mirror of
				https://github.com/11notes/docker-kms-gui.git
				synced 2025-10-30 19:23:31 +00:00 
			
		
		
		
	Compare commits
	
		
			53 Commits
		
	
	
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
|  | bf755ecf0d | ||
|  | 2ef047319a | ||
|  | d608769727 | ||
|  | 72d8d9c55c | ||
|  | d20153c545 | ||
|  | ce91a1f421 | ||
|  | dbce137fb8 | ||
|  | 4aed569709 | ||
|  | 8b1457602d | ||
|  | 847ff77077 | ||
|  | cfbf6347c2 | ||
|  | 7f4a0b5cf4 | ||
|  | c5bbc99c24 | ||
|  | 971ba4ffe4 | ||
|  | 1ba6193786 | ||
|  | 026ad460f2 | ||
|  | 3fe5ab5da7 | ||
|  | a04dad1275 | ||
|  | cabd8fd912 | ||
|  | 87b0cb92ea | ||
|  | 0ad0cd2171 | ||
|  | ac6cf03ce6 | ||
|  | 5426f03cc4 | ||
|  | d668e52b2f | ||
|  | 717231ea90 | ||
|  | 3afec57439 | ||
|  | 497b70ea6a | ||
|  | 3e9b1a5950 | ||
|  | 6e690e96c3 | ||
|  | f5249c6f6b | ||
|  | 78c5cb68db | ||
|  | 0cc9bf714a | ||
|  | 33f68a3b09 | ||
|  | 23ea81077b | ||
|  | 4309e308b3 | ||
|  | 36885bc9e5 | ||
|  | 65ab5cf49f | ||
|  | 60d6c33d69 | ||
|  | e555a3b1e3 | ||
|  | d161bab2d8 | ||
|  | 7754585854 | ||
|  | 2bbc9e2653 | ||
|  | a955ccb9b1 | ||
|  | 3822e0e370 | ||
|  | c06ececada | ||
|  | c8b7e470e4 | ||
|  | eea805e13a | ||
|  | 6909b2fc29 | ||
|  | caa7a8a1e6 | ||
|  | dcfb8ba91e | ||
|  | 129c21344c | ||
|  | 303774a72c | ||
|  | 23892c6d0b | 
							
								
								
									
										3
									
								
								.gitattributes
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitattributes
									
									
									
									
										vendored
									
									
								
							| @@ -1,2 +1 @@ | ||||
| # Auto detect text files and perform LF normalization | ||||
| * text=auto | ||||
| * text=auto | ||||
							
								
								
									
										247
									
								
								.github/workflows/docker.yml
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										247
									
								
								.github/workflows/docker.yml
									
									
									
									
										vendored
									
									
								
							| @@ -1,18 +1,50 @@ | ||||
| name: create and publish docker image | ||||
| name: docker | ||||
| run-name: ${{ inputs.run-name }} | ||||
|  | ||||
| on: | ||||
|   workflow_dispatch: | ||||
|   push: | ||||
|     tags: | ||||
|       - 'v*' | ||||
|     inputs: | ||||
|       run-name: | ||||
|         description: 'set run-name for workflow (multiple calls)' | ||||
|         type: string | ||||
|         required: false | ||||
|         default: 'docker' | ||||
|  | ||||
| env: | ||||
|   DOCKER_USERNAME: 11notes | ||||
|       release: | ||||
|         description: 'set WORKFLOW_GITHUB_RELEASE' | ||||
|         required: false | ||||
|         default: 'false' | ||||
|  | ||||
|       readme: | ||||
|         description: 'set WORKFLOW_GITHUB_README' | ||||
|         required: false | ||||
|         default: 'false' | ||||
|  | ||||
|       image: | ||||
|         description: 'set IMAGE' | ||||
|         required: false | ||||
|  | ||||
|       uid: | ||||
|         description: 'set IMAGE_UID' | ||||
|         required: false | ||||
|  | ||||
|       gid: | ||||
|         description: 'set IMAGE_GID' | ||||
|         required: false | ||||
|  | ||||
|       semverprefix: | ||||
|         description: 'prefix for semver tags' | ||||
|         required: false | ||||
|  | ||||
|       semversuffix: | ||||
|         description: 'suffix for semver tags' | ||||
|         required: false | ||||
|  | ||||
| jobs: | ||||
|   build-and-push-image: | ||||
|     runs-on: ubuntu-latest | ||||
|   docker: | ||||
|     runs-on: ubuntu-22.04 | ||||
|     permissions: | ||||
|       actions: read | ||||
|       contents: write | ||||
|       packages: write | ||||
|       security-events: write | ||||
| @@ -20,6 +52,18 @@ jobs: | ||||
|     steps:    | ||||
|       - name: init / checkout | ||||
|         uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 | ||||
|         with: | ||||
|           ref: ${{ github.ref_name }} | ||||
|           fetch-depth: 0 | ||||
|  | ||||
|       - name: init / inputs to env | ||||
|         if: github.event_name == 'workflow_dispatch' | ||||
|         run: | | ||||
|           cat << 'EOF' > .inputs | ||||
|           ${{ toJSON(github.event.inputs) }} | ||||
|           EOF | ||||
|           for KEY in $(cat .inputs | jq --raw-output 'keys[]' | tr '\n' ' '); do echo "input_$(echo ${KEY} | tr '[:upper:]' '[:lower:]')=$(cat .inputs | jq --raw-output '.'${KEY}'')" >> $GITHUB_ENV; done | ||||
|           rm -rf .inputs | ||||
|  | ||||
|       - name: init / .json to env | ||||
|         uses: rgarcia-phi/json-to-variables@9835d537368468c4e4de5254dc3efeadda183793 | ||||
| @@ -28,31 +72,51 @@ jobs: | ||||
|  | ||||
|       - name: init / setup environment | ||||
|         run: | | ||||
|           : # set default arch if not set | ||||
|           : # set image | ||||
|           LOCAL_IMAGE=${json_image} | ||||
|           if [ ! -z ${input_image} ]; then LOCAL_IMAGE=${input_image}; fi | ||||
|           echo "IMAGE=${LOCAL_IMAGE}" >> $GITHUB_ENV | ||||
|  | ||||
|           : # set defaults | ||||
|           echo "IMAGE_ARCH=${json_arch:-linux/amd64,linux/arm64}" >> $GITHUB_ENV | ||||
|           echo "WORKFLOW_GITHUB_RELEASE=${input_release:-true}" >> $GITHUB_ENV; | ||||
|           echo "WORKFLOW_GITHUB_README=${input_readme:-true}" >> $GITHUB_ENV; | ||||
|           echo "WORKFLOW_GRYPE_SCAN=${json_grype_scan:-true}" >> $GITHUB_ENV; | ||||
|           echo "WORKFLOW_GRYPE_SEVERITY_CUTOFF=${json_grype_severity:-high}" >> $GITHUB_ENV; | ||||
|  | ||||
|           : # create tags for semver, stable and other shenanigans | ||||
|           export LOCAL_SHA=$(git rev-parse --short HEAD) | ||||
|           export LOCAL_SEMVER_MAJOR=$(awk -F. '{ print $1 }' <<< ${json_version}) | ||||
|           export LOCAL_SEMVER_MINOR=$(awk -F. '{ print $2 }' <<< ${json_version}) | ||||
|           export LOCAL_SEMVER_PATCH=$(awk -F. '{ print $3 }' <<< ${json_version}) | ||||
|           export LOCAL_TAGS="${json_image}:latest" | ||||
|           if [ ! -z ${LOCAL_SEMVER_MAJOR} ]; then LOCAL_TAGS="${LOCAL_TAGS},${json_image}:${LOCAL_SEMVER_MAJOR}"; fi | ||||
|           if [ ! -z ${LOCAL_SEMVER_MINOR} ]; then LOCAL_TAGS="${LOCAL_TAGS},${json_image}:${LOCAL_SEMVER_MAJOR}.${LOCAL_SEMVER_MINOR}"; fi | ||||
|           if [ ! -z ${LOCAL_SEMVER_PATCH} ]; then LOCAL_TAGS="${LOCAL_TAGS},${json_image}:${LOCAL_SEMVER_MAJOR}.${LOCAL_SEMVER_MINOR}.${LOCAL_SEMVER_PATCH}"; fi | ||||
|           if echo "${LOCAL_TAGS}" | grep -q "${json_stable}" ; then LOCAL_TAGS="${LOCAL_TAGS},${json_image}:stable"; fi | ||||
|           if [ ! -z ${json_tags} ]; then SPECIAL_LOCAL_TAGS=$(echo ${json_tags} | sed 's/,/ /g'); for LOCAL_TAG in ${json_tags}; do LOCAL_TAGS="${LOCAL_TAGS},${json_image}:${LOCAL_TAG}"; done; fi | ||||
|           LOCAL_TAGS="${LOCAL_TAGS},${json_image}:${LOCAL_SHA}" | ||||
|           LOCAL_SHA=$(git rev-parse --short HEAD) | ||||
|           LOCAL_SEMVER_MAJOR=$(awk -F. '{ print $1 }' <<< ${json_semver_version}) | ||||
|           LOCAL_SEMVER_MINOR=$(awk -F. '{ print $2 }' <<< ${json_semver_version}) | ||||
|           LOCAL_SEMVER_PATCH=$(awk -F. '{ print $3 }' <<< ${json_semver_version}) | ||||
|           LOCAL_SEMVER_PREFIX="" | ||||
|           LOCAL_SEMVER_SUFFIX="" | ||||
|           LOCAL_SEMVER_RC="" | ||||
|           LOCAL_TAGS="${LOCAL_IMAGE}:${LOCAL_SHA}" | ||||
|           if [ ! -z ${input_semverprefix} ]; then LOCAL_SEMVER_PREFIX="${input_semverprefix}-"; fi | ||||
|           if [ ! -z ${input_semversuffix} ]; then LOCAL_SEMVER_SUFFIX="-${input_semversuffix}"; fi | ||||
|           if [ ! -z ${json_semver_rc} ]; then LOCAL_SEMVER_RC="${json_semver_rc}"; fi | ||||
|           if [ ! -z ${LOCAL_SEMVER_MAJOR} ]; then LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}${LOCAL_SEMVER_MAJOR}${LOCAL_SEMVER_SUFFIX}"; fi | ||||
|           if [ ! -z ${LOCAL_SEMVER_MINOR} ]; then LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}${LOCAL_SEMVER_MAJOR}.${LOCAL_SEMVER_MINOR}${LOCAL_SEMVER_SUFFIX}"; fi | ||||
|           if [ ! -z ${LOCAL_SEMVER_PATCH} ]; then LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}${LOCAL_SEMVER_MAJOR}.${LOCAL_SEMVER_MINOR}.${LOCAL_SEMVER_PATCH}${LOCAL_SEMVER_SUFFIX}"; fi | ||||
|           if echo "${LOCAL_TAGS}" | grep -q "${json_semver_stable}" ; then LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}stable${LOCAL_SEMVER_SUFFIX}"; fi | ||||
|           if echo "${LOCAL_TAGS}" | grep -q "${json_semver_latest}" ; then LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}latest${LOCAL_SEMVER_SUFFIX}"; fi | ||||
|           if [ ! -z ${json_semver_tags} ]; then SPECIAL_LOCAL_TAGS=$(echo ${json_semver_tags} | sed 's/,/ /g'); for LOCAL_TAG in ${json_semver_tags}; do LOCAL_TAGS="${LOCAL_TAGS},${LOCAL_IMAGE}:${LOCAL_SEMVER_PREFIX}${LOCAL_TAG}${LOCAL_SEMVER_SUFFIX}"; done; fi | ||||
|           echo "IMAGE_TAGS=${LOCAL_TAGS}" >> $GITHUB_ENV | ||||
|  | ||||
|           : # if for whatever reason UID/GID must be changed at build time | ||||
|           echo "IMAGE_UID=${json_uid:-1000}" >> $GITHUB_ENV | ||||
|           echo "IMAGE_GID=${json_gid:-1000}" >> $GITHUB_ENV | ||||
|           if [ ! -z ${input_uid} ]; then echo "IMAGE_UID=${input_uid}" >> $GITHUB_ENV; else echo "IMAGE_UID=${json_uid:-1000}" >> $GITHUB_ENV; fi | ||||
|           if [ ! -z ${input_gid} ]; then echo "IMAGE_GID=${input_gid}" >> $GITHUB_ENV; else echo "IMAGE_GID=${json_gid:-1000}" >> $GITHUB_ENV; fi | ||||
|  | ||||
|           : # set rc, prefix or suffix globally for semver and version | ||||
|           echo "IMAGE_SEMVER_PREFIX=${LOCAL_SEMVER_PREFIX}" >> $GITHUB_ENV | ||||
|           echo "IMAGE_SEMVER_SUFFIX=${LOCAL_SEMVER_SUFFIX}" >> $GITHUB_ENV | ||||
|           echo "IMAGE_VERSION_RC=${LOCAL_SEMVER_RC}" >> $GITHUB_ENV | ||||
|  | ||||
|       - name: docker / login to hub | ||||
|         uses: docker/login-action@9780b0c442fbb1117ed29e0efdff1e18412f7567 | ||||
|         with: | ||||
|           username: ${{ env.DOCKER_USERNAME }} | ||||
|           username: 11notes | ||||
|           password: ${{ secrets.DOCKER_TOKEN }} | ||||
|  | ||||
|       - name: docker / setup qemu | ||||
| @@ -61,49 +125,57 @@ jobs: | ||||
|       - name: docker / setup buildx | ||||
|         uses: docker/setup-buildx-action@6524bf65af31da8d45b59e8c27de4bd072b392f5 | ||||
|  | ||||
|       - name: grype / build & push | ||||
|       - name: grype / build & push & tag | ||||
|         id: grype-tag | ||||
|         uses: docker/build-push-action@67a2d409c0a876cbe6b11854e3e25193efe4e62d | ||||
|         with: | ||||
|           context: . | ||||
|           file: arch.dockerfile | ||||
|           push: true | ||||
|           platforms: ${{ env.IMAGE_ARCH }} | ||||
|           cache-from: type=registry,ref=${{ env.json_image }}:buildcache | ||||
|           cache-to: type=registry,ref=${{ env.json_image }}:buildcache,mode=max,compression=zstd,force-compression=true | ||||
|           cache-from: type=registry,ref=${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}buildcache${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|           cache-to: type=registry,ref=${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}buildcache${{ env.IMAGE_SEMVER_SUFFIX }},mode=max,compression=zstd,force-compression=true | ||||
|           build-args: | | ||||
|             APP_IMAGE=${{ env.json_image }} | ||||
|             APP_IMAGE=${{ env.IMAGE }} | ||||
|             APP_NAME=${{ env.json_name }} | ||||
|             APP_VERSION=${{ env.json_version }} | ||||
|             APP_VERSION=${{ env.json_semver_version }} | ||||
|             APP_ROOT=${{ env.json_root }} | ||||
|             APP_UID=${{ env.IMAGE_UID }} | ||||
|             APP_GID=${{ env.IMAGE_GID }} | ||||
|             NO_CACHE=$(date +%s) | ||||
|             APP_VERSION_PREFIX=${{ env.IMAGE_SEMVER_PREFIX }} | ||||
|             APP_VERSION_SUFFIX=${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|             APP_VERSION_RC=${{ env.IMAGE_VERSION_RC }} | ||||
|             APP_NO_CACHE=$(date +%s) | ||||
|           tags: | | ||||
|             ${{ env.json_image }}:grype | ||||
|             ${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}grype${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|  | ||||
|       - name: grype / scan | ||||
|         id: scan | ||||
|         if: env.WORKFLOW_GRYPE_SCAN == 'true' | ||||
|         id: grype-scan | ||||
|         uses: anchore/scan-action@abae793926ec39a78ab18002bc7fc45bbbd94342 | ||||
|         with: | ||||
|           image: ${{ env.json_image }}:grype | ||||
|           severity-cutoff: high | ||||
|           image: ${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}grype${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|           severity-cutoff: ${{ env.WORKFLOW_GRYPE_SEVERITY_CUTOFF }} | ||||
|           by-cve: true | ||||
|           output-format: 'sarif' | ||||
|  | ||||
|       - name: grype / delete tag | ||||
|         if: success() || failure() | ||||
|         if: steps.grype-tag.outcome == 'success' | ||||
|         run: | | ||||
|           curl --request DELETE \ | ||||
|             --url https://hub.docker.com/v2/repositories/${{ env.json_image }}/tags/grype/ \ | ||||
|             --url https://hub.docker.com/v2/repositories/${{ env.IMAGE }}/tags/${{ env.IMAGE_SEMVER_PREFIX }}grype${{ env.IMAGE_SEMVER_SUFFIX }}/ \ | ||||
|             --header 'authorization: jwt ${{ secrets.DOCKER_TOKEN }}' \ | ||||
|             --header 'content-type: application/json' \ | ||||
|             --fail | ||||
|  | ||||
|       - name: grype / report / upload | ||||
|       - name: codeql / upload | ||||
|         id: codeql-upload | ||||
|         if: steps.grype-scan.outcome == 'success' | ||||
|         uses: github/codeql-action/upload-sarif@48ab28a6f5dbc2a99bf1e0131198dd8f1df78169 | ||||
|         with: | ||||
|           sarif_file: ${{ steps.scan.outputs.sarif }} | ||||
|  | ||||
|       - name: grype / report / print | ||||
|         run: cat ${{ steps.scan.outputs.sarif }} | ||||
|           sarif_file: ${{ steps.grype-scan.outputs.sarif }} | ||||
|           wait-for-processing: false | ||||
|           category: grype | ||||
|  | ||||
|       - name: docker / build & push | ||||
|         uses: docker/build-push-action@67a2d409c0a876cbe6b11854e3e25193efe4e62d | ||||
| @@ -114,23 +186,87 @@ jobs: | ||||
|           sbom: true | ||||
|           provenance: mode=max | ||||
|           platforms: ${{ env.IMAGE_ARCH }} | ||||
|           cache-from: type=registry,ref=${{ env.json_image }}:buildcache | ||||
|           cache-to: type=registry,ref=${{ env.json_image }}:buildcache,mode=max,compression=zstd,force-compression=true | ||||
|           cache-from: type=registry,ref=${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}buildcache${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|           cache-to: type=registry,ref=${{ env.IMAGE }}:${{ env.IMAGE_SEMVER_PREFIX }}buildcache${{ env.IMAGE_SEMVER_SUFFIX }},mode=max,compression=zstd,force-compression=true | ||||
|           build-args: | | ||||
|             APP_IMAGE=${{ env.json_image }} | ||||
|             APP_IMAGE=${{ env.IMAGE }} | ||||
|             APP_NAME=${{ env.json_name }} | ||||
|             APP_VERSION=${{ env.json_version }} | ||||
|             APP_VERSION=${{ env.json_semver_version }} | ||||
|             APP_ROOT=${{ env.json_root }} | ||||
|             APP_UID=${{ env.IMAGE_UID }} | ||||
|             APP_GID=${{ env.IMAGE_GID }} | ||||
|             NO_CACHE=$(date +%s) | ||||
|             APP_VERSION_PREFIX=${{ env.IMAGE_SEMVER_PREFIX }} | ||||
|             APP_VERSION_SUFFIX=${{ env.IMAGE_SEMVER_SUFFIX }} | ||||
|             APP_VERSION_RC=${{ env.IMAGE_VERSION_RC }} | ||||
|             APP_NO_CACHE=$(date +%s) | ||||
|           tags: | | ||||
|             ${{ env.IMAGE_TAGS }} | ||||
|  | ||||
|       - name: github / create release notes | ||||
|       - name: github / release / log | ||||
|         id: git-log | ||||
|         run: | | ||||
|           LOCAL_LAST_TAG=$(git describe --abbrev=0 --tags `git rev-list --tags --skip=1 --max-count=1`) | ||||
|           echo "using last tag: ${LOCAL_LAST_TAG}" | ||||
|           LOCAL_COMMITS=$(git log ${LOCAL_LAST_TAG}..HEAD --oneline) | ||||
|  | ||||
|           EOF=$(dd if=/dev/urandom bs=15 count=1 status=none | base64) | ||||
|           echo "commits<<${EOF}" >> ${GITHUB_OUTPUT} | ||||
|           echo "${LOCAL_COMMITS}" >> ${GITHUB_OUTPUT} | ||||
|           echo "${EOF}" >> ${GITHUB_OUTPUT} | ||||
|  | ||||
|       - name: github / release / markdown | ||||
|         if: env.WORKFLOW_GITHUB_RELEASE == 'true' | ||||
|         id: git-release | ||||
|         uses: 11notes/action-docker-release@v1 | ||||
|         with: | ||||
|           git_log: ${{ steps.git-log.outputs.commits }} | ||||
|  | ||||
|       - name: github / release / create | ||||
|         if: env.WORKFLOW_GITHUB_RELEASE == 'true' && steps.git-release.outcome == 'success' | ||||
|         uses: actions/create-release@4c11c9fe1dcd9636620a16455165783b20fc7ea0 | ||||
|         env: | ||||
|           GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||||
|         run: gh release create ${{ github.ref_name }} -F RELEASE.md | ||||
|           GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} | ||||
|         with: | ||||
|           tag_name: ${{ github.ref }} | ||||
|           release_name: ${{ github.ref }} | ||||
|           body: ${{ steps.git-release.outputs.release }} | ||||
|           draft: false | ||||
|           prerelease: false | ||||
|  | ||||
|       - name: github / checkout master | ||||
|         continue-on-error: true | ||||
|         run: |          | ||||
|           git checkout master | ||||
|  | ||||
|       - name: github / create README.md | ||||
|         continue-on-error: true | ||||
|         if: env.WORKFLOW_GITHUB_README == 'true' | ||||
|         id: github-readme | ||||
|         uses: 11notes/action-docker-readme@v1 | ||||
|         with: | ||||
|           sarif_file: ${{ steps.grype-scan.outputs.sarif }} | ||||
|  | ||||
|       - name: github / commit & push | ||||
|         continue-on-error: true | ||||
|         if: steps.github-readme.outcome == 'success' | ||||
|         run: |          | ||||
|           git config user.name "github-actions[bot]" | ||||
|           git config user.email "41898282+github-actions[bot]@users.noreply.github.com" | ||||
|           git add README.md | ||||
|           git commit -m "auto update README.md" | ||||
|           git push | ||||
|  | ||||
|       - name: docker / push README.md to docker hub | ||||
|         if: hashFiles('README.md') != '' | ||||
|         uses: christian-korneck/update-container-description-action@d36005551adeaba9698d8d67a296bd16fa91f8e8 | ||||
|         env: | ||||
|           DOCKER_USER: 11notes | ||||
|           DOCKER_PASS: ${{ secrets.DOCKER_TOKEN }} | ||||
|         with: | ||||
|           destination_container_repo: ${{ env.IMAGE }} | ||||
|           provider: dockerhub | ||||
|           short_description: ${{ env.json_readme_description }} | ||||
|           readme_file: 'README.md' | ||||
|  | ||||
|       - name: github / update description and set repo defaults | ||||
|         run: | | ||||
| @@ -139,22 +275,11 @@ jobs: | ||||
|             --header 'authorization: Bearer ${{ secrets.REPOSITORY_TOKEN }}' \ | ||||
|             --header 'content-type: application/json' \ | ||||
|             --data '{ | ||||
|               "description":"${{ env.json_description }}", | ||||
|               "description":"${{ env.json_readme_description }}", | ||||
|               "homepage":"", | ||||
|               "has_issues":true, | ||||
|               "has_discussions":true, | ||||
|               "has_projects":false, | ||||
|               "has_wiki":false | ||||
|             }' \ | ||||
|             --fail | ||||
|  | ||||
|       - name: docker / push README.md to docker hub | ||||
|         uses: christian-korneck/update-container-description-action@d36005551adeaba9698d8d67a296bd16fa91f8e8 | ||||
|         env: | ||||
|           DOCKER_USER: ${{ env.DOCKER_USERNAME }} | ||||
|           DOCKER_PASS: ${{ secrets.DOCKER_TOKEN }} | ||||
|         with: | ||||
|           destination_container_repo: ${{ env.json_image }} | ||||
|           provider: dockerhub | ||||
|           short_description: ${{ env.json_description }} | ||||
|           readme_file: 'README.md' | ||||
|             --fail | ||||
							
								
								
									
										25
									
								
								.github/workflows/tags.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							
							
						
						
									
										25
									
								
								.github/workflows/tags.yml
									
									
									
									
										vendored
									
									
										Normal file
									
								
							| @@ -0,0 +1,25 @@ | ||||
| name: tags | ||||
| on: | ||||
|   push: | ||||
|     tags: | ||||
|       - 'v*' | ||||
| jobs: | ||||
|   docker: | ||||
|     runs-on: ubuntu-latest | ||||
|     steps:    | ||||
|       - name: build docker image | ||||
|         uses: the-actions-org/workflow-dispatch@3133c5d135c7dbe4be4f9793872b6ef331b53bc7 | ||||
|         with: | ||||
|           workflow: docker.yml | ||||
|           token: "${{ secrets.REPOSITORY_TOKEN }}" | ||||
|           inputs: '{ "release":"true", "readme":"true" }' | ||||
|  | ||||
|   docker-unraid: | ||||
|     runs-on: ubuntu-latest | ||||
|     steps:    | ||||
|       - name: build docker image for unraid community | ||||
|         uses: the-actions-org/workflow-dispatch@3133c5d135c7dbe4be4f9793872b6ef331b53bc7 | ||||
|         with: | ||||
|           workflow: docker.yml | ||||
|           token: "${{ secrets.REPOSITORY_TOKEN }}" | ||||
|           inputs: '{ "release":"false", "readme":"false", "uid":"99", "gid":"100", "semversuffix":"unraid", "run-name":"docker-unraid" }' | ||||
							
								
								
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										3
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							| @@ -1,2 +1 @@ | ||||
| maintain/ | ||||
| project* | ||||
| maintain/ | ||||
							
								
								
									
										20
									
								
								.json
									
									
									
									
									
								
							
							
						
						
									
										20
									
								
								.json
									
									
									
									
									
								
							| @@ -1,10 +1,22 @@ | ||||
| { | ||||
|   "image":"11notes/kms-gui", | ||||
|   "description":"Activate any version of Windows and Office, forever", | ||||
|   "name":"kms-gui", | ||||
|   "version":"646f476", | ||||
|   "root":"/kms", | ||||
|    | ||||
|   "stable":"646f476", | ||||
|   "parent":"11notes/kms:646f476" | ||||
|   "semver":{ | ||||
|     "version":"465f4d1", | ||||
|     "stable":"465f4d1", | ||||
|     "latest":"465f4d1" | ||||
|   }, | ||||
|  | ||||
|   "readme":{ | ||||
|     "description":"Activate any version of Windows and Office, forever", | ||||
|     "parent":{ | ||||
|       "image":"11notes/kms:465f4d1" | ||||
|     }, | ||||
|     "built":{ | ||||
|       "py-kms":"https://github.com/Py-KMS-Organization/py-kms", | ||||
|       "CustomIcon/pykms-frontend":"https://github.com/CustomIcon/pykms-frontend" | ||||
|     } | ||||
|   } | ||||
| } | ||||
							
								
								
									
										60
									
								
								README.md
									
									
									
									
									
								
							
							
						
						
									
										60
									
								
								README.md
									
									
									
									
									
								
							| @@ -1,11 +1,24 @@ | ||||
|  | ||||
|  | ||||
|  | ||||
| # 🏔️ kms-gui on Alpine | ||||
| [<img src="https://img.shields.io/badge/github-source-blue?logo=github&color=040308">](https://github.com/11notes/docker-kms-gui)[<img src="https://img.shields.io/github/issues/11notes/docker-kms-gui?color=7842f5">](https://github.com/11notes/docker-kms-gui/issues) | ||||
| # ⛰️ kms-gui | ||||
| [<img src="https://img.shields.io/badge/github-source-blue?logo=github&color=040308">](https://github.com/11notes/docker-kms-gui)[<img src="https://img.shields.io/github/issues/11notes/docker-kms-gui?color=7842f5">](https://github.com/11notes/docker-kms-gui/issues) | ||||
|  | ||||
| **Activate any version of Windows and Office, forever** | ||||
| Activate any version of Windows and Office, forever | ||||
|  | ||||
|  | ||||
| # MAIN TAGS 🏷️ | ||||
| These are the main tags for the image. There is also a tag for each commit and its shorthand sha256 value. | ||||
|  | ||||
| * [465f4d1](https://hub.docker.com/r/11notes/kms-gui/tags?name=465f4d1) | ||||
| * [stable](https://hub.docker.com/r/11notes/kms-gui/tags?name=stable) | ||||
| * [latest](https://hub.docker.com/r/11notes/kms-gui/tags?name=latest) | ||||
| * [465f4d1-unraid](https://hub.docker.com/r/11notes/kms-gui/tags?name=465f4d1-unraid) | ||||
| * [stable-unraid](https://hub.docker.com/r/11notes/kms-gui/tags?name=stable-unraid) | ||||
| * [latest-unraid](https://hub.docker.com/r/11notes/kms-gui/tags?name=latest-unraid) | ||||
|  | ||||
| # UNRAID VERSION 🟠 | ||||
| This image supports unraid by default. Simply add **-unraid** to any tag and the image will run as 99:100 instead of 1000:1000 causing no issues on unraid. Enjoy. | ||||
|  | ||||
|  | ||||
|  | ||||
| # SYNOPSIS 📖 | ||||
| **What can I do with this?** This image will run a web GUI for your [11notes/kms](https://hub.docker.com/r/11notes/kms) server. | ||||
| @@ -15,7 +28,7 @@ | ||||
| name: "kms" | ||||
| services: | ||||
|   kms: | ||||
|     image: "11notes/kms:latest" | ||||
|     image: "11notes/kms:stable" | ||||
|     container_name: "kms" | ||||
|     environment: | ||||
|       TZ: Europe/Zurich | ||||
| @@ -25,7 +38,7 @@ services: | ||||
|       - "1688:1688/tcp" | ||||
|     restart: always | ||||
|   kms-gui: | ||||
|     image: "11notes/kms-gui:646f476" | ||||
|     image: "11notes/kms-gui:465f4d1" | ||||
|     container_name: "kms-gui" | ||||
|     environment: | ||||
|       TZ: Europe/Zurich | ||||
| @@ -38,25 +51,42 @@ volumes: | ||||
|   var: | ||||
| ``` | ||||
|  | ||||
| # DEFAULT SETTINGS 🗃️ | ||||
| | Parameter | Value | Description | | ||||
| | --- | --- | --- | | ||||
| | `user` | docker | user name | | ||||
| | `uid` | 1000 | [user identifier](https://en.wikipedia.org/wiki/User_identifier) | | ||||
| | `gid` | 1000 | [group identifier](https://en.wikipedia.org/wiki/Group_identifier) | | ||||
| | `home` | /kms | home directory of user docker | | ||||
|  | ||||
| # ENVIRONMENT 📝 | ||||
| | Parameter | Value | Default | | ||||
| | --- | --- | --- | | ||||
| | `TZ` | [Time Zone](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones) | | | ||||
| | `DEBUG` | Show debug messages from image **not** app | | | ||||
| | `DEBUG` | Will activate debug option for container image and app (if available) | | | ||||
| | `KMS_GUI_STYLE` | switch the UI style of the webinterface (py-kms, custom-icon) | custom-icon | | ||||
|  | ||||
| # SOURCE 💾 | ||||
| * [11notes/kms-gui](https://github.com/11notes/docker-kms-gui) | ||||
|  | ||||
| # PARENT IMAGE 🏛️ | ||||
| * [11notes/kms:646f476](https://hub.docker.com/r/11notes/kms) | ||||
| * [11notes/kms:465f4d1](https://hub.docker.com/r/11notes/kms) | ||||
|  | ||||
| # BUILT WITH 🧰 | ||||
| * [py-kms](https://github.com/Py-KMS-Organization/py-kms) | ||||
| * [alpine](https://alpinelinux.org) | ||||
| * [CustomIcon/pykms-frontend](https://github.com/CustomIcon/pykms-frontend) | ||||
|  | ||||
| # GENERAL TIPS 📌 | ||||
| * Use a reverse proxy like Traefik, Nginx, HAproxy to terminate TLS and to protect your endpoints | ||||
| * Use Let’s Encrypt DNS-01 challenge to obtain valid SSL certificates for your services | ||||
|  | ||||
| # SECURITY VULNERABILITIES REPORT ⚡ | ||||
| | Severity | Package | Version | Fix Version | Type | Location | Data Namespace | Link | | ||||
| | --- | --- | --- | --- | --- | --- | --- | --- | | ||||
| | 4.7 (Medium) | linux-pam  | 1.6.1-r1  |   | apk  | /lib/apk/db/installed  | nvd:cpe  | [CVE-2024-10041](https://nvd.nist.gov/vuln/detail/CVE-2024-10041)  | | ||||
|  | ||||
|  | ||||
| # TIPS 📌 | ||||
| * Use a reverse proxy like Traefik, Nginx, HAproxy to terminate TLS with a valid certificate | ||||
| * Use Let’s Encrypt certificates to protect your SSL endpoints | ||||
|    | ||||
| # ElevenNotes™️ | ||||
| This image is provided to you at your own risk. Always make backups before updating an image to a different version. Check the [releases](https://github.com/11notes/docker-kms-gui/releases) for breaking changes. If you have any problems with using this image simply raise an [issue](https://github.com/11notes/docker-kms-gui/issues), thanks . You can find all my repositories on [github](https://github.com/11notes?tab=repositories). | ||||
| This image is provided to you at your own risk. Always make backups before updating an image to a different version. Check the [releases](https://github.com/11notes/docker-kms-gui/releases) for breaking changes. If you have any problems with using this image simply raise an [issue](https://github.com/11notes/docker-kms-gui/issues), thanks. If you have a question or inputs please create a new [discussion](https://github.com/11notes/docker-kms-gui/discussions) instead of an issue. You can find all my other repositories on [github](https://github.com/11notes?tab=repositories). | ||||
|  | ||||
| *created Fri, 21 Feb 2025 06:05:47 GMT* | ||||
| @@ -1,2 +0,0 @@ | ||||
| ### 🪄 Features | ||||
| * add DEBUG option via enivornment variable DEBUG | ||||
| @@ -1,7 +1,16 @@ | ||||
| ARG APP_VERSION=stable | ||||
| ARG APP_VERSION_PREFIX="" | ||||
| ARG APP_VERSION_SUFFIX="" | ||||
|  | ||||
| # :: Build / styles | ||||
|   FROM alpine/git AS styles | ||||
|   ARG APP_NO_CACHE | ||||
|   RUN set -ex; \ | ||||
|     git clone https://github.com/11notes/pykms-frontend.git; \ | ||||
|     cd /git/pykms-frontend; | ||||
|  | ||||
| # :: Header | ||||
|   FROM 11notes/kms:${APP_VERSION} | ||||
|   FROM 11notes/kms:${APP_VERSION_PREFIX}${APP_VERSION}${APP_VERSION_SUFFIX} | ||||
|  | ||||
|   # :: arguments | ||||
|     ARG TARGETARCH | ||||
| @@ -9,6 +18,8 @@ ARG APP_VERSION=stable | ||||
|     ARG APP_NAME | ||||
|     ARG APP_VERSION | ||||
|     ARG APP_ROOT | ||||
|     ARG APP_UID | ||||
|     ARG APP_GID | ||||
|  | ||||
|   # :: environment | ||||
|     ENV APP_IMAGE=${APP_IMAGE} | ||||
| @@ -16,6 +27,8 @@ ARG APP_VERSION=stable | ||||
|     ENV APP_VERSION=${APP_VERSION} | ||||
|     ENV APP_ROOT=${APP_ROOT} | ||||
|  | ||||
|     ENV KMS_GUI_STYLE="custom-icon" | ||||
|  | ||||
|     ENV PYKMS_SQLITE_DB_PATH=/kms/var/kms.db | ||||
|     ENV PYKMS_LICENSE_PATH=/opt/py-kms/LICENSE | ||||
|     ENV PYKMS_VERSION_PATH=/opt/py-kms/VERSION | ||||
| @@ -27,6 +40,7 @@ ARG APP_VERSION=stable | ||||
|  | ||||
|   # :: Run | ||||
|   USER root | ||||
|   RUN eleven printenv; | ||||
|  | ||||
|   # :: install application | ||||
|     RUN set -ex; \ | ||||
| @@ -41,11 +55,25 @@ ARG APP_VERSION=stable | ||||
|       pip3 install --no-cache-dir -r /opt/py-kms/requirements.gui.txt --break-system-packages; \ | ||||
|       apk del --no-network .build; | ||||
|  | ||||
|   # :: copy filesystem changes and set correct permissions | ||||
|     COPY ./rootfs / | ||||
|   # :: copy filesystem changes | ||||
|     COPY ./rootfs /       | ||||
|  | ||||
|   # :: add multi template option | ||||
|     RUN set -ex; \ | ||||
|       mkdir -p ${APP_ROOT}/styles/py-kms; \ | ||||
|       mkdir -p ${APP_ROOT}/styles/custom-icon; \ | ||||
|       cp -R /opt/py-kms/templates ${APP_ROOT}/styles/py-kms; \ | ||||
|       cp -R /opt/py-kms/static ${APP_ROOT}/styles/py-kms; \ | ||||
|       rm -rf /opt/py-kms/templates; \ | ||||
|       rm -rf /opt/py-kms/static; | ||||
|      | ||||
|     COPY --from=styles /git/pykms-frontend/templates ${APP_ROOT}/styles/custom-icon/templates | ||||
|     COPY --from=styles /git/pykms-frontend/static ${APP_ROOT}/styles/custom-icon/static | ||||
|  | ||||
|   # :: set correct permissions | ||||
|     RUN set -ex; \ | ||||
|       chmod +x -R /usr/local/bin; \ | ||||
|       chown -R 1000:1000 \ | ||||
|       chown -R ${APP_UID}:${APP_GID} \ | ||||
|         ${APP_ROOT} \ | ||||
|         /opt/py-kms; | ||||
|  | ||||
|   | ||||
| @@ -1,7 +1,7 @@ | ||||
| name: "kms" | ||||
| services: | ||||
|   kms: | ||||
|     image: "11notes/kms:latest" | ||||
|     image: "11notes/kms:stable" | ||||
|     container_name: "kms" | ||||
|     environment: | ||||
|       TZ: Europe/Zurich | ||||
| @@ -11,7 +11,7 @@ services: | ||||
|       - "1688:1688/tcp" | ||||
|     restart: always | ||||
|   kms-gui: | ||||
|     image: "11notes/kms-gui:646f476" | ||||
|     image: "11notes/kms-gui:465f4d1" | ||||
|     container_name: "kms-gui" | ||||
|     environment: | ||||
|       TZ: Europe/Zurich | ||||
|   | ||||
							
								
								
									
										
											BIN
										
									
								
								img/GUI.png
									
									
									
									
									
								
							
							
						
						
									
										
											BIN
										
									
								
								img/GUI.png
									
									
									
									
									
								
							
										
											Binary file not shown.
										
									
								
							| Before Width: | Height: | Size: 52 KiB | 
							
								
								
									
										
											BIN
										
									
								
								img/webGUICustomIcon.png
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										
											BIN
										
									
								
								img/webGUICustomIcon.png
									
									
									
									
									
										Normal file
									
								
							
										
											Binary file not shown.
										
									
								
							| After Width: | Height: | Size: 38 KiB | 
							
								
								
									
										18
									
								
								project.md
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										18
									
								
								project.md
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,18 @@ | ||||
|  | ||||
|  | ||||
| ${{ content_synopsis }} This image will run a web GUI for your [11notes/kms](https://hub.docker.com/r/11notes/kms) server. | ||||
|  | ||||
| ${{ content_compose }} | ||||
|  | ||||
| ${{ content_defaults }} | ||||
|  | ||||
| ${{ content_environment }} | ||||
| | `KMS_GUI_STYLE` | switch the UI style of the webinterface (py-kms, custom-icon) | custom-icon | | ||||
|  | ||||
| ${{ content_source }} | ||||
|  | ||||
| ${{ content_parent }} | ||||
|  | ||||
| ${{ content_built }} | ||||
|  | ||||
| ${{ content_tips }} | ||||
							
								
								
									
										
											BIN
										
									
								
								rootfs/opt/py-kms/static/favicon.ico
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										
											BIN
										
									
								
								rootfs/opt/py-kms/static/favicon.ico
									
									
									
									
									
										Normal file
									
								
							
										
											Binary file not shown.
										
									
								
							| After Width: | Height: | Size: 4.2 KiB | 
							
								
								
									
										45
									
								
								rootfs/opt/py-kms/templates/base.html
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										45
									
								
								rootfs/opt/py-kms/templates/base.html
									
									
									
									
									
										Normal file
									
								
							| @@ -0,0 +1,45 @@ | ||||
| <!DOCTYPE html> | ||||
| <html lang="en"> | ||||
| <head> | ||||
|     <meta charset="UTF-8"> | ||||
|     <title>py-kms {% block title %}{% endblock %}</title> | ||||
|     <link rel="icon" type="image/x-icon" href="{{ url_for('static', filename= 'favicon.ico') }}"> | ||||
|     <link rel="stylesheet" href="{{ url_for('static', filename= 'css/bulma.min.css') }}"> | ||||
|     <style> | ||||
|         #content { | ||||
|             margin: 1em; | ||||
|             overflow-x: auto; | ||||
|         } | ||||
|         pre { | ||||
|             overflow-x: auto; | ||||
|             padding: 0.5em; | ||||
|         } | ||||
|         {% if path != '/' %} | ||||
|         div.backtohome { | ||||
|             display: flex; | ||||
|             justify-content: center; | ||||
|         } | ||||
|         {% endif %} | ||||
|         {% block style %}{% endblock %} | ||||
|     </style> | ||||
| </head> | ||||
| <body> | ||||
|     <div id="content"> | ||||
|         {% block content %}{% endblock %} | ||||
|  | ||||
|         {% if path != '/' %} | ||||
|         <div class="block backtohome"> | ||||
|             <a class="button is-normal is-responsive" href="/"> | ||||
|                 Back to home | ||||
|             </a> | ||||
|         </div> | ||||
|         {% endif %} | ||||
|     </div> | ||||
|  | ||||
|     <script> | ||||
|         for(let element of document.getElementsByClassName('convert_timestamp')) { | ||||
|             element.innerText = new Date(element.innerText).toLocaleString(); | ||||
|         } | ||||
|     </script> | ||||
| </body> | ||||
| </html> | ||||
| @@ -38,12 +38,6 @@ th { | ||||
|             <p class="title">{{ count_clients_office }}</p> | ||||
|         </div> | ||||
|     </div> | ||||
|     <div class="level-item has-text-centered"> | ||||
|         <div> | ||||
|             <p class="heading">Products</p> | ||||
|             <p class="title"><a href="/products">{{ count_projects }}</a></p> | ||||
|         </div> | ||||
|     </div> | ||||
| </nav> | ||||
|  | ||||
| <hr> | ||||
| @@ -54,6 +48,7 @@ th { | ||||
|         <tr> | ||||
|             <th>Client ID</th> | ||||
|             <th>Machine Name</th> | ||||
|             <th>Machine IP</th> | ||||
|             <th>Application ID</th> | ||||
|             <th><abbr title="Stock Keeping Unit">SKU</abbr> ID</th> | ||||
|             <th>License Status</th> | ||||
| @@ -67,6 +62,7 @@ th { | ||||
|         <tr> | ||||
|             <th><pre class="clientMachineId">{{ client.clientMachineId }}</pre></th> | ||||
|             <td class="machineName">{{ client.machineName }}</td> | ||||
|             <td>{{ client.machineIp }}</td> | ||||
|             <td>{{ client.applicationId }}</td> | ||||
|             <td>{{ client.skuId }}</td> | ||||
|             <td>{{ client.licenseStatus }}</td> | ||||
|   | ||||
| @@ -6,6 +6,23 @@ | ||||
|       eleven log debug "setting kms-gui log level to DEBUG" | ||||
|     fi | ||||
|  | ||||
|     # apply correct style | ||||
|     rm -rf /opt/py-kms/templates | ||||
|     rm -rf /opt/py-kms/static | ||||
|     TEMPLATE_DIR=${APP_ROOT}/styles | ||||
|     case ${KMS_GUI_STYLE} in | ||||
|       py-kms) | ||||
|         ln -s ${TEMPLATE_DIR}/py-kms/templates /opt/py-kms/templates | ||||
|         ln -s ${TEMPLATE_DIR}/py-kms/static /opt/py-kms/static | ||||
|         eleven log info "using ${KMS_GUI_STYLE} GUI style" | ||||
|       ;; | ||||
|       *) | ||||
|         ln -s ${TEMPLATE_DIR}/custom-icon/templates /opt/py-kms/templates | ||||
|         ln -s ${TEMPLATE_DIR}/custom-icon/static /opt/py-kms/static | ||||
|         eleven log info "using custom-icon (default) GUI style" | ||||
|       ;; | ||||
|     esac | ||||
|  | ||||
|     cd /opt/py-kms | ||||
|     set -- "gunicorn" \ | ||||
|       --log-level ${LOG_LEVEL} \ | ||||
|   | ||||
		Reference in New Issue
	
	Block a user