testing-run-as-www-data testing-one-ssl-host
|
||||
|
||||
logs:
|
||||
docker-compose -f docker-compose.testing.yml logs
|
||||
docker compose -f ./testing/docker-compose/docker-compose.testing-default.yml logs
|
||||
|
||||
clean: stop rm prune
|
||||
|
||||
stop:
|
||||
docker-compose -f docker-compose.testing.yml stop
|
||||
docker compose -f ./testing/docker-compose/docker-compose.testing-default.yml stop
|
||||
|
||||
rm:
|
||||
docker-compose -f docker-compose.testing.yml rm
|
||||
docker compose -f ./testing/docker-compose/docker-compose.testing-default.yml rm
|
||||
|
||||
prune:
|
||||
docker rm `docker ps -q -a --filter status=exited`
|
||||
|
||||
@@ -1,5 +1,9 @@
|
||||
# Official phpMyAdmin Docker image
|
||||
|
||||
Note that since phpMyAdmin has been accepted in to the [official DockerHub repository](https://hub.docker.com/_/phpmyadmin), you can use
|
||||
either that or this older [phpMyAdmin repository](https://hub.docker.com/r/phpmyadmin/phpmyadmin/) for your Docker installation. This
|
||||
is maintained as a courtesy to users who have not migrated.
|
||||
|
||||
Run phpMyAdmin with Alpine, Apache and PHP FPM.
|
||||
|
||||
[](https://github.com/phpmyadmin/docker/actions?query=workflow%3A%22GitHub+CI%22)
|
||||
@@ -15,33 +19,28 @@ Run phpMyAdmin with Alpine, Apache and PHP FPM.
|
||||
[](https://doi-janky.infosiftr.net/job/multiarch/job/s390x/job/phpmyadmin)
|
||||
[][hub]
|
||||
[][hub]
|
||||
[](https://microbadger.com/images/phpmyadmin "Get your own image badge on microbadger.com")
|
||||
[](https://microbadger.com/images/phpmyadmin "Get your own version badge on microbadger.com")
|
||||
|
||||
|
||||
All following examples will bring you phpMyAdmin on `http://localhost:8080`
|
||||
All of the following examples will bring you phpMyAdmin on `http://localhost:8080`
|
||||
where you can enjoy your happy MySQL administration.
|
||||
|
||||
## Credentials
|
||||
|
||||
phpMyAdmin connects using your MySQL server credentials. Please check the corresponding
|
||||
database server image for information on what the default username and password are.
|
||||
To modify username and password during installation you can check the corresponding
|
||||
database server image on Docker Hub.
|
||||
phpMyAdmin connects using your MySQL server credentials. Please check your corresponding
|
||||
database server image for information on the default username and password or how to specify your own custom credentials during installation.
|
||||
|
||||
The official MySQL and MariaDB use the following environment variables to define these:
|
||||
The official MySQL and MariaDB images use the following environment variables to define these:
|
||||
|
||||
* `MYSQL_ROOT_PASSWORD` - This variable is mandatory and specifies the password that will be set for the `root` superuser account.
|
||||
* `MYSQL_USER`, `MYSQL_PASSWORD` - These variables are optional, used in conjunction to create a new user and to set that user's password.
|
||||
- `MYSQL_ROOT_PASSWORD` - This variable is mandatory and specifies the password that will be set for the `root` superuser account.
|
||||
- `MYSQL_USER`, `MYSQL_PASSWORD` - These variables are optional, used in conjunction to create a new user and to set that user's password.
|
||||
|
||||
## Supported Docker Hub tags
|
||||
|
||||
The following tags are available:
|
||||
|
||||
* `latest`, `fpm`, and `fpm-alpine` are always the most recent released version
|
||||
* Major versions, such as `5`, `5-fpm`, and `5-fpm-alpine`
|
||||
* Specific minor versions, such as `5.0`, `5.0-fpm`, and `5-fpm-alpine`
|
||||
* Specific patch versions, such as `5.0.0`, `5.0.0-fpm`, and `5.0.0-alpine`
|
||||
- `latest`, `fpm`, and `fpm-alpine` are always the most recent released version
|
||||
- Major versions, such as `5`, `5-fpm`, and `5-fpm-alpine`
|
||||
- Specific minor versions, such as `5.0`, `5.0-fpm`, and `5-fpm-alpine`
|
||||
- Specific patch versions, such as `5.0.0`, `5.0.0-fpm`, and `5.0.0-fpm-alpine`. Note that, on rare occasion, there may be an intermediary "docker-only" release, such as 4.9.2-1
|
||||
|
||||
A complete list of tags is [available at Docker Hub](https://hub.docker.com/_/phpmyadmin?tab=tags)
|
||||
|
||||
@@ -49,12 +48,12 @@ A complete list of tags is [available at Docker Hub](https://hub.docker.com/_/ph
|
||||
|
||||
We provide three variations:
|
||||
|
||||
* "apache" includes a full Apache webserver with PHP and includes everything needed to work out of the box.
|
||||
- "apache" includes a full Apache webserver with PHP and includes everything needed to work out of the box.
|
||||
This is the default when only a version number is requested.
|
||||
* "fpm" only starts a PHP FPM container. Use this variant if you already have a seperate webserver.
|
||||
- "fpm" only starts a PHP FPM container. Use this variant if you already have a separate webserver.
|
||||
This includes more tools and is therefore a larger image than the "fpm-alpine" variation.
|
||||
* "fpm-alpine" has a very small footprint. It is based on Alpine Linux and only starts a PHP FPM process.
|
||||
Use this variant if you already have a seperate webserver. If you need more tools that are not available on Alpine Linux, use the fpm image instead.
|
||||
- "fpm-alpine" has a very small footprint. It is based on Alpine Linux and only starts a PHP FPM process.
|
||||
Use this variant if you already have a separate webserver. If you need more tools that are not available on Alpine Linux, use the fpm image instead.
|
||||
|
||||
## Usage with linked server
|
||||
|
||||
@@ -62,111 +61,202 @@ First you need to run a MySQL or MariaDB server in Docker, and the phpMyAdmin im
|
||||
linked to the running database container:
|
||||
|
||||
```sh
|
||||
docker run --name myadmin -d --link mysql_db_server:db -p 8080:80 phpmyadmin
|
||||
docker run --name phpmyadmin -d --link mysql_db_server:db -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
## Usage with external server
|
||||
|
||||
You can specify a MySQL host in the `PMA_HOST` environment variable. You can also
|
||||
use `PMA_PORT` to specify port of the server in case it's not the default one:
|
||||
use `PMA_PORT` to specify the port of the server in case it's not the default one:
|
||||
|
||||
```sh
|
||||
docker run --name myadmin -d -e PMA_HOST=dbhost -p 8080:80 phpmyadmin
|
||||
docker run --name phpmyadmin -d -e PMA_HOST=dbhost -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
## Usage with arbitrary server
|
||||
|
||||
You can use arbitrary servers by adding ENV variable `PMA_ARBITRARY=1` to the startup command:
|
||||
You can use arbitrary servers by adding the environment variable `PMA_ARBITRARY=1` to the startup command:
|
||||
|
||||
```sh
|
||||
docker run --name myadmin -d -e PMA_ARBITRARY=1 -p 8080:80 phpmyadmin
|
||||
docker run --name phpmyadmin -d -e PMA_ARBITRARY=1 -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
## Usage with docker-compose and arbitrary server
|
||||
## Usage with docker compose and an arbitrary server
|
||||
|
||||
This will run phpMyAdmin with arbitrary server - allowing you to specify MySQL/MariaDB
|
||||
server on login page.
|
||||
This will run phpMyAdmin with the arbitrary server option - allowing you to specify any MySQL/MariaDB
|
||||
server on the login page.
|
||||
|
||||
Using the docker-compose.yml from https://github.com/phpmyadmin/docker
|
||||
```yaml
|
||||
version: '3.1'
|
||||
|
||||
```sh
|
||||
docker-compose up -d
|
||||
```
|
||||
services:
|
||||
db:
|
||||
image: mariadb:10.11
|
||||
restart: always
|
||||
environment:
|
||||
MYSQL_ROOT_PASSWORD: notSecureChangeMe
|
||||
|
||||
## Run the E2E tests with docker-compose
|
||||
|
||||
You can run the E2E tests with the local test environment by running MariaDB/MySQL databases. Adding ENV variable `PHPMYADMIN_RUN_TEST=true` already added on docker-compose file. Simply run:
|
||||
|
||||
Using the docker-compose.testing.yml from https://github.com/phpmyadmin/docker
|
||||
|
||||
```sh
|
||||
docker-compose -f docker-compose.testing.yml up phpmyadmin
|
||||
phpmyadmin:
|
||||
image: phpmyadmin
|
||||
restart: always
|
||||
ports:
|
||||
- 8080:80
|
||||
environment:
|
||||
- PMA_ARBITRARY=1
|
||||
```
|
||||
|
||||
## Adding Custom Configuration
|
||||
|
||||
You can add your own custom config.inc.php settings (such as Configuration Storage setup)
|
||||
by creating a file named "config.user.inc.php" with the various user defined settings
|
||||
by creating a file named `config.user.inc.php` with the various user defined settings
|
||||
in it, and then linking it into the container using:
|
||||
|
||||
```sh
|
||||
-v /some/local/directory/config.user.inc.php:/etc/phpmyadmin/config.user.inc.php
|
||||
```
|
||||
|
||||
On the "docker run" line like this:
|
||||
On the `docker run` line like this:
|
||||
|
||||
```sh
|
||||
docker run --name myadmin -d --link mysql_db_server:db -p 8080:80 -v /some/local/directory/config.user.inc.php:/etc/phpmyadmin/config.user.inc.php phpmyadmin
|
||||
docker run --name phpmyadmin -d --link mysql_db_server:db -p 8080:80 -v /some/local/directory/config.user.inc.php:/etc/phpmyadmin/config.user.inc.php phpmyadmin:latest
|
||||
```
|
||||
|
||||
See the following links for config file information.
|
||||
https://docs.phpmyadmin.net/en/latest/config.html#config
|
||||
https://docs.phpmyadmin.net/en/latest/setup.html
|
||||
Be sure to have `<?php` as your first line of the configuration file or the contents will not be detected as PHP code.
|
||||
|
||||
## Usage behind reverse proxys
|
||||
Example:
|
||||
|
||||
```php
|
||||
<?php
|
||||
|
||||
$cfg['ShowPhpInfo'] = true; // Adds a link to phpinfo() on the home page
|
||||
```
|
||||
|
||||
See the following links for config file information:
|
||||
|
||||
- https://docs.phpmyadmin.net/en/latest/config.html#config
|
||||
- https://docs.phpmyadmin.net/en/latest/setup.html
|
||||
|
||||
## Adding custom configuration in `/etc/phpmyadmin/conf.d`
|
||||
|
||||
you can also consider storing your custom configuration files in the folder `/etc/phpmyadmin/conf.d`, which is very suitable for managing multiple phpMyAdmin configuration files for different hosts,Then you can create `server-1.php`, `server-2.php`, or any file name you want, and store them in the conf.d directory mounted on the host.
|
||||
|
||||
On the `docker run` line like this:
|
||||
|
||||
```sh
|
||||
docker run --name phpmyadmin -d --link mysql_db_server:db -p 8080:80 -v /some/local/directory/conf.d:/etc/phpmyadmin/conf.d:ro phpmyadmin:latest
|
||||
```
|
||||
|
||||
## Usage behind a reverse proxy
|
||||
|
||||
Set the variable ``PMA_ABSOLUTE_URI`` to the fully-qualified path (``https://pma.example.net/``) where the reverse proxy makes phpMyAdmin available.
|
||||
|
||||
## Sessions persistence
|
||||
|
||||
In order to keep your sessions active between container updates you will need to mount the `/sessions` folder.
|
||||
|
||||
```sh
|
||||
-v /some/local/directory/sessions:/sessions:rw
|
||||
```
|
||||
|
||||
## Connect to the database over SSL
|
||||
|
||||
Set the variable ``PMA_SSL`` to `1` to enable SSL usage from phpMyAdmin to the MySQL server.
|
||||
The default value is `0`.
|
||||
The variable ``PMA_SSLS`` can be used as a comma seperated sequence of `0` and `1` where multiple hosts are mentioned.
|
||||
Values order must follow the ``PMA_HOSTS`` and will be computed accordingly.
|
||||
|
||||
```sh
|
||||
docker run --name phpmyadmin -d -e PMA_HOSTS=sslhost -e PMA_SSL=1 -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
```sh
|
||||
docker run --name phpmyadmin -d -e PMA_HOSTS='sslhost,nosslhost' -e PMA_SSLS='1,0' -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
## Environment variables summary
|
||||
|
||||
* ``PMA_ARBITRARY`` - when set to 1 connection to the arbitrary server will be allowed
|
||||
* ``PMA_HOST`` - define address/host name of the MySQL server
|
||||
* ``PMA_VERBOSE`` - define verbose name of the MySQL server
|
||||
* ``PMA_PORT`` - define port of the MySQL server
|
||||
* ``PMA_HOSTS`` - define comma separated list of address/host names of the MySQL servers
|
||||
* ``PMA_VERBOSES`` - define comma separated list of verbose names of the MySQL servers
|
||||
* ``PMA_PORTS`` - define comma separated list of ports of the MySQL servers
|
||||
* ``PMA_USER`` and ``PMA_PASSWORD`` - define username to use for config authentication method
|
||||
* ``PMA_ABSOLUTE_URI`` - define user-facing URI
|
||||
* ``PMA_CONFIG_BASE64`` - if set, this option will override the default `config.inc.php` with the base64 decoded contents of the variable
|
||||
* ``PMA_USER_CONFIG_BASE64`` - if set, this option will override the default `config.user.inc.php` with the base64 decoded contents of the variable
|
||||
* ``PMA_ABSOLUTE_URI`` - the full URL to phpMyAdmin. Sometimes needed when used in a reverse-proxy configuration. Don't set this unless needed. See [documentation](https://docs.phpmyadmin.net/en/latest/config.html#cfg_PmaAbsoluteUri).
|
||||
* ``PMA_CONTROLHOST`` - when set, this points to an alternate database host used for storing the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage) database
|
||||
* ``PMA_CONTROLPORT`` - if set, will override the default port (3306) for connecting to the control host for storing the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage) database
|
||||
* ``PMA_PMADB`` - define the name of the database to be used for the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage). When not set, the advanced features are not enabled by default (they can still potentially be enabled by the user when logging in with the zero conf (zero configuration) feature. Suggested values: `phpmyadmin` or `pmadb`
|
||||
* ``PMA_CONTROLUSER`` - define the username for phpMyAdmin to use for advanced features (the [controluser](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_controluser))
|
||||
* ``PMA_CONTROLPASS`` - define the password for phpMyAdmin to use with the [controluser](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_controlpass)
|
||||
* ``PMA_QUERYHISTORYDB`` - when set [to true](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryDB), enables storing [SQL history](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_history) to the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage). When [false](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryDB), history is stored in the browser and is cleared when logging out
|
||||
* ``PMA_QUERYHISTORYMAX`` - when set to an integer, controls the number of history items. See [documentation](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryMax). Defaults to `25`.
|
||||
* ``MAX_EXECUTION_TIME`` - if set, will override the maximum execution time in seconds (default 600) for phpMyAdmin ([$cfg['ExecTimeLimit']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_ExecTimeLimit)) and PHP [max_execution_time](https://www.php.net/manual/en/info.configuration.php#ini.max-execution-time) (format as `[0-9+]`)
|
||||
* ``MEMORY_LIMIT`` - if set, will override the memory limit (default 512M) for phpMyAdmin ([$cfg['MemoryLimit']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_MemoryLimit)) and PHP [memory_limit](https://www.php.net/manual/en/ini.core.php#ini.memory-limit) (format as `[0-9+](K,M,G)`)
|
||||
* ``UPLOAD_LIMIT`` - if set, this option will override the default value for apache and php-fpm (format as `[0-9+](K,M,G)` default value is 2048K, this will change ``upload_max_filesize`` and ``post_max_size`` values)
|
||||
* ``HIDE_PHP_VERSION`` - if defined, this option will hide the PHP version (`expose_php = Off`). Set to any value (such as `HIDE_PHP_VERSION=true`).
|
||||
- ``PMA_ARBITRARY`` - when set to 1 connection to the arbitrary server will be allowed
|
||||
- ``PMA_HOST`` - define address/host name of the MySQL server
|
||||
- ``PMA_VERBOSE`` - define verbose name of the MySQL server
|
||||
- ``PMA_PORT`` - define port of the MySQL server
|
||||
- ``PMA_HOSTS`` - define comma separated list of address/host names of the MySQL servers
|
||||
- ``PMA_VERBOSES`` - define comma separated list of verbose names of the MySQL servers
|
||||
- ``PMA_PORTS`` - define comma separated list of ports of the MySQL servers
|
||||
- ``PMA_SOCKET`` - define socket file for the MySQL connection
|
||||
- ``PMA_SOCKETS`` - define comma separated list of socket files for the MySQL connections
|
||||
- ``PMA_SSL_DIR`` - define the path used for SSL files generated from environement variables, default value is `/etc/phpmyadmin/ssl`
|
||||
- ``PMA_SSL`` - when set to 1, defines SSL usage for the MySQL connection
|
||||
- ``PMA_SSLS`` - comma separated list of `0` and `1` defining SSL usage for the corresponding MySQL connections
|
||||
- ``PMA_SSL_VERIFY`` - when set to 1, enables SSL certificate verification for the MySQL connection.
|
||||
- ``PMA_SSL_VERIFIES`` - comma-separated list of `0` and `1` to enable or disable SSL certificate verification for multiple MySQL connections.
|
||||
- ``PMA_SSL_CA`` - in the context of mutual TLS security, allows setting your CA certificate file as a string inside the default `config.inc.php`.
|
||||
- ``PMA_SSL_CAS`` - in the context of mutual TLS security, allows setting multiple CA certificate files as a comma-separated list of strings inside the default `config.inc.php`.
|
||||
- ``PMA_SSL_CERT`` - in the context of mutual TLS security, allows setting your certificate file as a string inside the default `config.inc.php`.
|
||||
- ``PMA_SSL_CERTS`` - in the context of mutual TLS security, allows setting multiple certificate files as a comma-separated list of strings inside the default `config.inc.php`.
|
||||
- ``PMA_SSL_KEY`` - in the context of mutual TLS security, allows setting your private key file as a string inside the default `config.inc.php`.
|
||||
- ``PMA_SSL_KEYS`` - in the context of mutual TLS security, allows setting multiple private key files as a comma-separated list of strings inside the default `config.inc.php`.
|
||||
- ``PMA_USER`` and ``PMA_PASSWORD`` - define username and password to use only with the `config` authentication method
|
||||
- ``PMA_ABSOLUTE_URI`` - the full URL to phpMyAdmin. Sometimes needed when used in a reverse-proxy configuration. Don't set this unless needed. See [documentation](https://docs.phpmyadmin.net/en/latest/config.html#cfg_PmaAbsoluteUri).
|
||||
- ``PMA_CONFIG_BASE64`` - if set, this option will override the default `config.inc.php` with the base64 decoded contents of the variable
|
||||
- ``PMA_USER_CONFIG_BASE64`` - if set, this option will override the default `config.user.inc.php` with the base64 decoded contents of the variable
|
||||
- ``PMA_UPLOADDIR`` - if defined, this option will set the path where files can be saved to be available to import ([$cfg['UploadDir']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_UploadDir))
|
||||
- ``PMA_SAVEDIR`` - if defined, this option will set the path where exported files can be saved ([$cfg['SaveDir']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_SaveDir))
|
||||
- ``PMA_CONTROLHOST`` - when set, this points to an alternate database host used for storing the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage) database
|
||||
- ``PMA_CONTROLPORT`` - if set, will override the default port (3306) for connecting to the control host for storing the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage) database
|
||||
- ``PMA_PMADB`` - define the name of the database to be used for the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage). When not set, the advanced features are not enabled by default: they can still potentially be enabled by the user when logging in with the zero conf (zero configuration) feature. Suggested values: `phpmyadmin` or `pmadb`
|
||||
- ``PMA_CONTROLUSER`` - define the username for phpMyAdmin to use for advanced features (the [controluser](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_controluser))
|
||||
- ``PMA_CONTROLPASS`` - define the password for phpMyAdmin to use with the [controluser](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_controlpass)
|
||||
- ``PMA_QUERYHISTORYDB`` - when set [to true](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryDB), enables storing [SQL history](https://docs.phpmyadmin.net/en/latest/config.html#cfg_Servers_history) to the [phpMyAdmin Configuration Storage database](https://docs.phpmyadmin.net/en/latest/setup.html#phpmyadmin-configuration-storage). When [false](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryDB), history is stored in the browser and is cleared when logging out
|
||||
- ``PMA_QUERYHISTORYMAX`` - when set to an integer, controls the number of history items. See [documentation](https://docs.phpmyadmin.net/en/latest/config.html#cfg_QueryHistoryMax). Defaults to `25`.
|
||||
- ``MAX_EXECUTION_TIME`` - if set, will override the maximum execution time in seconds (default 600) for phpMyAdmin ([$cfg['ExecTimeLimit']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_ExecTimeLimit)) and PHP [max_execution_time](https://www.php.net/manual/en/info.configuration.php#ini.max-execution-time) (format as `[0-9+]`)
|
||||
- ``MEMORY_LIMIT`` - if set, will override the memory limit (default 512M) for phpMyAdmin ([$cfg['MemoryLimit']](https://docs.phpmyadmin.net/en/latest/config.html#cfg_MemoryLimit)) and PHP [memory_limit](https://www.php.net/manual/en/ini.core.php#ini.memory-limit) (format as `[0-9+](K,M,G)` where K is for Kilobytes, M for Megabytes, G for Gigabytes and 1K = 1024 bytes)
|
||||
- ``UPLOAD_LIMIT`` - if set, this option will override the default value for apache and php-fpm (format as `[0-9+](K,M,G)` default value is 2048K, this will change ``upload_max_filesize`` and ``post_max_size`` values)
|
||||
- ``TZ`` - if defined, this option will change the default PHP `date.timezone` from `UTC`. See [documentation](https://www.php.net/manual/en/timezones.php) for supported values.
|
||||
- ``HIDE_PHP_VERSION`` - if defined, this option will hide the PHP version (`expose_php = Off`). Set to any value (such as `HIDE_PHP_VERSION=true`).
|
||||
- ``APACHE_PORT`` - if defined, this option will change the default Apache port from `80` in case you want it to run on a different port like an unprivileged port. Set to any port value (such as `APACHE_PORT=8090`)
|
||||
|
||||
For usage with Docker secrets, appending ``_FILE`` to the ``PMA_PASSWORD`` environment variable is allowed (it overrides ``PMA_PASSWORD`` if it is set):
|
||||
|
||||
```sh
|
||||
docker run --name myadmin -d -e PMA_PASSWORD_FILE=/run/secrets/db_password.txt -p 8080:80 phpmyadmin
|
||||
docker run --name phpmyadmin -d -e PMA_PASSWORD_FILE=/run/secrets/db_password.txt -p 8080:80 phpmyadmin:latest
|
||||
```
|
||||
|
||||
#### Variables that can store the file contents using ``_BASE64``
|
||||
|
||||
- `PMA_SSL_CA`
|
||||
- `PMA_SSL_CAS`
|
||||
- `PMA_SSL_KEY`
|
||||
- `PMA_SSL_KEYS`
|
||||
- `PMA_SSL_CERT`
|
||||
- `PMA_SSL_CERTS`
|
||||
|
||||
Also includes: `PMA_CONFIG_BASE64` or `PMA_USER_CONFIG_BASE64`.
|
||||
|
||||
For example, the variable would be named `PMA_SSL_CA_BASE64` and the value is the base64 encoded contents of the file.
|
||||
|
||||
#### Variables that can be read from a file using ``_FILE``
|
||||
|
||||
- `PMA_PASSWORD`
|
||||
- `MYSQL_ROOT_PASSWORD`
|
||||
- `MYSQL_PASSWORD`
|
||||
- `PMA_HOSTS`
|
||||
- `PMA_HOST`
|
||||
- `PMA_CONTROLPASS`
|
||||
- `MYSQL_ROOT_PASSWORD`
|
||||
- `MYSQL_PASSWORD`
|
||||
- `PMA_USER`
|
||||
- `PMA_PASSWORD`
|
||||
- `PMA_HOSTS`
|
||||
- `PMA_HOST`
|
||||
- `PMA_CONTROLHOST`
|
||||
- `PMA_CONTROLUSER`
|
||||
- `PMA_CONTROLPASS`
|
||||
|
||||
## Run the E2E tests for this docker image
|
||||
|
||||
You can run the E2E test suite on a local test environment.
|
||||
The Requirements are `make`, `docker` and the `docker compose` plugin.
|
||||
|
||||
Clone this repository: `https://github.com/phpmyadmin/docker.git`
|
||||
|
||||
And then run this command to start the test suite:
|
||||
```sh
|
||||
make run-tests
|
||||
```
|
||||
|
||||
For more detailed documentation see https://docs.phpmyadmin.net/en/latest/setup.html#installing-using-docker
|
||||
|
||||
|
||||
+55
-28
@@ -1,11 +1,17 @@
|
||||
FROM php:7.4-apache
|
||||
# DO NOT EDIT: created by update.sh from Dockerfile-debian.template
|
||||
FROM php:8.2-apache
|
||||
|
||||
# Install dependencies
|
||||
RUN set -ex; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
libbz2-dev \
|
||||
libfreetype6-dev \
|
||||
@@ -23,27 +29,52 @@ RUN set -ex; \
|
||||
mysqli \
|
||||
opcache \
|
||||
zip \
|
||||
bcmath \
|
||||
; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
ldd "$(php -r 'echo ini_get("extension_dir");')"/*.so \
|
||||
| awk '/=>/ { print $3 }' \
|
||||
extdir="$(php -r 'echo ini_get("extension_dir");')"; \
|
||||
ldd "$extdir"/*.so \
|
||||
| awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); print so }' \
|
||||
| sort -u \
|
||||
| xargs -r dpkg-query -S \
|
||||
| cut -d: -f1 \
|
||||
| sort -u \
|
||||
| xargs -rt apt-mark manual; \
|
||||
\
|
||||
# start: Apache specific build
|
||||
a2enmod remoteip; \
|
||||
# end: Apache specific build
|
||||
\
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
ldd "$extdir"/*.so | grep -qzv "=> not found" || (echo "Sanity check failed: missing libraries:"; ldd "$extdir"/*.so | grep " => not found"; exit 1); \
|
||||
ldd "$extdir"/*.so | grep -q "libzip.so.* => .*/libzip.so.*" || (echo "Sanity check failed: libzip.so is not referenced"; ldd "$extdir"/*.so; exit 1); \
|
||||
err="$(php --version 3>&1 1>&2 2>&3)"; \
|
||||
[ -z "$err" ] || (echo "Sanity check failed: php returned errors; $err"; exit 1;); \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# set recommended PHP.ini settings
|
||||
# see https://secure.php.net/manual/en/opcache.installation.php
|
||||
ENV PMA_SSL_DIR /etc/phpmyadmin/ssl
|
||||
ENV MAX_EXECUTION_TIME 600
|
||||
ENV MEMORY_LIMIT 512M
|
||||
ENV UPLOAD_LIMIT 2048K
|
||||
ENV TZ UTC
|
||||
ENV SESSION_SAVE_PATH /sessions
|
||||
RUN set -ex; \
|
||||
mkdir $SESSION_SAVE_PATH; \
|
||||
mkdir -p $PMA_SSL_DIR; \
|
||||
chmod 1777 $SESSION_SAVE_PATH; \
|
||||
chmod 755 $PMA_SSL_DIR; \
|
||||
chown www-data:www-data /etc/phpmyadmin; \
|
||||
chown www-data:www-data $PMA_SSL_DIR; \
|
||||
chown www-data:www-data $SESSION_SAVE_PATH; \
|
||||
\
|
||||
{ \
|
||||
echo 'opcache.memory_consumption=128'; \
|
||||
@@ -65,11 +96,15 @@ RUN set -ex; \
|
||||
echo 'memory_limit=${MEMORY_LIMIT}'; \
|
||||
echo 'post_max_size=${UPLOAD_LIMIT}'; \
|
||||
echo 'upload_max_filesize=${UPLOAD_LIMIT}'; \
|
||||
echo 'date.timezone=${TZ}'; \
|
||||
echo 'session.save_path=${SESSION_SAVE_PATH}'; \
|
||||
} > $PHP_INI_DIR/conf.d/phpmyadmin-misc.ini
|
||||
|
||||
USER www-data:www-data
|
||||
|
||||
# Calculate download URL
|
||||
ENV VERSION 5.1.0
|
||||
ENV SHA256 aa8ccf357f672012384df34e1c2bc70147476761c8458a0dad6233497e142c68
|
||||
ENV VERSION 5.2.2
|
||||
ENV SHA256 f881819a3b11e653b0212afaf0cc105db85c767715cb3f5852670f7fc36c9669
|
||||
ENV URL https://files.phpmyadmin.net/phpMyAdmin/${VERSION}/phpMyAdmin-${VERSION}-all-languages.tar.xz
|
||||
|
||||
LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
@@ -84,44 +119,36 @@ LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
|
||||
# Download tarball, verify it using gpg and extract
|
||||
RUN set -ex; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
export GNUPGHOME="$(mktemp -d)"; \
|
||||
export GPGKEY="3D06A59ECE730EB71B511C17CE752F178259BD92"; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz $URL; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz.asc $URL.asc; \
|
||||
echo "$SHA256 *phpMyAdmin.tar.xz" | sha256sum -c -; \
|
||||
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver ipv4.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.gnupg.net --recv-keys "$GPGKEY" \
|
||||
gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver pgp.mit.edu --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY"; \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.openpgp.org --recv-keys "$GPGKEY"; \
|
||||
gpg --batch --verify phpMyAdmin.tar.xz.asc phpMyAdmin.tar.xz; \
|
||||
tar -xf phpMyAdmin.tar.xz -C /var/www/html --strip-components=1; \
|
||||
mkdir -p /var/www/html/tmp; \
|
||||
chown www-data:www-data /var/www/html/tmp; \
|
||||
gpgconf --kill all; \
|
||||
rm -r "$GNUPGHOME" phpMyAdmin.tar.xz phpMyAdmin.tar.xz.asc; \
|
||||
rm -rf /var/www/html/setup/ /var/www/html/examples/ /var/www/html/test/ /var/www/html/po/ /var/www/html/composer.json /var/www/html/RELEASE-DATE-$VERSION; \
|
||||
sed -i "s@define('CONFIG_DIR'.*@define('CONFIG_DIR', '/etc/phpmyadmin/');@" /var/www/html/libraries/vendor_config.php; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
rm -r -v /var/www/html/setup/ /var/www/html/examples/ /var/www/html/js/src/ /var/www/html/babel.config.json /var/www/html/doc/html/_sources/ /var/www/html/RELEASE-DATE-$VERSION /var/www/html/CONTRIBUTING.md; \
|
||||
grep -q -F "'configFile' => ROOT_PATH . 'config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
sed -i "s@'configFile' => .*@'configFile' => '/etc/phpmyadmin/config.inc.php',@" /var/www/html/libraries/vendor_config.php; \
|
||||
grep -q -F "'configFile' => '/etc/phpmyadmin/config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
php -l /var/www/html/libraries/vendor_config.php; \
|
||||
find /var/www/html -type d -exec chmod 555 {} \;; \
|
||||
find /var/www/html -type f -exec chmod 444 {} \;; \
|
||||
chmod 1777 /var/www/html/tmp;
|
||||
|
||||
# Copy configuration
|
||||
COPY config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data helpers.php /etc/phpmyadmin/helpers.php
|
||||
|
||||
# Copy main script
|
||||
COPY docker-entrypoint.sh /docker-entrypoint.sh
|
||||
|
||||
USER root
|
||||
ENTRYPOINT [ "/docker-entrypoint.sh" ]
|
||||
CMD ["apache2-foreground"]
|
||||
|
||||
+115
-21
@@ -1,9 +1,10 @@
|
||||
<?php
|
||||
|
||||
require('/etc/phpmyadmin/config.secret.inc.php');
|
||||
require_once '/etc/phpmyadmin/config.secret.inc.php';
|
||||
require_once '/etc/phpmyadmin/helpers.php';
|
||||
|
||||
/* Ensure we got the environment */
|
||||
$vars = array(
|
||||
$vars = [
|
||||
'PMA_ARBITRARY',
|
||||
'PMA_HOST',
|
||||
'PMA_HOSTS',
|
||||
@@ -24,20 +25,45 @@ $vars = array(
|
||||
'PMA_QUERYHISTORYDB',
|
||||
'PMA_QUERYHISTORYMAX',
|
||||
'MAX_EXECUTION_TIME',
|
||||
'MEMORY_LIMIT'
|
||||
);
|
||||
'MEMORY_LIMIT',
|
||||
'PMA_UPLOADDIR',
|
||||
'PMA_SAVEDIR',
|
||||
'PMA_SSL',
|
||||
'PMA_SSLS',
|
||||
'PMA_SSL_DIR',
|
||||
'PMA_SSL_VERIFY',
|
||||
'PMA_SSL_VERIFIES',
|
||||
'PMA_SSL_CA',
|
||||
'PMA_SSL_CAS',
|
||||
'PMA_SSL_CA_BASE64',
|
||||
'PMA_SSL_CAS_BASE64',
|
||||
'PMA_SSL_KEY',
|
||||
'PMA_SSL_KEYS',
|
||||
'PMA_SSL_KEY_BASE64',
|
||||
'PMA_SSL_KEYS_BASE64',
|
||||
'PMA_SSL_CERT',
|
||||
'PMA_SSL_CERTS',
|
||||
'PMA_SSL_CERT_BASE64',
|
||||
'PMA_SSL_CERTS_BASE64',
|
||||
];
|
||||
|
||||
foreach ($vars as $var) {
|
||||
$env = getenv($var);
|
||||
if (!isset($_ENV[$var]) && $env !== false) {
|
||||
$_ENV[$var] = $env;
|
||||
}
|
||||
}
|
||||
|
||||
if (! defined('PMA_SSL_DIR')) {
|
||||
define('PMA_SSL_DIR', $_ENV['PMA_SSL_DIR'] ?? '/etc/phpmyadmin/ssl');
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYDB'])) {
|
||||
$cfg['QueryHistoryDB'] = boolval($_ENV['PMA_QUERYHISTORYDB']);
|
||||
$cfg['QueryHistoryDB'] = (bool) $_ENV['PMA_QUERYHISTORYDB'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYMAX'])) {
|
||||
$cfg['QueryHistoryMax'] = intval($_ENV['PMA_QUERYHISTORYMAX']);
|
||||
$cfg['QueryHistoryMax'] = (int) $_ENV['PMA_QUERYHISTORYMAX'];
|
||||
}
|
||||
|
||||
/* Arbitrary server connection */
|
||||
@@ -50,29 +76,84 @@ if (isset($_ENV['PMA_ABSOLUTE_URI'])) {
|
||||
$cfg['PmaAbsoluteUri'] = trim($_ENV['PMA_ABSOLUTE_URI']);
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SSL_CA_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CA'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CA_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL key from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEY_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEY'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEY_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL certificate from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERT_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERT'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERT_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL CA certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CAS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CAS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CAS_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL keys from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEYS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEYS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEYS_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERTS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERTS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERTS_BASE64'], 'phpmyadmin-ssl-KEY', 'key', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Figure out hosts */
|
||||
|
||||
/* Fallback to default linked */
|
||||
$hosts = array('db');
|
||||
$hosts = ['db'];
|
||||
|
||||
/* Set by environment */
|
||||
if (!empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = array($_ENV['PMA_HOST']);
|
||||
$verbose = array($_ENV['PMA_VERBOSE']);
|
||||
$ports = array($_ENV['PMA_PORT']);
|
||||
} elseif (!empty($_ENV['PMA_HOSTS'])) {
|
||||
if (! empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = [$_ENV['PMA_HOST']];
|
||||
$verbose = [$_ENV['PMA_VERBOSE']];
|
||||
$ports = [$_ENV['PMA_PORT']];
|
||||
$ssls = [$_ENV['PMA_SSL']];
|
||||
$ssl_verifies = [$_ENV['PMA_SSL_VERIFY']];
|
||||
$ssl_cas = [$_ENV['PMA_SSL_CA']];
|
||||
$ssl_keys = [$_ENV['PMA_SSL_KEY']];
|
||||
$ssl_certs = [$_ENV['PMA_SSL_CERT']];
|
||||
} elseif (! empty($_ENV['PMA_HOSTS'])) {
|
||||
$hosts = array_map('trim', explode(',', $_ENV['PMA_HOSTS']));
|
||||
$verbose = array_map('trim', explode(',', $_ENV['PMA_VERBOSES']));
|
||||
$ports = array_map('trim', explode(',', $_ENV['PMA_PORTS']));
|
||||
$ssls = array_map('trim', explode(',', $_ENV['PMA_SSLS']));
|
||||
$ssl_verifies = array_map('trim', explode(',', $_ENV['PMA_SSL_VERIFIES']));
|
||||
$ssl_cas = array_map('trim', explode(',', $_ENV['PMA_SSL_CAS']));
|
||||
$ssl_keys = array_map('trim', explode(',', $_ENV['PMA_SSL_KEYS']));
|
||||
$ssl_certs = array_map('trim', explode(',', $_ENV['PMA_SSL_CERTS']));
|
||||
}
|
||||
if (!empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = array($_ENV['PMA_SOCKET']);
|
||||
} elseif (!empty($_ENV['PMA_SOCKETS'])) {
|
||||
|
||||
if (! empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = [$_ENV['PMA_SOCKET']];
|
||||
} elseif (! empty($_ENV['PMA_SOCKETS'])) {
|
||||
$sockets = explode(',', $_ENV['PMA_SOCKETS']);
|
||||
}
|
||||
|
||||
/* Server settings */
|
||||
for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
if (isset($ssls[$i - 1]) && $ssls[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl'] = $ssls[$i - 1];
|
||||
}
|
||||
if (isset($ssl_verifies[$i - 1]) && $ssl_verifies[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl_verify'] = $ssl_verifies[$i - 1];
|
||||
}
|
||||
if (isset($ssl_cas[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_ca'] = $ssl_cas[$i - 1];
|
||||
}
|
||||
if (isset($ssl_keys[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_key'] = $ssl_keys[$i - 1];
|
||||
}
|
||||
if (isset($ssl_certs[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_cert'] = $ssl_certs[$i - 1];
|
||||
}
|
||||
$cfg['Servers'][$i]['host'] = $hosts[$i - 1];
|
||||
if (isset($verbose[$i - 1])) {
|
||||
$cfg['Servers'][$i]['verbose'] = $verbose[$i - 1];
|
||||
@@ -124,9 +205,10 @@ for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['compress'] = false;
|
||||
$cfg['Servers'][$i]['AllowNoPassword'] = true;
|
||||
}
|
||||
for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['socket'] = $sockets[$i - 1];
|
||||
$cfg['Servers'][$i]['host'] = 'localhost';
|
||||
// Avoid overwriting the last server id $i, use another variable name
|
||||
for ($socketHostId = 1; isset($sockets[$socketHostId - 1]); $socketHostId++) {
|
||||
$cfg['Servers'][$socketHostId]['socket'] = $sockets[$socketHostId - 1];
|
||||
$cfg['Servers'][$socketHostId]['host'] = 'localhost';
|
||||
}
|
||||
/*
|
||||
* Revert back to last configured server to make
|
||||
@@ -135,8 +217,13 @@ for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$i--;
|
||||
|
||||
/* Uploads setup */
|
||||
$cfg['UploadDir'] = '';
|
||||
$cfg['SaveDir'] = '';
|
||||
if (isset($_ENV['PMA_UPLOADDIR'])) {
|
||||
$cfg['UploadDir'] = $_ENV['PMA_UPLOADDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SAVEDIR'])) {
|
||||
$cfg['SaveDir'] = $_ENV['PMA_SAVEDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['MAX_EXECUTION_TIME'])) {
|
||||
$cfg['ExecTimeLimit'] = $_ENV['MAX_EXECUTION_TIME'];
|
||||
@@ -148,5 +235,12 @@ if (isset($_ENV['MEMORY_LIMIT'])) {
|
||||
|
||||
/* Include User Defined Settings Hook */
|
||||
if (file_exists('/etc/phpmyadmin/config.user.inc.php')) {
|
||||
include('/etc/phpmyadmin/config.user.inc.php');
|
||||
include '/etc/phpmyadmin/config.user.inc.php';
|
||||
}
|
||||
|
||||
/* Support additional configurations */
|
||||
if (is_dir('/etc/phpmyadmin/conf.d/')) {
|
||||
foreach (glob('/etc/phpmyadmin/conf.d/*.php') as $filename) {
|
||||
include $filename;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ if [[ "$1" == apache2* ]] || [ "$1" == php-fpm ]; then
|
||||
\$cfg['blowfish_secret'] = '$(tr -dc 'a-zA-Z0-9~!@#$%^&*_()+}{?></";.,[]=-' < /dev/urandom | fold -w 32 | head -n 1)';
|
||||
EOT
|
||||
fi
|
||||
chgrp www-data /etc/phpmyadmin/config.secret.inc.php
|
||||
|
||||
if [ ! -f /etc/phpmyadmin/config.user.inc.php ]; then
|
||||
touch /etc/phpmyadmin/config.user.inc.php
|
||||
@@ -28,6 +29,15 @@ if [ ! -z "${PMA_USER_CONFIG_BASE64}" ]; then
|
||||
echo "${PMA_USER_CONFIG_BASE64}" | base64 -d > /etc/phpmyadmin/config.user.inc.php
|
||||
fi
|
||||
|
||||
# start: Apache specific settings
|
||||
if [ -n "${APACHE_PORT+x}" ]; then
|
||||
echo "Setting apache port to ${APACHE_PORT}."
|
||||
sed -i "/VirtualHost \*:80/c\\<VirtualHost \*:${APACHE_PORT}\>" /etc/apache2/sites-enabled/000-default.conf
|
||||
sed -i "/Listen 80/c\Listen ${APACHE_PORT}" /etc/apache2/ports.conf
|
||||
apachectl configtest
|
||||
fi
|
||||
# end: Apache specific settings
|
||||
|
||||
get_docker_secret() {
|
||||
local env_var="${1}"
|
||||
local env_var_file="${env_var}_FILE"
|
||||
@@ -40,11 +50,14 @@ get_docker_secret() {
|
||||
fi
|
||||
}
|
||||
|
||||
get_docker_secret PMA_USER
|
||||
get_docker_secret PMA_PASSWORD
|
||||
get_docker_secret MYSQL_ROOT_PASSWORD
|
||||
get_docker_secret MYSQL_PASSWORD
|
||||
get_docker_secret PMA_HOSTS
|
||||
get_docker_secret PMA_HOST
|
||||
get_docker_secret PMA_CONTROLHOST
|
||||
get_docker_secret PMA_CONTROLUSER
|
||||
get_docker_secret PMA_CONTROLPASS
|
||||
|
||||
exec "$@"
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
/**
|
||||
* Helper function to decode and save multiple SSL files from base64.
|
||||
*
|
||||
* @param string $base64FilesContents The base64 encoded string containing multiple files separated by commas.
|
||||
* If no commas are present, the entire string is treated as a single file.
|
||||
* @param string $prefix The prefix to use for the generated file names.
|
||||
* @param string $extension The file extension to use for the generated files.
|
||||
* @param string $storageFolder The folder where to store the generated files.
|
||||
*
|
||||
* @return string A comma-separated list of paths to the generated files.
|
||||
*/
|
||||
function decodeBase64AndSaveFiles(string $base64FilesContents, string $prefix, string $extension, string $storageFolder): string
|
||||
{
|
||||
// Ensure the output directory exists
|
||||
if (! is_dir($storageFolder)) {
|
||||
mkdir($storageFolder, 0755, true);
|
||||
}
|
||||
|
||||
// Split the base64 string into an array of files
|
||||
$base64FilesContents = explode(',', trim($base64FilesContents));
|
||||
$counter = 1;
|
||||
$outputFiles = [];
|
||||
|
||||
// Process each file
|
||||
foreach ($base64FilesContents as $base64FileContent) {
|
||||
$outputFile = $storageFolder . '/' . $prefix . '-' . $counter . '.' . $extension;
|
||||
|
||||
$fileContent = base64_decode($base64FileContent, true);
|
||||
if ($fileContent === false) {
|
||||
echo 'Failed to decode: ' . $base64FileContent;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Write the decoded file to the output directory
|
||||
if (file_put_contents($outputFile, $fileContent) === false) {
|
||||
echo 'Failed to write to ' . $outputFile;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Add the output file path to the list
|
||||
$outputFiles[] = $outputFile;
|
||||
$counter++;
|
||||
}
|
||||
|
||||
// Return a comma-separated list of the generated file paths
|
||||
return implode(',', $outputFiles);
|
||||
}
|
||||
+115
-21
@@ -1,9 +1,10 @@
|
||||
<?php
|
||||
|
||||
require('/etc/phpmyadmin/config.secret.inc.php');
|
||||
require_once '/etc/phpmyadmin/config.secret.inc.php';
|
||||
require_once '/etc/phpmyadmin/helpers.php';
|
||||
|
||||
/* Ensure we got the environment */
|
||||
$vars = array(
|
||||
$vars = [
|
||||
'PMA_ARBITRARY',
|
||||
'PMA_HOST',
|
||||
'PMA_HOSTS',
|
||||
@@ -24,20 +25,45 @@ $vars = array(
|
||||
'PMA_QUERYHISTORYDB',
|
||||
'PMA_QUERYHISTORYMAX',
|
||||
'MAX_EXECUTION_TIME',
|
||||
'MEMORY_LIMIT'
|
||||
);
|
||||
'MEMORY_LIMIT',
|
||||
'PMA_UPLOADDIR',
|
||||
'PMA_SAVEDIR',
|
||||
'PMA_SSL',
|
||||
'PMA_SSLS',
|
||||
'PMA_SSL_DIR',
|
||||
'PMA_SSL_VERIFY',
|
||||
'PMA_SSL_VERIFIES',
|
||||
'PMA_SSL_CA',
|
||||
'PMA_SSL_CAS',
|
||||
'PMA_SSL_CA_BASE64',
|
||||
'PMA_SSL_CAS_BASE64',
|
||||
'PMA_SSL_KEY',
|
||||
'PMA_SSL_KEYS',
|
||||
'PMA_SSL_KEY_BASE64',
|
||||
'PMA_SSL_KEYS_BASE64',
|
||||
'PMA_SSL_CERT',
|
||||
'PMA_SSL_CERTS',
|
||||
'PMA_SSL_CERT_BASE64',
|
||||
'PMA_SSL_CERTS_BASE64',
|
||||
];
|
||||
|
||||
foreach ($vars as $var) {
|
||||
$env = getenv($var);
|
||||
if (!isset($_ENV[$var]) && $env !== false) {
|
||||
$_ENV[$var] = $env;
|
||||
}
|
||||
}
|
||||
|
||||
if (! defined('PMA_SSL_DIR')) {
|
||||
define('PMA_SSL_DIR', $_ENV['PMA_SSL_DIR'] ?? '/etc/phpmyadmin/ssl');
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYDB'])) {
|
||||
$cfg['QueryHistoryDB'] = boolval($_ENV['PMA_QUERYHISTORYDB']);
|
||||
$cfg['QueryHistoryDB'] = (bool) $_ENV['PMA_QUERYHISTORYDB'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYMAX'])) {
|
||||
$cfg['QueryHistoryMax'] = intval($_ENV['PMA_QUERYHISTORYMAX']);
|
||||
$cfg['QueryHistoryMax'] = (int) $_ENV['PMA_QUERYHISTORYMAX'];
|
||||
}
|
||||
|
||||
/* Arbitrary server connection */
|
||||
@@ -50,29 +76,84 @@ if (isset($_ENV['PMA_ABSOLUTE_URI'])) {
|
||||
$cfg['PmaAbsoluteUri'] = trim($_ENV['PMA_ABSOLUTE_URI']);
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SSL_CA_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CA'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CA_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL key from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEY_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEY'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEY_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL certificate from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERT_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERT'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERT_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL CA certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CAS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CAS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CAS_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL keys from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEYS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEYS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEYS_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERTS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERTS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERTS_BASE64'], 'phpmyadmin-ssl-KEY', 'key', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Figure out hosts */
|
||||
|
||||
/* Fallback to default linked */
|
||||
$hosts = array('db');
|
||||
$hosts = ['db'];
|
||||
|
||||
/* Set by environment */
|
||||
if (!empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = array($_ENV['PMA_HOST']);
|
||||
$verbose = array($_ENV['PMA_VERBOSE']);
|
||||
$ports = array($_ENV['PMA_PORT']);
|
||||
} elseif (!empty($_ENV['PMA_HOSTS'])) {
|
||||
if (! empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = [$_ENV['PMA_HOST']];
|
||||
$verbose = [$_ENV['PMA_VERBOSE']];
|
||||
$ports = [$_ENV['PMA_PORT']];
|
||||
$ssls = [$_ENV['PMA_SSL']];
|
||||
$ssl_verifies = [$_ENV['PMA_SSL_VERIFY']];
|
||||
$ssl_cas = [$_ENV['PMA_SSL_CA']];
|
||||
$ssl_keys = [$_ENV['PMA_SSL_KEY']];
|
||||
$ssl_certs = [$_ENV['PMA_SSL_CERT']];
|
||||
} elseif (! empty($_ENV['PMA_HOSTS'])) {
|
||||
$hosts = array_map('trim', explode(',', $_ENV['PMA_HOSTS']));
|
||||
$verbose = array_map('trim', explode(',', $_ENV['PMA_VERBOSES']));
|
||||
$ports = array_map('trim', explode(',', $_ENV['PMA_PORTS']));
|
||||
$ssls = array_map('trim', explode(',', $_ENV['PMA_SSLS']));
|
||||
$ssl_verifies = array_map('trim', explode(',', $_ENV['PMA_SSL_VERIFIES']));
|
||||
$ssl_cas = array_map('trim', explode(',', $_ENV['PMA_SSL_CAS']));
|
||||
$ssl_keys = array_map('trim', explode(',', $_ENV['PMA_SSL_KEYS']));
|
||||
$ssl_certs = array_map('trim', explode(',', $_ENV['PMA_SSL_CERTS']));
|
||||
}
|
||||
if (!empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = array($_ENV['PMA_SOCKET']);
|
||||
} elseif (!empty($_ENV['PMA_SOCKETS'])) {
|
||||
|
||||
if (! empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = [$_ENV['PMA_SOCKET']];
|
||||
} elseif (! empty($_ENV['PMA_SOCKETS'])) {
|
||||
$sockets = explode(',', $_ENV['PMA_SOCKETS']);
|
||||
}
|
||||
|
||||
/* Server settings */
|
||||
for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
if (isset($ssls[$i - 1]) && $ssls[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl'] = $ssls[$i - 1];
|
||||
}
|
||||
if (isset($ssl_verifies[$i - 1]) && $ssl_verifies[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl_verify'] = $ssl_verifies[$i - 1];
|
||||
}
|
||||
if (isset($ssl_cas[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_ca'] = $ssl_cas[$i - 1];
|
||||
}
|
||||
if (isset($ssl_keys[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_key'] = $ssl_keys[$i - 1];
|
||||
}
|
||||
if (isset($ssl_certs[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_cert'] = $ssl_certs[$i - 1];
|
||||
}
|
||||
$cfg['Servers'][$i]['host'] = $hosts[$i - 1];
|
||||
if (isset($verbose[$i - 1])) {
|
||||
$cfg['Servers'][$i]['verbose'] = $verbose[$i - 1];
|
||||
@@ -124,9 +205,10 @@ for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['compress'] = false;
|
||||
$cfg['Servers'][$i]['AllowNoPassword'] = true;
|
||||
}
|
||||
for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['socket'] = $sockets[$i - 1];
|
||||
$cfg['Servers'][$i]['host'] = 'localhost';
|
||||
// Avoid overwriting the last server id $i, use another variable name
|
||||
for ($socketHostId = 1; isset($sockets[$socketHostId - 1]); $socketHostId++) {
|
||||
$cfg['Servers'][$socketHostId]['socket'] = $sockets[$socketHostId - 1];
|
||||
$cfg['Servers'][$socketHostId]['host'] = 'localhost';
|
||||
}
|
||||
/*
|
||||
* Revert back to last configured server to make
|
||||
@@ -135,8 +217,13 @@ for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$i--;
|
||||
|
||||
/* Uploads setup */
|
||||
$cfg['UploadDir'] = '';
|
||||
$cfg['SaveDir'] = '';
|
||||
if (isset($_ENV['PMA_UPLOADDIR'])) {
|
||||
$cfg['UploadDir'] = $_ENV['PMA_UPLOADDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SAVEDIR'])) {
|
||||
$cfg['SaveDir'] = $_ENV['PMA_SAVEDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['MAX_EXECUTION_TIME'])) {
|
||||
$cfg['ExecTimeLimit'] = $_ENV['MAX_EXECUTION_TIME'];
|
||||
@@ -148,5 +235,12 @@ if (isset($_ENV['MEMORY_LIMIT'])) {
|
||||
|
||||
/* Include User Defined Settings Hook */
|
||||
if (file_exists('/etc/phpmyadmin/config.user.inc.php')) {
|
||||
include('/etc/phpmyadmin/config.user.inc.php');
|
||||
include '/etc/phpmyadmin/config.user.inc.php';
|
||||
}
|
||||
|
||||
/* Support additional configurations */
|
||||
if (is_dir('/etc/phpmyadmin/conf.d/')) {
|
||||
foreach (glob('/etc/phpmyadmin/conf.d/*.php') as $filename) {
|
||||
include $filename;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ if [[ "$1" == apache2* ]] || [ "$1" == php-fpm ]; then
|
||||
\$cfg['blowfish_secret'] = '$(tr -dc 'a-zA-Z0-9~!@#$%^&*_()+}{?></";.,[]=-' < /dev/urandom | fold -w 32 | head -n 1)';
|
||||
EOT
|
||||
fi
|
||||
chgrp www-data /etc/phpmyadmin/config.secret.inc.php
|
||||
|
||||
if [ ! -f /etc/phpmyadmin/config.user.inc.php ]; then
|
||||
touch /etc/phpmyadmin/config.user.inc.php
|
||||
@@ -28,6 +29,15 @@ if [ ! -z "${PMA_USER_CONFIG_BASE64}" ]; then
|
||||
echo "${PMA_USER_CONFIG_BASE64}" | base64 -d > /etc/phpmyadmin/config.user.inc.php
|
||||
fi
|
||||
|
||||
# start: Apache specific settings
|
||||
if [ -n "${APACHE_PORT+x}" ]; then
|
||||
echo "Setting apache port to ${APACHE_PORT}."
|
||||
sed -i "/VirtualHost \*:80/c\\<VirtualHost \*:${APACHE_PORT}\>" /etc/apache2/sites-enabled/000-default.conf
|
||||
sed -i "/Listen 80/c\Listen ${APACHE_PORT}" /etc/apache2/ports.conf
|
||||
apachectl configtest
|
||||
fi
|
||||
# end: Apache specific settings
|
||||
|
||||
get_docker_secret() {
|
||||
local env_var="${1}"
|
||||
local env_var_file="${env_var}_FILE"
|
||||
@@ -40,11 +50,14 @@ get_docker_secret() {
|
||||
fi
|
||||
}
|
||||
|
||||
get_docker_secret PMA_USER
|
||||
get_docker_secret PMA_PASSWORD
|
||||
get_docker_secret MYSQL_ROOT_PASSWORD
|
||||
get_docker_secret MYSQL_PASSWORD
|
||||
get_docker_secret PMA_HOSTS
|
||||
get_docker_secret PMA_HOST
|
||||
get_docker_secret PMA_CONTROLHOST
|
||||
get_docker_secret PMA_CONTROLUSER
|
||||
get_docker_secret PMA_CONTROLPASS
|
||||
|
||||
exec "$@"
|
||||
|
||||
+37
-18
@@ -1,9 +1,11 @@
|
||||
FROM php:7.4-fpm-alpine
|
||||
# DO NOT EDIT: created by update.sh from Dockerfile-alpine.template
|
||||
FROM php:8.2-fpm-alpine
|
||||
|
||||
# docker-entrypoint.sh dependencies
|
||||
# install and docker-entrypoint.sh dependencies
|
||||
RUN apk add --no-cache \
|
||||
bash \
|
||||
tzdata
|
||||
tzdata \
|
||||
gnupg
|
||||
|
||||
# Install dependencies
|
||||
RUN set -ex; \
|
||||
@@ -25,6 +27,7 @@ RUN set -ex; \
|
||||
mysqli \
|
||||
opcache \
|
||||
zip \
|
||||
bcmath \
|
||||
; \
|
||||
\
|
||||
runDeps="$( \
|
||||
@@ -33,15 +36,25 @@ RUN set -ex; \
|
||||
| sort -u \
|
||||
| awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' \
|
||||
)"; \
|
||||
apk add --virtual .phpmyadmin-phpexts-rundeps $runDeps; \
|
||||
apk add --no-network --virtual .phpmyadmin-phpexts-rundeps $runDeps; \
|
||||
apk del --no-network .build-deps
|
||||
|
||||
# set recommended PHP.ini settings
|
||||
# see https://secure.php.net/manual/en/opcache.installation.php
|
||||
ENV PMA_SSL_DIR /etc/phpmyadmin/ssl
|
||||
ENV MAX_EXECUTION_TIME 600
|
||||
ENV MEMORY_LIMIT 512M
|
||||
ENV UPLOAD_LIMIT 2048K
|
||||
ENV TZ UTC
|
||||
ENV SESSION_SAVE_PATH /sessions
|
||||
RUN set -ex; \
|
||||
mkdir $SESSION_SAVE_PATH; \
|
||||
mkdir -p $PMA_SSL_DIR; \
|
||||
chmod 1777 $SESSION_SAVE_PATH; \
|
||||
chmod 755 $PMA_SSL_DIR; \
|
||||
chown www-data:www-data /etc/phpmyadmin; \
|
||||
chown www-data:www-data $PMA_SSL_DIR; \
|
||||
chown www-data:www-data $SESSION_SAVE_PATH; \
|
||||
\
|
||||
{ \
|
||||
echo 'opcache.memory_consumption=128'; \
|
||||
@@ -63,11 +76,15 @@ RUN set -ex; \
|
||||
echo 'memory_limit=${MEMORY_LIMIT}'; \
|
||||
echo 'post_max_size=${UPLOAD_LIMIT}'; \
|
||||
echo 'upload_max_filesize=${UPLOAD_LIMIT}'; \
|
||||
echo 'date.timezone=${TZ}'; \
|
||||
echo 'session.save_path=${SESSION_SAVE_PATH}'; \
|
||||
} > $PHP_INI_DIR/conf.d/phpmyadmin-misc.ini
|
||||
|
||||
USER www-data:www-data
|
||||
|
||||
# Calculate download URL
|
||||
ENV VERSION 5.1.0
|
||||
ENV SHA256 aa8ccf357f672012384df34e1c2bc70147476761c8458a0dad6233497e142c68
|
||||
ENV VERSION 5.2.2
|
||||
ENV SHA256 f881819a3b11e653b0212afaf0cc105db85c767715cb3f5852670f7fc36c9669
|
||||
ENV URL https://files.phpmyadmin.net/phpMyAdmin/${VERSION}/phpMyAdmin-${VERSION}-all-languages.tar.xz
|
||||
|
||||
LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
@@ -82,35 +99,37 @@ LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
|
||||
# Download tarball, verify it using gpg and extract
|
||||
RUN set -ex; \
|
||||
apk add --no-cache --virtual .fetch-deps \
|
||||
gnupg \
|
||||
; \
|
||||
\
|
||||
export GNUPGHOME="$(mktemp -d)"; \
|
||||
export GPGKEY="3D06A59ECE730EB71B511C17CE752F178259BD92"; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz $URL; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz.asc $URL.asc; \
|
||||
echo "$SHA256 *phpMyAdmin.tar.xz" | sha256sum -c -; \
|
||||
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver ipv4.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.gnupg.net --recv-keys "$GPGKEY" \
|
||||
gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver pgp.mit.edu --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY"; \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.openpgp.org --recv-keys "$GPGKEY"; \
|
||||
gpg --batch --verify phpMyAdmin.tar.xz.asc phpMyAdmin.tar.xz; \
|
||||
tar -xf phpMyAdmin.tar.xz -C /var/www/html --strip-components=1; \
|
||||
mkdir -p /var/www/html/tmp; \
|
||||
chown www-data:www-data /var/www/html/tmp; \
|
||||
gpgconf --kill all; \
|
||||
rm -r "$GNUPGHOME" phpMyAdmin.tar.xz phpMyAdmin.tar.xz.asc; \
|
||||
rm -rf /var/www/html/setup/ /var/www/html/examples/ /var/www/html/test/ /var/www/html/po/ /var/www/html/composer.json /var/www/html/RELEASE-DATE-$VERSION; \
|
||||
sed -i "s@define('CONFIG_DIR'.*@define('CONFIG_DIR', '/etc/phpmyadmin/');@" /var/www/html/libraries/vendor_config.php; \
|
||||
apk del --no-network .fetch-deps
|
||||
rm -r -v /var/www/html/setup/ /var/www/html/examples/ /var/www/html/js/src/ /var/www/html/babel.config.json /var/www/html/doc/html/_sources/ /var/www/html/RELEASE-DATE-$VERSION /var/www/html/CONTRIBUTING.md; \
|
||||
grep -q -F "'configFile' => ROOT_PATH . 'config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
sed -i "s@'configFile' => .*@'configFile' => '/etc/phpmyadmin/config.inc.php',@" /var/www/html/libraries/vendor_config.php; \
|
||||
grep -q -F "'configFile' => '/etc/phpmyadmin/config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
php -l /var/www/html/libraries/vendor_config.php; \
|
||||
find /var/www/html -type d -exec chmod 555 {} \;; \
|
||||
find /var/www/html -type f -exec chmod 444 {} \;; \
|
||||
chmod 1777 /var/www/html/tmp;
|
||||
|
||||
# Copy configuration
|
||||
COPY config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data helpers.php /etc/phpmyadmin/helpers.php
|
||||
|
||||
# Copy main script
|
||||
COPY docker-entrypoint.sh /docker-entrypoint.sh
|
||||
|
||||
USER root
|
||||
ENTRYPOINT [ "/docker-entrypoint.sh" ]
|
||||
CMD ["php-fpm"]
|
||||
|
||||
+115
-21
@@ -1,9 +1,10 @@
|
||||
<?php
|
||||
|
||||
require('/etc/phpmyadmin/config.secret.inc.php');
|
||||
require_once '/etc/phpmyadmin/config.secret.inc.php';
|
||||
require_once '/etc/phpmyadmin/helpers.php';
|
||||
|
||||
/* Ensure we got the environment */
|
||||
$vars = array(
|
||||
$vars = [
|
||||
'PMA_ARBITRARY',
|
||||
'PMA_HOST',
|
||||
'PMA_HOSTS',
|
||||
@@ -24,20 +25,45 @@ $vars = array(
|
||||
'PMA_QUERYHISTORYDB',
|
||||
'PMA_QUERYHISTORYMAX',
|
||||
'MAX_EXECUTION_TIME',
|
||||
'MEMORY_LIMIT'
|
||||
);
|
||||
'MEMORY_LIMIT',
|
||||
'PMA_UPLOADDIR',
|
||||
'PMA_SAVEDIR',
|
||||
'PMA_SSL',
|
||||
'PMA_SSLS',
|
||||
'PMA_SSL_DIR',
|
||||
'PMA_SSL_VERIFY',
|
||||
'PMA_SSL_VERIFIES',
|
||||
'PMA_SSL_CA',
|
||||
'PMA_SSL_CAS',
|
||||
'PMA_SSL_CA_BASE64',
|
||||
'PMA_SSL_CAS_BASE64',
|
||||
'PMA_SSL_KEY',
|
||||
'PMA_SSL_KEYS',
|
||||
'PMA_SSL_KEY_BASE64',
|
||||
'PMA_SSL_KEYS_BASE64',
|
||||
'PMA_SSL_CERT',
|
||||
'PMA_SSL_CERTS',
|
||||
'PMA_SSL_CERT_BASE64',
|
||||
'PMA_SSL_CERTS_BASE64',
|
||||
];
|
||||
|
||||
foreach ($vars as $var) {
|
||||
$env = getenv($var);
|
||||
if (!isset($_ENV[$var]) && $env !== false) {
|
||||
$_ENV[$var] = $env;
|
||||
}
|
||||
}
|
||||
|
||||
if (! defined('PMA_SSL_DIR')) {
|
||||
define('PMA_SSL_DIR', $_ENV['PMA_SSL_DIR'] ?? '/etc/phpmyadmin/ssl');
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYDB'])) {
|
||||
$cfg['QueryHistoryDB'] = boolval($_ENV['PMA_QUERYHISTORYDB']);
|
||||
$cfg['QueryHistoryDB'] = (bool) $_ENV['PMA_QUERYHISTORYDB'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYMAX'])) {
|
||||
$cfg['QueryHistoryMax'] = intval($_ENV['PMA_QUERYHISTORYMAX']);
|
||||
$cfg['QueryHistoryMax'] = (int) $_ENV['PMA_QUERYHISTORYMAX'];
|
||||
}
|
||||
|
||||
/* Arbitrary server connection */
|
||||
@@ -50,29 +76,84 @@ if (isset($_ENV['PMA_ABSOLUTE_URI'])) {
|
||||
$cfg['PmaAbsoluteUri'] = trim($_ENV['PMA_ABSOLUTE_URI']);
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SSL_CA_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CA'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CA_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL key from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEY_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEY'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEY_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL certificate from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERT_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERT'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERT_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL CA certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CAS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CAS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CAS_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL keys from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEYS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEYS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEYS_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERTS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERTS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERTS_BASE64'], 'phpmyadmin-ssl-KEY', 'key', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Figure out hosts */
|
||||
|
||||
/* Fallback to default linked */
|
||||
$hosts = array('db');
|
||||
$hosts = ['db'];
|
||||
|
||||
/* Set by environment */
|
||||
if (!empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = array($_ENV['PMA_HOST']);
|
||||
$verbose = array($_ENV['PMA_VERBOSE']);
|
||||
$ports = array($_ENV['PMA_PORT']);
|
||||
} elseif (!empty($_ENV['PMA_HOSTS'])) {
|
||||
if (! empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = [$_ENV['PMA_HOST']];
|
||||
$verbose = [$_ENV['PMA_VERBOSE']];
|
||||
$ports = [$_ENV['PMA_PORT']];
|
||||
$ssls = [$_ENV['PMA_SSL']];
|
||||
$ssl_verifies = [$_ENV['PMA_SSL_VERIFY']];
|
||||
$ssl_cas = [$_ENV['PMA_SSL_CA']];
|
||||
$ssl_keys = [$_ENV['PMA_SSL_KEY']];
|
||||
$ssl_certs = [$_ENV['PMA_SSL_CERT']];
|
||||
} elseif (! empty($_ENV['PMA_HOSTS'])) {
|
||||
$hosts = array_map('trim', explode(',', $_ENV['PMA_HOSTS']));
|
||||
$verbose = array_map('trim', explode(',', $_ENV['PMA_VERBOSES']));
|
||||
$ports = array_map('trim', explode(',', $_ENV['PMA_PORTS']));
|
||||
$ssls = array_map('trim', explode(',', $_ENV['PMA_SSLS']));
|
||||
$ssl_verifies = array_map('trim', explode(',', $_ENV['PMA_SSL_VERIFIES']));
|
||||
$ssl_cas = array_map('trim', explode(',', $_ENV['PMA_SSL_CAS']));
|
||||
$ssl_keys = array_map('trim', explode(',', $_ENV['PMA_SSL_KEYS']));
|
||||
$ssl_certs = array_map('trim', explode(',', $_ENV['PMA_SSL_CERTS']));
|
||||
}
|
||||
if (!empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = array($_ENV['PMA_SOCKET']);
|
||||
} elseif (!empty($_ENV['PMA_SOCKETS'])) {
|
||||
|
||||
if (! empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = [$_ENV['PMA_SOCKET']];
|
||||
} elseif (! empty($_ENV['PMA_SOCKETS'])) {
|
||||
$sockets = explode(',', $_ENV['PMA_SOCKETS']);
|
||||
}
|
||||
|
||||
/* Server settings */
|
||||
for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
if (isset($ssls[$i - 1]) && $ssls[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl'] = $ssls[$i - 1];
|
||||
}
|
||||
if (isset($ssl_verifies[$i - 1]) && $ssl_verifies[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl_verify'] = $ssl_verifies[$i - 1];
|
||||
}
|
||||
if (isset($ssl_cas[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_ca'] = $ssl_cas[$i - 1];
|
||||
}
|
||||
if (isset($ssl_keys[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_key'] = $ssl_keys[$i - 1];
|
||||
}
|
||||
if (isset($ssl_certs[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_cert'] = $ssl_certs[$i - 1];
|
||||
}
|
||||
$cfg['Servers'][$i]['host'] = $hosts[$i - 1];
|
||||
if (isset($verbose[$i - 1])) {
|
||||
$cfg['Servers'][$i]['verbose'] = $verbose[$i - 1];
|
||||
@@ -124,9 +205,10 @@ for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['compress'] = false;
|
||||
$cfg['Servers'][$i]['AllowNoPassword'] = true;
|
||||
}
|
||||
for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['socket'] = $sockets[$i - 1];
|
||||
$cfg['Servers'][$i]['host'] = 'localhost';
|
||||
// Avoid overwriting the last server id $i, use another variable name
|
||||
for ($socketHostId = 1; isset($sockets[$socketHostId - 1]); $socketHostId++) {
|
||||
$cfg['Servers'][$socketHostId]['socket'] = $sockets[$socketHostId - 1];
|
||||
$cfg['Servers'][$socketHostId]['host'] = 'localhost';
|
||||
}
|
||||
/*
|
||||
* Revert back to last configured server to make
|
||||
@@ -135,8 +217,13 @@ for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$i--;
|
||||
|
||||
/* Uploads setup */
|
||||
$cfg['UploadDir'] = '';
|
||||
$cfg['SaveDir'] = '';
|
||||
if (isset($_ENV['PMA_UPLOADDIR'])) {
|
||||
$cfg['UploadDir'] = $_ENV['PMA_UPLOADDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SAVEDIR'])) {
|
||||
$cfg['SaveDir'] = $_ENV['PMA_SAVEDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['MAX_EXECUTION_TIME'])) {
|
||||
$cfg['ExecTimeLimit'] = $_ENV['MAX_EXECUTION_TIME'];
|
||||
@@ -148,5 +235,12 @@ if (isset($_ENV['MEMORY_LIMIT'])) {
|
||||
|
||||
/* Include User Defined Settings Hook */
|
||||
if (file_exists('/etc/phpmyadmin/config.user.inc.php')) {
|
||||
include('/etc/phpmyadmin/config.user.inc.php');
|
||||
include '/etc/phpmyadmin/config.user.inc.php';
|
||||
}
|
||||
|
||||
/* Support additional configurations */
|
||||
if (is_dir('/etc/phpmyadmin/conf.d/')) {
|
||||
foreach (glob('/etc/phpmyadmin/conf.d/*.php') as $filename) {
|
||||
include $filename;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ if [[ "$1" == apache2* ]] || [ "$1" == php-fpm ]; then
|
||||
\$cfg['blowfish_secret'] = '$(tr -dc 'a-zA-Z0-9~!@#$%^&*_()+}{?></";.,[]=-' < /dev/urandom | fold -w 32 | head -n 1)';
|
||||
EOT
|
||||
fi
|
||||
chgrp www-data /etc/phpmyadmin/config.secret.inc.php
|
||||
|
||||
if [ ! -f /etc/phpmyadmin/config.user.inc.php ]; then
|
||||
touch /etc/phpmyadmin/config.user.inc.php
|
||||
@@ -28,6 +29,7 @@ if [ ! -z "${PMA_USER_CONFIG_BASE64}" ]; then
|
||||
echo "${PMA_USER_CONFIG_BASE64}" | base64 -d > /etc/phpmyadmin/config.user.inc.php
|
||||
fi
|
||||
|
||||
|
||||
get_docker_secret() {
|
||||
local env_var="${1}"
|
||||
local env_var_file="${env_var}_FILE"
|
||||
@@ -40,11 +42,14 @@ get_docker_secret() {
|
||||
fi
|
||||
}
|
||||
|
||||
get_docker_secret PMA_USER
|
||||
get_docker_secret PMA_PASSWORD
|
||||
get_docker_secret MYSQL_ROOT_PASSWORD
|
||||
get_docker_secret MYSQL_PASSWORD
|
||||
get_docker_secret PMA_HOSTS
|
||||
get_docker_secret PMA_HOST
|
||||
get_docker_secret PMA_CONTROLHOST
|
||||
get_docker_secret PMA_CONTROLUSER
|
||||
get_docker_secret PMA_CONTROLPASS
|
||||
|
||||
exec "$@"
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
/**
|
||||
* Helper function to decode and save multiple SSL files from base64.
|
||||
*
|
||||
* @param string $base64FilesContents The base64 encoded string containing multiple files separated by commas.
|
||||
* If no commas are present, the entire string is treated as a single file.
|
||||
* @param string $prefix The prefix to use for the generated file names.
|
||||
* @param string $extension The file extension to use for the generated files.
|
||||
* @param string $storageFolder The folder where to store the generated files.
|
||||
*
|
||||
* @return string A comma-separated list of paths to the generated files.
|
||||
*/
|
||||
function decodeBase64AndSaveFiles(string $base64FilesContents, string $prefix, string $extension, string $storageFolder): string
|
||||
{
|
||||
// Ensure the output directory exists
|
||||
if (! is_dir($storageFolder)) {
|
||||
mkdir($storageFolder, 0755, true);
|
||||
}
|
||||
|
||||
// Split the base64 string into an array of files
|
||||
$base64FilesContents = explode(',', trim($base64FilesContents));
|
||||
$counter = 1;
|
||||
$outputFiles = [];
|
||||
|
||||
// Process each file
|
||||
foreach ($base64FilesContents as $base64FileContent) {
|
||||
$outputFile = $storageFolder . '/' . $prefix . '-' . $counter . '.' . $extension;
|
||||
|
||||
$fileContent = base64_decode($base64FileContent, true);
|
||||
if ($fileContent === false) {
|
||||
echo 'Failed to decode: ' . $base64FileContent;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Write the decoded file to the output directory
|
||||
if (file_put_contents($outputFile, $fileContent) === false) {
|
||||
echo 'Failed to write to ' . $outputFile;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Add the output file path to the list
|
||||
$outputFiles[] = $outputFile;
|
||||
$counter++;
|
||||
}
|
||||
|
||||
// Return a comma-separated list of the generated file paths
|
||||
return implode(',', $outputFiles);
|
||||
}
|
||||
+52
-28
@@ -1,11 +1,17 @@
|
||||
FROM php:7.4-fpm
|
||||
# DO NOT EDIT: created by update.sh from Dockerfile-debian.template
|
||||
FROM php:8.2-fpm
|
||||
|
||||
# Install dependencies
|
||||
RUN set -ex; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
libbz2-dev \
|
||||
libfreetype6-dev \
|
||||
@@ -23,27 +29,49 @@ RUN set -ex; \
|
||||
mysqli \
|
||||
opcache \
|
||||
zip \
|
||||
bcmath \
|
||||
; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
ldd "$(php -r 'echo ini_get("extension_dir");')"/*.so \
|
||||
| awk '/=>/ { print $3 }' \
|
||||
extdir="$(php -r 'echo ini_get("extension_dir");')"; \
|
||||
ldd "$extdir"/*.so \
|
||||
| awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); print so }' \
|
||||
| sort -u \
|
||||
| xargs -r dpkg-query -S \
|
||||
| cut -d: -f1 \
|
||||
| sort -u \
|
||||
| xargs -rt apt-mark manual; \
|
||||
\
|
||||
\
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*; \
|
||||
ldd "$extdir"/*.so | grep -qzv "=> not found" || (echo "Sanity check failed: missing libraries:"; ldd "$extdir"/*.so | grep " => not found"; exit 1); \
|
||||
ldd "$extdir"/*.so | grep -q "libzip.so.* => .*/libzip.so.*" || (echo "Sanity check failed: libzip.so is not referenced"; ldd "$extdir"/*.so; exit 1); \
|
||||
err="$(php --version 3>&1 1>&2 2>&3)"; \
|
||||
[ -z "$err" ] || (echo "Sanity check failed: php returned errors; $err"; exit 1;); \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# set recommended PHP.ini settings
|
||||
# see https://secure.php.net/manual/en/opcache.installation.php
|
||||
ENV PMA_SSL_DIR /etc/phpmyadmin/ssl
|
||||
ENV MAX_EXECUTION_TIME 600
|
||||
ENV MEMORY_LIMIT 512M
|
||||
ENV UPLOAD_LIMIT 2048K
|
||||
ENV TZ UTC
|
||||
ENV SESSION_SAVE_PATH /sessions
|
||||
RUN set -ex; \
|
||||
mkdir $SESSION_SAVE_PATH; \
|
||||
mkdir -p $PMA_SSL_DIR; \
|
||||
chmod 1777 $SESSION_SAVE_PATH; \
|
||||
chmod 755 $PMA_SSL_DIR; \
|
||||
chown www-data:www-data /etc/phpmyadmin; \
|
||||
chown www-data:www-data $PMA_SSL_DIR; \
|
||||
chown www-data:www-data $SESSION_SAVE_PATH; \
|
||||
\
|
||||
{ \
|
||||
echo 'opcache.memory_consumption=128'; \
|
||||
@@ -65,11 +93,15 @@ RUN set -ex; \
|
||||
echo 'memory_limit=${MEMORY_LIMIT}'; \
|
||||
echo 'post_max_size=${UPLOAD_LIMIT}'; \
|
||||
echo 'upload_max_filesize=${UPLOAD_LIMIT}'; \
|
||||
echo 'date.timezone=${TZ}'; \
|
||||
echo 'session.save_path=${SESSION_SAVE_PATH}'; \
|
||||
} > $PHP_INI_DIR/conf.d/phpmyadmin-misc.ini
|
||||
|
||||
USER www-data:www-data
|
||||
|
||||
# Calculate download URL
|
||||
ENV VERSION 5.1.0
|
||||
ENV SHA256 aa8ccf357f672012384df34e1c2bc70147476761c8458a0dad6233497e142c68
|
||||
ENV VERSION 5.2.2
|
||||
ENV SHA256 f881819a3b11e653b0212afaf0cc105db85c767715cb3f5852670f7fc36c9669
|
||||
ENV URL https://files.phpmyadmin.net/phpMyAdmin/${VERSION}/phpMyAdmin-${VERSION}-all-languages.tar.xz
|
||||
|
||||
LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
@@ -84,44 +116,36 @@ LABEL org.opencontainers.image.title="Official phpMyAdmin Docker image" \
|
||||
|
||||
# Download tarball, verify it using gpg and extract
|
||||
RUN set -ex; \
|
||||
\
|
||||
savedAptMark="$(apt-mark showmanual)"; \
|
||||
\
|
||||
apt-get update; \
|
||||
apt-get install -y --no-install-recommends \
|
||||
gnupg \
|
||||
dirmngr \
|
||||
; \
|
||||
\
|
||||
export GNUPGHOME="$(mktemp -d)"; \
|
||||
export GPGKEY="3D06A59ECE730EB71B511C17CE752F178259BD92"; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz $URL; \
|
||||
curl -fsSL -o phpMyAdmin.tar.xz.asc $URL.asc; \
|
||||
echo "$SHA256 *phpMyAdmin.tar.xz" | sha256sum -c -; \
|
||||
gpg --batch --keyserver ha.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver ipv4.pool.sks-keyservers.net --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.gnupg.net --recv-keys "$GPGKEY" \
|
||||
gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver pgp.mit.edu --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY"; \
|
||||
|| gpg --batch --keyserver keyserver.pgp.com --recv-keys "$GPGKEY" \
|
||||
|| gpg --batch --keyserver keys.openpgp.org --recv-keys "$GPGKEY"; \
|
||||
gpg --batch --verify phpMyAdmin.tar.xz.asc phpMyAdmin.tar.xz; \
|
||||
tar -xf phpMyAdmin.tar.xz -C /var/www/html --strip-components=1; \
|
||||
mkdir -p /var/www/html/tmp; \
|
||||
chown www-data:www-data /var/www/html/tmp; \
|
||||
gpgconf --kill all; \
|
||||
rm -r "$GNUPGHOME" phpMyAdmin.tar.xz phpMyAdmin.tar.xz.asc; \
|
||||
rm -rf /var/www/html/setup/ /var/www/html/examples/ /var/www/html/test/ /var/www/html/po/ /var/www/html/composer.json /var/www/html/RELEASE-DATE-$VERSION; \
|
||||
sed -i "s@define('CONFIG_DIR'.*@define('CONFIG_DIR', '/etc/phpmyadmin/');@" /var/www/html/libraries/vendor_config.php; \
|
||||
\
|
||||
apt-mark auto '.*' > /dev/null; \
|
||||
apt-mark manual $savedAptMark; \
|
||||
apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
rm -r -v /var/www/html/setup/ /var/www/html/examples/ /var/www/html/js/src/ /var/www/html/babel.config.json /var/www/html/doc/html/_sources/ /var/www/html/RELEASE-DATE-$VERSION /var/www/html/CONTRIBUTING.md; \
|
||||
grep -q -F "'configFile' => ROOT_PATH . 'config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
sed -i "s@'configFile' => .*@'configFile' => '/etc/phpmyadmin/config.inc.php',@" /var/www/html/libraries/vendor_config.php; \
|
||||
grep -q -F "'configFile' => '/etc/phpmyadmin/config.inc.php'," /var/www/html/libraries/vendor_config.php; \
|
||||
php -l /var/www/html/libraries/vendor_config.php; \
|
||||
find /var/www/html -type d -exec chmod 555 {} \;; \
|
||||
find /var/www/html -type f -exec chmod 444 {} \;; \
|
||||
chmod 1777 /var/www/html/tmp;
|
||||
|
||||
# Copy configuration
|
||||
COPY config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data config.inc.php /etc/phpmyadmin/config.inc.php
|
||||
COPY --chown=www-data:www-data helpers.php /etc/phpmyadmin/helpers.php
|
||||
|
||||
# Copy main script
|
||||
COPY docker-entrypoint.sh /docker-entrypoint.sh
|
||||
|
||||
USER root
|
||||
ENTRYPOINT [ "/docker-entrypoint.sh" ]
|
||||
CMD ["php-fpm"]
|
||||
|
||||
+115
-21
@@ -1,9 +1,10 @@
|
||||
<?php
|
||||
|
||||
require('/etc/phpmyadmin/config.secret.inc.php');
|
||||
require_once '/etc/phpmyadmin/config.secret.inc.php';
|
||||
require_once '/etc/phpmyadmin/helpers.php';
|
||||
|
||||
/* Ensure we got the environment */
|
||||
$vars = array(
|
||||
$vars = [
|
||||
'PMA_ARBITRARY',
|
||||
'PMA_HOST',
|
||||
'PMA_HOSTS',
|
||||
@@ -24,20 +25,45 @@ $vars = array(
|
||||
'PMA_QUERYHISTORYDB',
|
||||
'PMA_QUERYHISTORYMAX',
|
||||
'MAX_EXECUTION_TIME',
|
||||
'MEMORY_LIMIT'
|
||||
);
|
||||
'MEMORY_LIMIT',
|
||||
'PMA_UPLOADDIR',
|
||||
'PMA_SAVEDIR',
|
||||
'PMA_SSL',
|
||||
'PMA_SSLS',
|
||||
'PMA_SSL_DIR',
|
||||
'PMA_SSL_VERIFY',
|
||||
'PMA_SSL_VERIFIES',
|
||||
'PMA_SSL_CA',
|
||||
'PMA_SSL_CAS',
|
||||
'PMA_SSL_CA_BASE64',
|
||||
'PMA_SSL_CAS_BASE64',
|
||||
'PMA_SSL_KEY',
|
||||
'PMA_SSL_KEYS',
|
||||
'PMA_SSL_KEY_BASE64',
|
||||
'PMA_SSL_KEYS_BASE64',
|
||||
'PMA_SSL_CERT',
|
||||
'PMA_SSL_CERTS',
|
||||
'PMA_SSL_CERT_BASE64',
|
||||
'PMA_SSL_CERTS_BASE64',
|
||||
];
|
||||
|
||||
foreach ($vars as $var) {
|
||||
$env = getenv($var);
|
||||
if (!isset($_ENV[$var]) && $env !== false) {
|
||||
$_ENV[$var] = $env;
|
||||
}
|
||||
}
|
||||
|
||||
if (! defined('PMA_SSL_DIR')) {
|
||||
define('PMA_SSL_DIR', $_ENV['PMA_SSL_DIR'] ?? '/etc/phpmyadmin/ssl');
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYDB'])) {
|
||||
$cfg['QueryHistoryDB'] = boolval($_ENV['PMA_QUERYHISTORYDB']);
|
||||
$cfg['QueryHistoryDB'] = (bool) $_ENV['PMA_QUERYHISTORYDB'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_QUERYHISTORYMAX'])) {
|
||||
$cfg['QueryHistoryMax'] = intval($_ENV['PMA_QUERYHISTORYMAX']);
|
||||
$cfg['QueryHistoryMax'] = (int) $_ENV['PMA_QUERYHISTORYMAX'];
|
||||
}
|
||||
|
||||
/* Arbitrary server connection */
|
||||
@@ -50,29 +76,84 @@ if (isset($_ENV['PMA_ABSOLUTE_URI'])) {
|
||||
$cfg['PmaAbsoluteUri'] = trim($_ENV['PMA_ABSOLUTE_URI']);
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SSL_CA_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CA'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CA_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL key from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEY_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEY'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEY_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save the SSL certificate from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERT_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERT'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERT_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL CA certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CAS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CAS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CAS_BASE64'], 'phpmyadmin-ssl-CA', 'pem', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL keys from base64 */
|
||||
if (isset($_ENV['PMA_SSL_KEYS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_KEYS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_KEYS_BASE64'], 'phpmyadmin-ssl-CERT', 'cert', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Decode and save multiple SSL certificates from base64 */
|
||||
if (isset($_ENV['PMA_SSL_CERTS_BASE64'])) {
|
||||
$_ENV['PMA_SSL_CERTS'] = decodeBase64AndSaveFiles($_ENV['PMA_SSL_CERTS_BASE64'], 'phpmyadmin-ssl-KEY', 'key', PMA_SSL_DIR);
|
||||
}
|
||||
|
||||
/* Figure out hosts */
|
||||
|
||||
/* Fallback to default linked */
|
||||
$hosts = array('db');
|
||||
$hosts = ['db'];
|
||||
|
||||
/* Set by environment */
|
||||
if (!empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = array($_ENV['PMA_HOST']);
|
||||
$verbose = array($_ENV['PMA_VERBOSE']);
|
||||
$ports = array($_ENV['PMA_PORT']);
|
||||
} elseif (!empty($_ENV['PMA_HOSTS'])) {
|
||||
if (! empty($_ENV['PMA_HOST'])) {
|
||||
$hosts = [$_ENV['PMA_HOST']];
|
||||
$verbose = [$_ENV['PMA_VERBOSE']];
|
||||
$ports = [$_ENV['PMA_PORT']];
|
||||
$ssls = [$_ENV['PMA_SSL']];
|
||||
$ssl_verifies = [$_ENV['PMA_SSL_VERIFY']];
|
||||
$ssl_cas = [$_ENV['PMA_SSL_CA']];
|
||||
$ssl_keys = [$_ENV['PMA_SSL_KEY']];
|
||||
$ssl_certs = [$_ENV['PMA_SSL_CERT']];
|
||||
} elseif (! empty($_ENV['PMA_HOSTS'])) {
|
||||
$hosts = array_map('trim', explode(',', $_ENV['PMA_HOSTS']));
|
||||
$verbose = array_map('trim', explode(',', $_ENV['PMA_VERBOSES']));
|
||||
$ports = array_map('trim', explode(',', $_ENV['PMA_PORTS']));
|
||||
$ssls = array_map('trim', explode(',', $_ENV['PMA_SSLS']));
|
||||
$ssl_verifies = array_map('trim', explode(',', $_ENV['PMA_SSL_VERIFIES']));
|
||||
$ssl_cas = array_map('trim', explode(',', $_ENV['PMA_SSL_CAS']));
|
||||
$ssl_keys = array_map('trim', explode(',', $_ENV['PMA_SSL_KEYS']));
|
||||
$ssl_certs = array_map('trim', explode(',', $_ENV['PMA_SSL_CERTS']));
|
||||
}
|
||||
if (!empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = array($_ENV['PMA_SOCKET']);
|
||||
} elseif (!empty($_ENV['PMA_SOCKETS'])) {
|
||||
|
||||
if (! empty($_ENV['PMA_SOCKET'])) {
|
||||
$sockets = [$_ENV['PMA_SOCKET']];
|
||||
} elseif (! empty($_ENV['PMA_SOCKETS'])) {
|
||||
$sockets = explode(',', $_ENV['PMA_SOCKETS']);
|
||||
}
|
||||
|
||||
/* Server settings */
|
||||
for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
if (isset($ssls[$i - 1]) && $ssls[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl'] = $ssls[$i - 1];
|
||||
}
|
||||
if (isset($ssl_verifies[$i - 1]) && $ssl_verifies[$i - 1] === '1') {
|
||||
$cfg['Servers'][$i]['ssl_verify'] = $ssl_verifies[$i - 1];
|
||||
}
|
||||
if (isset($ssl_cas[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_ca'] = $ssl_cas[$i - 1];
|
||||
}
|
||||
if (isset($ssl_keys[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_key'] = $ssl_keys[$i - 1];
|
||||
}
|
||||
if (isset($ssl_certs[$i - 1])) {
|
||||
$cfg['Servers'][$i]['ssl_cert'] = $ssl_certs[$i - 1];
|
||||
}
|
||||
$cfg['Servers'][$i]['host'] = $hosts[$i - 1];
|
||||
if (isset($verbose[$i - 1])) {
|
||||
$cfg['Servers'][$i]['verbose'] = $verbose[$i - 1];
|
||||
@@ -124,9 +205,10 @@ for ($i = 1; isset($hosts[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['compress'] = false;
|
||||
$cfg['Servers'][$i]['AllowNoPassword'] = true;
|
||||
}
|
||||
for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$cfg['Servers'][$i]['socket'] = $sockets[$i - 1];
|
||||
$cfg['Servers'][$i]['host'] = 'localhost';
|
||||
// Avoid overwriting the last server id $i, use another variable name
|
||||
for ($socketHostId = 1; isset($sockets[$socketHostId - 1]); $socketHostId++) {
|
||||
$cfg['Servers'][$socketHostId]['socket'] = $sockets[$socketHostId - 1];
|
||||
$cfg['Servers'][$socketHostId]['host'] = 'localhost';
|
||||
}
|
||||
/*
|
||||
* Revert back to last configured server to make
|
||||
@@ -135,8 +217,13 @@ for ($i = 1; isset($sockets[$i - 1]); $i++) {
|
||||
$i--;
|
||||
|
||||
/* Uploads setup */
|
||||
$cfg['UploadDir'] = '';
|
||||
$cfg['SaveDir'] = '';
|
||||
if (isset($_ENV['PMA_UPLOADDIR'])) {
|
||||
$cfg['UploadDir'] = $_ENV['PMA_UPLOADDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['PMA_SAVEDIR'])) {
|
||||
$cfg['SaveDir'] = $_ENV['PMA_SAVEDIR'];
|
||||
}
|
||||
|
||||
if (isset($_ENV['MAX_EXECUTION_TIME'])) {
|
||||
$cfg['ExecTimeLimit'] = $_ENV['MAX_EXECUTION_TIME'];
|
||||
@@ -148,5 +235,12 @@ if (isset($_ENV['MEMORY_LIMIT'])) {
|
||||
|
||||
/* Include User Defined Settings Hook */
|
||||
if (file_exists('/etc/phpmyadmin/config.user.inc.php')) {
|
||||
include('/etc/phpmyadmin/config.user.inc.php');
|
||||
include '/etc/phpmyadmin/config.user.inc.php';
|
||||
}
|
||||
|
||||
/* Support additional configurations */
|
||||
if (is_dir('/etc/phpmyadmin/conf.d/')) {
|
||||
foreach (glob('/etc/phpmyadmin/conf.d/*.php') as $filename) {
|
||||
include $filename;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -7,6 +7,7 @@ if [[ "$1" == apache2* ]] || [ "$1" == php-fpm ]; then
|
||||
\$cfg['blowfish_secret'] = '$(tr -dc 'a-zA-Z0-9~!@#$%^&*_()+}{?></";.,[]=-' < /dev/urandom | fold -w 32 | head -n 1)';
|
||||
EOT
|
||||
fi
|
||||
chgrp www-data /etc/phpmyadmin/config.secret.inc.php
|
||||
|
||||
if [ ! -f /etc/phpmyadmin/config.user.inc.php ]; then
|
||||
touch /etc/phpmyadmin/config.user.inc.php
|
||||
@@ -28,6 +29,7 @@ if [ ! -z "${PMA_USER_CONFIG_BASE64}" ]; then
|
||||
echo "${PMA_USER_CONFIG_BASE64}" | base64 -d > /etc/phpmyadmin/config.user.inc.php
|
||||
fi
|
||||
|
||||
|
||||
get_docker_secret() {
|
||||
local env_var="${1}"
|
||||
local env_var_file="${env_var}_FILE"
|
||||
@@ -40,11 +42,14 @@ get_docker_secret() {
|
||||
fi
|
||||
}
|
||||
|
||||
get_docker_secret PMA_USER
|
||||
get_docker_secret PMA_PASSWORD
|
||||
get_docker_secret MYSQL_ROOT_PASSWORD
|
||||
get_docker_secret MYSQL_PASSWORD
|
||||
get_docker_secret PMA_HOSTS
|
||||
get_docker_secret PMA_HOST
|
||||
get_docker_secret PMA_CONTROLHOST
|
||||
get_docker_secret PMA_CONTROLUSER
|
||||
get_docker_secret PMA_CONTROLPASS
|
||||
|
||||
exec "$@"
|
||||
|
||||
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
/**
|
||||
* Helper function to decode and save multiple SSL files from base64.
|
||||
*
|
||||
* @param string $base64FilesContents The base64 encoded string containing multiple files separated by commas.
|
||||
* If no commas are present, the entire string is treated as a single file.
|
||||
* @param string $prefix The prefix to use for the generated file names.
|
||||
* @param string $extension The file extension to use for the generated files.
|
||||
* @param string $storageFolder The folder where to store the generated files.
|
||||
*
|
||||
* @return string A comma-separated list of paths to the generated files.
|
||||
*/
|
||||
function decodeBase64AndSaveFiles(string $base64FilesContents, string $prefix, string $extension, string $storageFolder): string
|
||||
{
|
||||
// Ensure the output directory exists
|
||||
if (! is_dir($storageFolder)) {
|
||||
mkdir($storageFolder, 0755, true);
|
||||
}
|
||||
|
||||
// Split the base64 string into an array of files
|
||||
$base64FilesContents = explode(',', trim($base64FilesContents));
|
||||
$counter = 1;
|
||||
$outputFiles = [];
|
||||
|
||||
// Process each file
|
||||
foreach ($base64FilesContents as $base64FileContent) {
|
||||
$outputFile = $storageFolder . '/' . $prefix . '-' . $counter . '.' . $extension;
|
||||
|
||||
$fileContent = base64_decode($base64FileContent, true);
|
||||
if ($fileContent === false) {
|
||||
echo 'Failed to decode: ' . $base64FileContent;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Write the decoded file to the output directory
|
||||
if (file_put_contents($outputFile, $fileContent) === false) {
|
||||
echo 'Failed to write to ' . $outputFile;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Add the output file path to the list
|
||||
$outputFiles[] = $outputFile;
|
||||
$counter++;
|
||||
}
|
||||
|
||||
// Return a comma-separated list of the generated file paths
|
||||
return implode(',', $outputFiles);
|
||||
}
|
||||
@@ -1,25 +1,26 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
#!/usr/bin/env bash
|
||||
set -Eeuo pipefail
|
||||
|
||||
self="$(basename "$BASH_SOURCE")"
|
||||
cd "$(dirname "$(readlink -f "$BASH_SOURCE")")"
|
||||
|
||||
# Get the most recent commit which modified any of "$@".
|
||||
# get the most recent commit which modified any of "$@"
|
||||
fileCommit() {
|
||||
git log -1 --format='format:%H' HEAD -- "$@"
|
||||
}
|
||||
|
||||
# Get the most recent commit which modified "$1/Dockerfile" or any file that
|
||||
# the Dockerfile copies into the rootfs (with COPY).
|
||||
dockerfileCommit() {
|
||||
# get the most recent commit which modified "$1/Dockerfile" or any file COPY'd from "$1/Dockerfile"
|
||||
dirCommit() {
|
||||
local dir="$1"; shift
|
||||
(
|
||||
cd "$dir";
|
||||
fileCommit Dockerfile \
|
||||
cd "$dir"
|
||||
fileCommit \
|
||||
Dockerfile \
|
||||
$(git show HEAD:./Dockerfile | awk '
|
||||
toupper($1) == "COPY" {
|
||||
for (i = 2; i < NF; i++)
|
||||
print $i;
|
||||
for (i = 2; i < NF; i++) {
|
||||
print $i
|
||||
}
|
||||
}
|
||||
')
|
||||
)
|
||||
@@ -29,9 +30,9 @@ getArches() {
|
||||
local repo="$1"; shift
|
||||
local officialImagesUrl='https://github.com/docker-library/official-images/raw/master/library/'
|
||||
|
||||
eval "declare -g -A parentRepoToArches=( $(
|
||||
eval "declare -A -g parentRepoToArches=( $(
|
||||
find -name 'Dockerfile' -exec awk '
|
||||
toupper($1) == "FROM" && $2 !~ /^('"$repo"'|scratch|microsoft\/[^:]+)(:|$)/ {
|
||||
toupper($1) == "FROM" && $2 !~ /^('"$repo"'|scratch|.*\/.*)(:|$)/ {
|
||||
print "'"$officialImagesUrl"'" $2
|
||||
}
|
||||
' '{}' + \
|
||||
@@ -39,6 +40,7 @@ getArches() {
|
||||
| xargs bashbrew cat --format '[{{ .RepoName }}:{{ .TagName }}]="{{ join " " .TagEntry.Architectures }}"'
|
||||
) )"
|
||||
}
|
||||
getArches 'phpmyadmin'
|
||||
|
||||
if ! command -v bashbrew --version &> /dev/null
|
||||
then
|
||||
@@ -47,9 +49,6 @@ then
|
||||
exit 1
|
||||
fi
|
||||
|
||||
getArches 'phpmyadmin'
|
||||
|
||||
# Header.
|
||||
cat <<-EOH
|
||||
# This file is generated via https://github.com/phpmyadmin/docker/blob/$(fileCommit "$self")/$self
|
||||
Maintainers: Isaac Bennetch <bennetch@gmail.com> (@ibennetch),
|
||||
@@ -64,10 +63,10 @@ join() {
|
||||
echo "${out#$sep}"
|
||||
}
|
||||
|
||||
latest="$(curl -fsSL 'https://www.phpmyadmin.net/home_page/version.json' | jq -r '.version')"
|
||||
latest="$(curl -fsSL 'https://www.phpmyadmin.net/home_page/version.json' | jq -r '.version' | grep -E '^[0-9]{1,}.[0-9]{1,}.[0-9]{1,}$')"
|
||||
|
||||
for variant in apache fpm fpm-alpine; do
|
||||
commit="$(dockerfileCommit "$variant")"
|
||||
commit="$(dirCommit "$variant")"
|
||||
fullversion="$(git show "$commit":"$variant/Dockerfile" | awk '$1 == "ENV" && $2 == "VERSION" { print $3; exit }')"
|
||||
|
||||
versionAliases=( "$fullversion" "${fullversion%.*}" "${fullversion%.*.*}" )
|
||||
|
||||
+51
@@ -0,0 +1,51 @@
|
||||
<?php
|
||||
|
||||
declare(strict_types=1);
|
||||
|
||||
/**
|
||||
* Helper function to decode and save multiple SSL files from base64.
|
||||
*
|
||||
* @param string $base64FilesContents The base64 encoded string containing multiple files separated by commas.
|
||||
* If no commas are present, the entire string is treated as a single file.
|
||||
* @param string $prefix The prefix to use for the generated file names.
|
||||
* @param string $extension The file extension to use for the generated files.
|
||||
* @param string $storageFolder The folder where to store the generated files.
|
||||
*
|
||||
* @return string A comma-separated list of paths to the generated files.
|
||||
*/
|
||||
function decodeBase64AndSaveFiles(string $base64FilesContents, string $prefix, string $extension, string $storageFolder): string
|
||||
{
|
||||
// Ensure the output directory exists
|
||||
if (! is_dir($storageFolder)) {
|
||||
mkdir($storageFolder, 0755, true);
|
||||
}
|
||||
|
||||
// Split the base64 string into an array of files
|
||||
$base64FilesContents = explode(',', trim($base64FilesContents));
|
||||
$counter = 1;
|
||||
$outputFiles = [];
|
||||
|
||||
// Process each file
|
||||
foreach ($base64FilesContents as $base64FileContent) {
|
||||
$outputFile = $storageFolder . '/' . $prefix . '-' . $counter . '.' . $extension;
|
||||
|
||||
$fileContent = base64_decode($base64FileContent, true);
|
||||
if ($fileContent === false) {
|
||||
echo 'Failed to decode: ' . $base64FileContent;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Write the decoded file to the output directory
|
||||
if (file_put_contents($outputFile, $fileContent) === false) {
|
||||
echo 'Failed to write to ' . $outputFile;
|
||||
exit(1);
|
||||
}
|
||||
|
||||
// Add the output file path to the list
|
||||
$outputFiles[] = $outputFile;
|
||||
$counter++;
|
||||
}
|
||||
|
||||
// Return a comma-separated list of the generated file paths
|
||||
return implode(',', $outputFiles);
|
||||
}
|
||||
+3
-3
@@ -1,9 +1,9 @@
|
||||
# Testing image for phpMyAdmin
|
||||
|
||||
FROM alpine:3.12
|
||||
FROM alpine:3.21
|
||||
|
||||
# Install test dependencies
|
||||
RUN set -ex; \
|
||||
\
|
||||
apk add --no-cache --update mariadb-client bash \
|
||||
py3-html5lib py3-pytest py3-mechanize
|
||||
apk add --no-cache --update mariadb-client mariadb-connector-c bash \
|
||||
py3-html5lib py3-pytest py3-mechanize curl
|
||||
|
||||
@@ -4,6 +4,7 @@ def pytest_addoption(parser):
|
||||
parser.addoption("--url")
|
||||
parser.addoption("--username")
|
||||
parser.addoption("--password")
|
||||
parser.addoption("--root-password")
|
||||
parser.addoption("--server")
|
||||
parser.addoption("--sqlfile")
|
||||
|
||||
@@ -19,6 +20,10 @@ def username(request):
|
||||
def password(request):
|
||||
return request.config.getoption("--password")
|
||||
|
||||
@pytest.fixture
|
||||
def root_password(request):
|
||||
return request.config.getoption("--root-password")
|
||||
|
||||
@pytest.fixture
|
||||
def server(request):
|
||||
return request.config.getoption("--server")
|
||||
|
||||
@@ -0,0 +1,69 @@
|
||||
version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_HOST: db_server
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/conf.d/config.test.php:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
volumes:
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
+12
-12
@@ -2,34 +2,32 @@ version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.3}
|
||||
container_name: phpmyadmin_testing_db
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MYSQL_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mysqladmin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 5s
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
volumes:
|
||||
- ./testing/testing.cnf:/etc/mysql/conf.d/testing.cnf:ro
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: apache
|
||||
container_name: phpmyadmin_testing_apache
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_ARBITRARY: 1
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
volumes:
|
||||
- ./testing/config.user.inc.php:/etc/phpmyadmin/config.user.inc.php
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
@@ -38,6 +36,8 @@ services:
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
@@ -49,7 +49,7 @@ services:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: testing
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
@@ -60,7 +60,7 @@ services:
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
volumes:
|
||||
- ./:/tests:ro
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
@@ -0,0 +1,70 @@
|
||||
version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_HOST: db_server
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
APACHE_PORT: 8090
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost:8090/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 8090
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
volumes:
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
@@ -0,0 +1,80 @@
|
||||
version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_HOST: db_server
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
PMA_UPLOADDIR: /etc/phpmyadmin/imports
|
||||
PMA_SAVEDIR: /etc/phpmyadmin/exports
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
- phpmyadmin-data:/etc/phpmyadmin/imports:ro
|
||||
- phpmyadmin-data:/etc/phpmyadmin/exports
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
PMA_UPLOADDIR: /etc/phpmyadmin/imports
|
||||
PMA_SAVEDIR: /etc/phpmyadmin/exports
|
||||
volumes:
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
- phpmyadmin-data:/etc/phpmyadmin/imports
|
||||
- phpmyadmin-data:/etc/phpmyadmin/exports
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
|
||||
volumes:
|
||||
phpmyadmin-data:
|
||||
+12
-12
@@ -2,34 +2,32 @@ version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.3}
|
||||
container_name: phpmyadmin_testing_db
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MYSQL_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mysqladmin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 5s
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
volumes:
|
||||
- ./testing/testing.cnf:/etc/mysql/conf.d/testing.cnf:ro
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: apache
|
||||
container_name: phpmyadmin_testing_apache
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_HOST: db_server
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
volumes:
|
||||
- ./testing/config.user.inc.php:/etc/phpmyadmin/config.user.inc.php
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
@@ -38,6 +36,8 @@ services:
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
@@ -49,7 +49,7 @@ services:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: testing
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
@@ -60,7 +60,7 @@ services:
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
volumes:
|
||||
- ./:/tests:ro
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
@@ -0,0 +1,75 @@
|
||||
version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.11}
|
||||
environment:
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
volumes:
|
||||
- db-socket:/run/mysqld/
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_SOCKET: /run/mysqld/mysqld.sock
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
- db-socket:/run/mysqld/
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
volumes:
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
|
||||
volumes:
|
||||
db-socket:
|
||||
@@ -0,0 +1,105 @@
|
||||
version: "3.1"
|
||||
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:11}
|
||||
command:
|
||||
- "--plugin_load_add=server_audit"
|
||||
- "--server_audit=FORCE_PLUS_PERMANENT"
|
||||
- "--server_audit_events=connect"
|
||||
- "--server_audit_logging"
|
||||
#- "--server_audit_file_path=/var/log/mariadb-audit/audit.log"
|
||||
- "--ssl-ca=/etc/phpmyadmin/ssl/ca-cert.pem"
|
||||
- "--ssl-cert=/etc/phpmyadmin/ssl/server-cert.pem"
|
||||
- "--ssl-key=/etc/phpmyadmin/ssl/server-key.pem"
|
||||
- "--require-secure-transport=ON"
|
||||
- "--server-audit-logging=ON"
|
||||
environment:
|
||||
MARIADB_USER: secure-user
|
||||
MARIADB_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_ROOT_PASSWORD:-random-pass}"
|
||||
# The database name used in the import test
|
||||
MARIADB_DATABASE: World
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-prandom-pass"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- mariadb.phpmyadmin.local
|
||||
tmpfs:
|
||||
- /var/lib/mysql:rw,noexec,nosuid,size=300m
|
||||
volumes:
|
||||
#- ../secure-user.sql:/docker-entrypoint-initdb.d/secure-user.sql:ro
|
||||
- ../ca-cert.pem:/etc/phpmyadmin/ssl/ca-cert.pem:ro
|
||||
- ../ca-key.pem:/etc/phpmyadmin/ssl/ca-key.pem:ro
|
||||
- ../server-cert.pem:/etc/phpmyadmin/ssl/server-cert.pem:ro
|
||||
- ../server-key.pem:/etc/phpmyadmin/ssl/server-key.pem:ro
|
||||
#- ../mariadb-audit:/var/log/mariadb-audit
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
environment:
|
||||
PMA_HOST: mariadb.phpmyadmin.local
|
||||
PMA_SSL: 1
|
||||
PMA_SSL_VERIFY: 1
|
||||
PMA_SSL_CA: /etc/phpmyadmin/ssl/ca-cert.pem
|
||||
PMA_SSL_CERT: /etc/phpmyadmin/ssl/client-cert.pem
|
||||
PMA_SSL_KEY: /etc/phpmyadmin/ssl/client-key.pem
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
HIDE_PHP_VERSION: 1
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
- ../ca-cert.pem:/etc/phpmyadmin/ssl/ca-cert.pem:ro
|
||||
- ../client-cert.pem:/etc/phpmyadmin/ssl/client-cert.pem:ro
|
||||
- ../client-key.pem:/etc/phpmyadmin/ssl/client-key.pem:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_USER: secure-user
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
TESTSUITE_ROOT_PASSWORD: "${TESTSUITE_ROOT_PASSWORD:-random-pass}"
|
||||
PMA_HOST: mariadb.phpmyadmin.local
|
||||
PMA_PORT: 3306
|
||||
IS_USING_SSL: true
|
||||
volumes:
|
||||
- ../ca-cert.pem:/etc/phpmyadmin/ssl/ca-cert.pem:ro
|
||||
- ../server-cert.pem:/etc/phpmyadmin/ssl/server-cert.pem:ro
|
||||
- ../client-cert.pem:/etc/phpmyadmin/ssl/client-cert.pem:ro
|
||||
- ../client-key.pem:/etc/phpmyadmin/ssl/client-key.pem:ro
|
||||
- ../../:/tests:ro
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
@@ -0,0 +1,76 @@
|
||||
services:
|
||||
db_server:
|
||||
image: ${DB:-mariadb:10.11}
|
||||
# mysql:mysql in MariaDB for Docker (https://stackoverflow.com/a/55241769/5155484)
|
||||
user: 999:999
|
||||
environment:
|
||||
MARIADB_ROOT_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
healthcheck:
|
||||
test: ["CMD", "mariadb-admin", "ping", "-uroot", "-p${TESTSUITE_PASSWORD:-my-secret-pw}"]
|
||||
start_period: 10s
|
||||
interval: 5s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_db
|
||||
volumes:
|
||||
- mariadb-data:/var/lib/mysql
|
||||
|
||||
phpmyadmin:
|
||||
build:
|
||||
context: ../../apache
|
||||
# www-data:www-data in Debian (https://stackoverflow.com/a/69290889/5155484)
|
||||
user: 33:33
|
||||
environment:
|
||||
PMA_HOST: db_server
|
||||
UPLOAD_LIMIT: 123M
|
||||
MAX_EXECUTION_TIME: 125
|
||||
volumes:
|
||||
- ../config.user.inc.php:/etc/phpmyadmin/config.user.inc.php:ro
|
||||
healthcheck:
|
||||
test: ["CMD", "curl", "-Ss", "http://localhost/robots.txt"]
|
||||
start_period: 5s
|
||||
interval: 3s
|
||||
timeout: 60s
|
||||
retries: 10
|
||||
networks:
|
||||
testing:
|
||||
aliases:
|
||||
- phpmyadmin_testing_apache
|
||||
depends_on:
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
|
||||
sut:
|
||||
# nobody:nobody
|
||||
user: 65534:65534
|
||||
depends_on:
|
||||
phpmyadmin:
|
||||
condition: service_healthy
|
||||
db_server:
|
||||
condition: service_healthy
|
||||
build:
|
||||
context: ../
|
||||
command: "/tests/testing/test-docker.sh"
|
||||
networks:
|
||||
testing:
|
||||
environment:
|
||||
TESTSUITE_HOSTNAME: phpmyadmin_testing_apache
|
||||
TESTSUITE_PORT: 80
|
||||
TESTSUITE_PASSWORD: "${TESTSUITE_PASSWORD:-my-secret-pw}"
|
||||
PMA_HOST: phpmyadmin_testing_db
|
||||
PMA_PORT: 3306
|
||||
SKIP_EXPOSE_PHP_TEST: true
|
||||
volumes:
|
||||
- ../../:/tests:ro
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
working_dir: /tests
|
||||
|
||||
networks:
|
||||
testing:
|
||||
driver: bridge
|
||||
|
||||
volumes:
|
||||
mariadb-data:
|
||||
Executable
+37
@@ -0,0 +1,37 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -eu
|
||||
|
||||
# Source: https://github.com/chio-nzgft/docker-MariaDB-with-SSL
|
||||
# See: https://dev.mysql.com/doc/refman/5.7/en/creating-ssl-files-using-openssl.html
|
||||
|
||||
|
||||
ROOT_DIR="$(realpath $(dirname $0))"
|
||||
echo "Using root dir: $ROOT_DIR"
|
||||
|
||||
cd "$ROOT_DIR"
|
||||
|
||||
rm -f *.pem
|
||||
|
||||
SUBJECT_CA="/C=US/O=phpMyAdmin testing/OU=Docker/CN=ssl-ca.phpmyadmin.local/emailAddress=ssl-ca@example.org"
|
||||
SUBJECT_CLIENT="/C=US/O=phpMyAdmin testing/OU=Docker/CN=client.phpmyadmin.local/emailAddress=secure-user@example.org"
|
||||
SUBJECT_SERVER="/C=US/O=phpMyAdmin testing/OU=Docker/CN=mariadb.phpmyadmin.local"
|
||||
|
||||
echo "CA key"
|
||||
|
||||
openssl genrsa 2048 > ca-key.pem
|
||||
openssl req -new -x509 -nodes -days 3600 -subj "${SUBJECT_CA}" -key ca-key.pem -out ca-cert.pem
|
||||
echo "server key"
|
||||
|
||||
openssl req -subj "${SUBJECT_SERVER}" -newkey rsa:2048 -days 3600 -nodes -keyout server-key.pem -out server-req.pem
|
||||
openssl rsa -in server-key.pem -out server-key.pem
|
||||
openssl x509 -req -in server-req.pem -days 3600 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out server-cert.pem
|
||||
echo "client key"
|
||||
|
||||
openssl req -subj "${SUBJECT_CLIENT}" -newkey rsa:2048 -days 3600 -nodes -keyout client-key.pem -out client-req.pem
|
||||
openssl rsa -in client-key.pem -out client-key.pem
|
||||
openssl x509 -req -in client-req.pem -days 3600 -CA ca-cert.pem -CAkey ca-key.pem -set_serial 01 -out client-cert.pem
|
||||
echo "check key ok"
|
||||
|
||||
openssl verify -CAfile ca-cert.pem server-cert.pem client-cert.pem
|
||||
chmod 666 *.pem
|
||||
+118
-13
@@ -1,4 +1,4 @@
|
||||
#!/usr/bin/env python2
|
||||
#!/usr/bin/env python3
|
||||
import argparse
|
||||
import os
|
||||
import subprocess
|
||||
@@ -31,15 +31,18 @@ def do_login(br, url, username, password, server):
|
||||
response = br.submit()
|
||||
return response
|
||||
|
||||
def test_phpmyadmin(url, username, password, server, sqlfile):
|
||||
def get_world_sql_path():
|
||||
if os.path.exists('/world.sql'):
|
||||
return '/world.sql'
|
||||
elif os.path.exists('./world.sql'):
|
||||
return './world.sql'
|
||||
else:
|
||||
path = os.path.dirname(os.path.realpath(__file__))
|
||||
return path + '/world.sql'
|
||||
|
||||
def test_import(url, username, password, server, sqlfile):
|
||||
if sqlfile is None:
|
||||
if os.path.exists('/world.sql'):
|
||||
sqlfile = '/world.sql'
|
||||
elif os.path.exists('./world.sql'):
|
||||
sqlfile = './world.sql'
|
||||
else:
|
||||
path = os.path.dirname(os.path.realpath(__file__))
|
||||
sqlfile = path + '/world.sql'
|
||||
sqlfile = get_world_sql_path()
|
||||
|
||||
br = create_browser()
|
||||
|
||||
@@ -55,7 +58,9 @@ def test_phpmyadmin(url, username, password, server, sqlfile):
|
||||
br.select_form('import')
|
||||
br.form.add_file(open(sqlfile), 'text/plain', sqlfile)
|
||||
response = br.submit()
|
||||
assert(b'5326 queries executed' in response.read())
|
||||
response = response.read()
|
||||
|
||||
assert(b'5326 queries executed' in response)
|
||||
|
||||
|
||||
def docker_secret(env_name):
|
||||
@@ -78,17 +83,54 @@ def docker_secret(env_name):
|
||||
def test_phpmyadmin_secrets():
|
||||
docker_secret('MYSQL_PASSWORD')
|
||||
docker_secret('MYSQL_ROOT_PASSWORD')
|
||||
docker_secret('PMA_USER')
|
||||
docker_secret('PMA_PASSWORD')
|
||||
docker_secret('PMA_HOSTS')
|
||||
docker_secret('PMA_HOST')
|
||||
docker_secret('PMA_CONTROLHOST')
|
||||
docker_secret('PMA_CONTROLUSER')
|
||||
docker_secret('PMA_CONTROLPASS')
|
||||
|
||||
def test_is_using_ssl(url, username, password, server):
|
||||
is_using_ssl = os.environ.get('IS_USING_SSL');
|
||||
|
||||
def test_php_ini(url, username, password, server):
|
||||
br = create_browser()
|
||||
response = do_login(br, url, username, password, server)
|
||||
response = response.read()
|
||||
|
||||
assert(b'Show PHP information' in response.read())
|
||||
assert(b'Server connection' in response)
|
||||
|
||||
if is_using_ssl:
|
||||
assert(b'SSL is used' in response)
|
||||
assert(b'SSL is not being used' not in response)
|
||||
else:
|
||||
assert(b'SSL is used' not in response)
|
||||
assert(b'SSL is not being used' in response)
|
||||
|
||||
def test_is_using_ssl_client_cert(url, server):
|
||||
is_using_ssl = os.environ.get('IS_USING_SSL');
|
||||
if not is_using_ssl:
|
||||
pytest.skip("Missing IS_USING_SSL ENV", allow_module_level=True)
|
||||
|
||||
br = create_browser()
|
||||
password = ""
|
||||
response = do_login(br, url, "ssl-specific-user", password, server)
|
||||
response = response.read()
|
||||
|
||||
assert(b'Server connection' in response)
|
||||
assert(b'ssl-specific-user@' in response)
|
||||
|
||||
assert(b'SSL is used' in response)
|
||||
assert(b'SSL is not being used' not in response)
|
||||
|
||||
def test_php_ini(url, username, password, server):
|
||||
skip_expose_php_test = os.environ.get('SKIP_EXPOSE_PHP_TEST');
|
||||
|
||||
br = create_browser()
|
||||
response = do_login(br, url, username, password, server)
|
||||
response = response.read()
|
||||
|
||||
assert(b'Show PHP information' in response)
|
||||
|
||||
# Open Show PHP information
|
||||
response = br.follow_link(text_regex=re.compile('Show PHP information'))
|
||||
@@ -98,10 +140,73 @@ def test_php_ini(url, username, password, server):
|
||||
assert(b'upload_max_filesize' in response)
|
||||
assert(b'post_max_size' in response)
|
||||
assert(b'expose_php' in response)
|
||||
assert(b'session.save_path' in response)
|
||||
|
||||
assert(b'<tr><td class="e">max_execution_time</td><td class="v">125</td><td class="v">125</td></tr>' in response)
|
||||
|
||||
assert(b'<tr><td class="e">upload_max_filesize</td><td class="v">123M</td><td class="v">123M</td></tr>' in response)
|
||||
assert(b'<tr><td class="e">post_max_size</td><td class="v">123M</td><td class="v">123M</td></tr>' in response)
|
||||
|
||||
assert(b'<tr><td class="e">expose_php</td><td class="v">Off</td><td class="v">Off</td></tr>' in response)
|
||||
if not skip_expose_php_test:
|
||||
assert(b'<tr><td class="e">expose_php</td><td class="v">Off</td><td class="v">Off</td></tr>' in response)
|
||||
|
||||
assert(b'<tr><td class="e">session.save_path</td><td class="v">/sessions</td><td class="v">/sessions</td></tr>' in response)
|
||||
|
||||
def test_import_from_folder(url, username, password, server, sqlfile):
|
||||
upload_dir = os.environ.get('PMA_UPLOADDIR');
|
||||
if not upload_dir:
|
||||
pytest.skip("Missing PMA_UPLOADDIR ENV", allow_module_level=True)
|
||||
|
||||
# Copy file into the volume
|
||||
with open(get_world_sql_path(), 'rb') as src, open(upload_dir + '/world-data.sql', 'wb') as dst:
|
||||
dst.write(src.read())
|
||||
|
||||
br = create_browser()
|
||||
|
||||
response = do_login(br, url, username, password, server)
|
||||
|
||||
assert(b'Server version' in response.read())
|
||||
|
||||
# Open server import
|
||||
response = br.follow_link(text_regex=re.compile('Import'))
|
||||
response = response.read()
|
||||
|
||||
assert(b'Browse your computer:' in response)
|
||||
assert(upload_dir.encode() in response)
|
||||
assert(b'world-data.sql' in response)
|
||||
|
||||
def test_export_to_folder(url, username, password, server, sqlfile):
|
||||
save_dir = os.environ.get('PMA_SAVEDIR');
|
||||
if not save_dir:
|
||||
pytest.skip("Missing PMA_SAVEDIR ENV", allow_module_level=True)
|
||||
|
||||
# Delete file from previous runs
|
||||
if os.path.exists(save_dir + "/db_server.sql"):
|
||||
os.remove(save_dir + "/db_server.sql")
|
||||
|
||||
assert os.path.exists(save_dir + "/db_server.sql") == False
|
||||
|
||||
# Avoid: "The web server does not have permission to save the file"
|
||||
os.chmod(save_dir , 0o777)
|
||||
|
||||
br = create_browser()
|
||||
|
||||
response = do_login(br, url, username, password, server)
|
||||
|
||||
assert(b'Server version' in response.read())
|
||||
|
||||
# Open server export
|
||||
response = br.follow_link(text_regex=re.compile('Export'))
|
||||
response = response.read()
|
||||
assert(b'Save on server in the directory' in response)
|
||||
assert(save_dir.encode() in response)
|
||||
|
||||
br.select_form('dump')
|
||||
br.find_control("quick_export_onserver").items[0].selected=True
|
||||
|
||||
response = br.submit()
|
||||
response = response.read()
|
||||
|
||||
assert(b'Dump has been saved to file' in response)
|
||||
assert(b'Dump has been saved to file /etc/phpmyadmin/exports/db_server.sql' in response)
|
||||
assert os.path.exists(save_dir + "/db_server.sql") == True
|
||||
|
||||
+67
-4
@@ -1,5 +1,7 @@
|
||||
#!/bin/sh
|
||||
|
||||
set -eu
|
||||
|
||||
# Set phpMyAdmin environment
|
||||
PHPMYADMIN_HOSTNAME=${TESTSUITE_HOSTNAME:=localhost}
|
||||
PHPMYADMIN_PORT=${TESTSUITE_PORT:=80}
|
||||
@@ -8,9 +10,24 @@ PHPMYADMIN_URL=http://${PHPMYADMIN_HOSTNAME}:${PHPMYADMIN_PORT}/
|
||||
# Set database environment
|
||||
PHPMYADMIN_DB_HOSTNAME=${PMA_HOST:=localhost}
|
||||
PHPMYADMIN_DB_PORT=${PMA_PORT:=3306}
|
||||
TESTSUITE_USER=${TESTSUITE_USER:=root}
|
||||
TESTSUITE_ROOT_PASSWORD=${TESTSUITE_ROOT_PASSWORD:-}
|
||||
|
||||
if [ ! -z "${TESTSUITE_HOSTNAME_ARBITRARY}" ]; then
|
||||
SERVER="--server ${PHPMYADMIN_DB_HOSTNAME}"
|
||||
SUBJECT_CA="/C=US/O=phpMyAdmin testing/OU=Docker/CN=ssl-ca.phpmyadmin.local/emailAddress=ssl-ca@example.org"
|
||||
SUBJECT_CLIENT="/C=US/O=phpMyAdmin testing/OU=Docker/CN=client.phpmyadmin.local/emailAddress=secure-user@example.org"
|
||||
|
||||
if [ "${TESTSUITE_USER}" = "root" ] && [ -n "${TESTSUITE_ROOT_PASSWORD}" ]; then
|
||||
echo "Do not use TESTSUITE_ROOT_PASSWORD with TESTSUITE_USER=root"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
TEST_CLI_ARGS=""
|
||||
if [ -n "${TESTSUITE_HOSTNAME_ARBITRARY:-}" ]; then
|
||||
TEST_CLI_ARGS="$TEST_CLI_ARGS --server ${PHPMYADMIN_DB_HOSTNAME}"
|
||||
fi
|
||||
|
||||
if [ -n "${TESTSUITE_ROOT_PASSWORD}" ]; then
|
||||
TEST_CLI_ARGS="$TEST_CLI_ARGS --root-password ${TESTSUITE_ROOT_PASSWORD}"
|
||||
fi
|
||||
|
||||
# Find test script
|
||||
@@ -20,7 +37,45 @@ else
|
||||
FILENAME=./testing/phpmyadmin_test.py
|
||||
fi
|
||||
|
||||
mysql -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"${TESTSUITE_USER:=root}" -p"${TESTSUITE_PASSWORD}" -e "SELECT @@version;" > /dev/null
|
||||
SSL_FLAG="--skip-ssl"
|
||||
|
||||
if [ -n "${IS_USING_SSL:-}" ]; then
|
||||
SSL_FLAG="--ssl --ssl-verify-server-cert --ssl-ca=/etc/phpmyadmin/ssl/ca-cert.pem"
|
||||
fi
|
||||
|
||||
mariadb $SSL_FLAG -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"$TESTSUITE_USER" -p"${TESTSUITE_PASSWORD}" -e "SELECT @@version;SHOW VARIABLES LIKE 'require_secure_transport';SHOW VARIABLES LIKE '%ssl%';"
|
||||
|
||||
if [ -n "${IS_USING_SSL:-}" ]; then
|
||||
set +e
|
||||
mariadb --skip-ssl -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"$TESTSUITE_USER" -p"${TESTSUITE_PASSWORD}" -e "SELECT @@version;SHOW VARIABLES LIKE 'require_secure_transport';" 1> /dev/null 2> /dev/null
|
||||
if [ $? != 1 ]; then
|
||||
echo "The server does not enforce SSL connections, stopping the test."
|
||||
exit 1
|
||||
fi
|
||||
set -e
|
||||
fi
|
||||
|
||||
if [ -n "${IS_USING_SSL:-}" ] && [ -n "${TESTSUITE_ROOT_PASSWORD}" ]; then
|
||||
mariadb $SSL_FLAG -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"root" -p"${TESTSUITE_ROOT_PASSWORD}" \
|
||||
-e "CREATE USER 'ssl-specific-user'@'%' REQUIRE SUBJECT '$SUBJECT_CLIENT' AND ISSUER '$SUBJECT_CA';"
|
||||
|
||||
set +e
|
||||
mariadb $SSL_FLAG --ssl-cert=/etc/phpmyadmin/ssl/client-cert.pem --ssl-key=/etc/phpmyadmin/ssl/client-key.pem -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"ssl-specific-user" -e "SELECT @@version;SHOW VARIABLES LIKE 'require_secure_transport';" 1> /dev/null 2> /dev/null
|
||||
if [ $? != 0 ]; then
|
||||
echo "The server should accept the SSL client cert login, stopping the test."
|
||||
exit 1
|
||||
fi
|
||||
set -e
|
||||
|
||||
set +e
|
||||
mariadb $SSL_FLAG -h "${PHPMYADMIN_DB_HOSTNAME}" -P"${PHPMYADMIN_DB_PORT}" -u"ssl-specific-user" -e "SELECT @@version;SHOW VARIABLES LIKE 'require_secure_transport';" 1> /dev/null 2> /dev/null
|
||||
if [ $? != 1 ]; then
|
||||
echo "The server should refuse the login without a client cert, stopping the test."
|
||||
exit 1
|
||||
fi
|
||||
set -e
|
||||
fi
|
||||
|
||||
ret=$?
|
||||
|
||||
if [ $ret -ne 0 ] ; then
|
||||
@@ -28,9 +83,17 @@ if [ $ret -ne 0 ] ; then
|
||||
exit $ret
|
||||
fi
|
||||
|
||||
curl -fsSL --output /dev/null "${PHPMYADMIN_URL}"
|
||||
ret=$?
|
||||
|
||||
if [ $ret -ne 0 ] ; then
|
||||
echo "Could not connect to ${PHPMYADMIN_URL}"
|
||||
exit $ret
|
||||
fi
|
||||
|
||||
# Perform tests
|
||||
ret=0
|
||||
pytest -p no:cacheprovider -q --url "$PHPMYADMIN_URL" --username ${TESTSUITE_USER:=root} --password "$TESTSUITE_PASSWORD" $SERVER $FILENAME
|
||||
pytest -p no:cacheprovider -q --url "$PHPMYADMIN_URL" --username $TESTSUITE_USER --password "$TESTSUITE_PASSWORD" $TEST_CLI_ARGS $FILENAME
|
||||
ret=$?
|
||||
|
||||
# Show debug output in case of failure
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
[mysqld]
|
||||
default_authentication_plugin = mysql_native_password
|
||||
@@ -1,18 +1,10 @@
|
||||
#!/bin/bash
|
||||
set -e
|
||||
set -eu -o pipefail
|
||||
|
||||
# Check for dependencies
|
||||
command -v curl >/dev/null 2>&1 || { echo >&2 "'curl' is required but not found. Aborting."; exit 1; }
|
||||
command -v jq >/dev/null 2>&1 || { echo >&2 "'jq' is required but not found. Aborting."; exit 1; }
|
||||
if [ -z "${BASH_VERSINFO}" ] || [ -z "${BASH_VERSINFO[0]}" ] || [ ${BASH_VERSINFO[0]} -lt 4 ]; then
|
||||
echo "BASH version 4.0 or greater is required. Aborting."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
declare -A cmd=(
|
||||
[apache]='apache2-foreground'
|
||||
[fpm]='php-fpm'
|
||||
[fpm-alpine]='php-fpm'
|
||||
variants=(
|
||||
apache
|
||||
fpm
|
||||
fpm-alpine
|
||||
)
|
||||
|
||||
declare -A base=(
|
||||
@@ -21,18 +13,89 @@ declare -A base=(
|
||||
[fpm-alpine]='alpine'
|
||||
)
|
||||
|
||||
latest="$(curl -fsSL 'https://www.phpmyadmin.net/home_page/version.json' | jq -r '.version')"
|
||||
sha256="$(curl -fsSL "https://files.phpmyadmin.net/phpMyAdmin/$latest/phpMyAdmin-$latest-all-languages.tar.xz.sha256" | cut -f1 -d ' ' | tr -cd 'a-f0-9' | cut -c 1-64)"
|
||||
declare -A php_version=(
|
||||
[default]='8.2'
|
||||
)
|
||||
|
||||
for variant in apache fpm fpm-alpine; do
|
||||
template="Dockerfile-${base[$variant]}.template"
|
||||
cp $template "$variant/Dockerfile"
|
||||
cp config.inc.php "$variant/config.inc.php"
|
||||
cp docker-entrypoint.sh "$variant/docker-entrypoint.sh"
|
||||
declare -A cmd=(
|
||||
[apache]='apache2-foreground'
|
||||
[fpm]='php-fpm'
|
||||
[fpm-alpine]='php-fpm'
|
||||
)
|
||||
|
||||
gpg_key='3D06A59ECE730EB71B511C17CE752F178259BD92'
|
||||
|
||||
function download_url() {
|
||||
echo "https://files.phpmyadmin.net/phpMyAdmin/$1/phpMyAdmin-$1-all-languages.tar.xz"
|
||||
}
|
||||
|
||||
function create_variant() {
|
||||
local variant="$1"
|
||||
local version="$2"
|
||||
local sha256="$3"
|
||||
|
||||
local branch="$(sed -ne 's/^\([0-9]*\.[0-9]*\)\..*$/\1/p' <<< "$version")"
|
||||
local url="$(download_url "$version")"
|
||||
local ascUrl="$(download_url "$version").asc"
|
||||
local phpVersion="${php_version[$version]-${php_version[default]}}"
|
||||
|
||||
echo "updating $version [$branch] $variant"
|
||||
|
||||
# Create the variant directory with a Dockerfile
|
||||
mkdir -p "$variant"
|
||||
|
||||
local template="Dockerfile-${base[$variant]}.template"
|
||||
echo "# DO NOT EDIT: created by update.sh from $template" > "$variant/Dockerfile"
|
||||
cat "$template" >> "$variant/Dockerfile"
|
||||
|
||||
# Replace Dockerfile variables
|
||||
sed -ri -e '
|
||||
s/%%VERSION%%/'"$latest"'/;
|
||||
s/%%SHA256%%/'"$sha256"'/;
|
||||
s/%%VARIANT%%/'"$variant"'/;
|
||||
s/%%VERSION%%/'"$version"'/;
|
||||
s/%%SHA256%%/'"$sha256"'/;
|
||||
s/%%DOWNLOAD_URL%%/'"$(sed -e 's/[\/&]/\\&/g' <<< "$url")"'/;
|
||||
s/%%DOWNLOAD_URL_ASC%%/'"$(sed -e 's/[\/&]/\\&/g' <<< "$ascUrl")"'/;
|
||||
s/%%PHP_VERSION%%/'"$phpVersion"'/g;
|
||||
s/%%GPG_KEY%%/'"$gpg_key"'/g;
|
||||
s/%%CMD%%/'"${cmd[$variant]}"'/;
|
||||
' "$variant/Dockerfile"
|
||||
|
||||
# Copy docker-entrypoint.sh
|
||||
cp docker-entrypoint.sh "$variant/docker-entrypoint.sh"
|
||||
if [ "$variant" != "apache" ]; then
|
||||
sed -i "/^# start: Apache specific settings$/,/^# end: Apache specific settings$/d" "$variant/docker-entrypoint.sh"
|
||||
sed -i "/^\s*# start: Apache specific build$/,/^\s*# end: Apache specific build$/d" "$variant/Dockerfile"
|
||||
fi
|
||||
|
||||
# Copy config.inc.php and helpers.php
|
||||
cp config.inc.php "$variant/config.inc.php"
|
||||
cp helpers.php "$variant/helpers.php"
|
||||
|
||||
# Add variant to versions.json
|
||||
versionVariantsJson="$(jq -e \
|
||||
--arg branch "$branch" --arg variant "$variant" --arg base "${base[$variant]}" --arg phpVersion "$phpVersion" \
|
||||
'.[$branch].variants[$variant] = {"variant": $variant, "base": $base, "phpVersion": $phpVersion}' versions.json)"
|
||||
versionJson="$(jq -e \
|
||||
--arg branch "$branch" --arg version "$version" --arg sha256 "$sha256" --arg url "$url" --arg ascUrl "$ascUrl" --argjson variants "$versionVariantsJson" \
|
||||
'.[$branch] = {"branch": $branch, "version": $version, "sha256": $sha256, "url": $url, "ascUrl": $ascUrl, "variants": $variants[$branch].variants}' versions.json)"
|
||||
printf '%s\n' "$versionJson" > versions.json
|
||||
}
|
||||
|
||||
# Check script dependencies
|
||||
command -v curl >/dev/null 2>&1 || { echo >&2 "'curl' is required but not found. Aborting."; exit 1; }
|
||||
command -v jq >/dev/null 2>&1 || { echo >&2 "'jq' is required but not found. Aborting."; exit 1; }
|
||||
[ -n "${BASH_VERSINFO}" ] && [ -n "${BASH_VERSINFO[0]}" ] && [ ${BASH_VERSINFO[0]} -ge 4 ] \
|
||||
|| { echo >&2 "Bash 4.0 or greater is required. Aborting."; exit 1; }
|
||||
|
||||
# Create variants
|
||||
printf '%s\n' "{}" > versions.json
|
||||
|
||||
latest="$(curl -fsSL 'https://www.phpmyadmin.net/home_page/version.json' | jq -r '.version' | grep -E '^[0-9]{1,}.[0-9]{1,}.[0-9]{1,}$')"
|
||||
sha256="$(curl -fsSL "$(download_url "$latest").sha256" | cut -f1 -d ' ' | tr -cd 'a-f0-9' | cut -c 1-64)"
|
||||
|
||||
for variant in "${variants[@]}"; do
|
||||
create_variant "$variant" "$latest" "$sha256"
|
||||
done
|
||||
|
||||
# Cleanup the file as for now it's not wanted in the repository
|
||||
rm versions.json
|
||||
|
||||
Reference in New Issue
Block a user