Skip to content

Commit e1186b3

Browse files
committed
syntax and readme updates
1 parent dd62b8e commit e1186b3

4 files changed

Lines changed: 13 additions & 12 deletions

File tree

Dockerfile

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
# syntax=docker/dockerfile:1
2+
13
FROM ghcr.io/linuxserver/baseimage-selkies:arch
24

35
# set version label
@@ -29,4 +31,4 @@ RUN \
2931
COPY /root /
3032

3133
# ports and volumes
32-
EXPOSE 3000
34+
EXPOSE 3001

Dockerfile.aarch64

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,5 @@
1+
# syntax=docker/dockerfile:1
2+
13
FROM ghcr.io/linuxserver/baseimage-selkies:arm64v8-arch
24

35
# set version label
@@ -29,4 +31,4 @@ RUN \
2931
COPY /root /
3032

3133
# ports and volumes
32-
EXPOSE 3000
34+
EXPOSE 3001

README.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,8 @@ By default, this container has no authentication. The optional `CUSTOM_USER` and
7878

7979
The web interface includes a terminal with passwordless `sudo` access. Any user with access to the GUI can gain root control within the container, install arbitrary software, and probe your local network.
8080

81+
While not generally recommended, certain legacy environments specifically those with older hardware or outdated Linux distributions may require the deactivation of the standard seccomp profile to get containerized desktop software to run. This can be achieved by utilizing the `--security-opt seccomp=unconfined` parameter. It is critical to use this option only when absolutely necessary as it disables a key security layer of Docker, elevating the potential for container escape vulnerabilities.
82+
8183
### Options in all Selkies-based GUI containers
8284

8385
This container is based on [Docker Baseimage Selkies](https://github.com/linuxserver/docker-baseimage-selkies), which provides the following environment variables and run configurations to customize its functionality.
@@ -220,8 +222,6 @@ services:
220222
darktable:
221223
image: lscr.io/linuxserver/darktable:latest
222224
container_name: darktable
223-
security_opt:
224-
- seccomp:unconfined #optional
225225
environment:
226226
- PUID=1000
227227
- PGID=1000
@@ -231,6 +231,7 @@ services:
231231
ports:
232232
- 3000:3000
233233
- 3001:3001
234+
shm_size: "1gb"
234235
restart: unless-stopped
235236
```
236237
@@ -239,13 +240,13 @@ services:
239240
```bash
240241
docker run -d \
241242
--name=darktable \
242-
--security-opt seccomp=unconfined `#optional` \
243243
-e PUID=1000 \
244244
-e PGID=1000 \
245245
-e TZ=Etc/UTC \
246246
-p 3000:3000 \
247247
-p 3001:3001 \
248248
-v /path/to/config:/config \
249+
--shm-size="1gb" \
249250
--restart unless-stopped \
250251
lscr.io/linuxserver/darktable:latest
251252
```
@@ -262,7 +263,7 @@ Containers are configured using parameters passed at runtime (such as those abov
262263
| `-e PGID=1000` | for GroupID - see below for explanation |
263264
| `-e TZ=Etc/UTC` | specify a timezone to use, see this [list](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones#List). |
264265
| `-v /config` | Users home directory in the container, stores program settings and images |
265-
| `--security-opt seccomp=unconfined` | For Docker Engine only, many modern gui apps need this to function on older hosts as syscalls are unknown to Docker. |
266+
| `--shm-size=` | Recommended for all desktop images. |
266267

267268
## Environment variables from files (Docker secrets)
268269

readme-vars.yml

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -17,19 +17,15 @@ development_versions: false
1717
# container parameters
1818
common_param_env_vars_enabled: true
1919
param_container_name: "{{ project_name }}"
20-
param_usage_include_env: true
21-
param_env_vars:
22-
- {env_var: "TZ", env_value: "Europe/London", desc: "Specify a timezone to use EG Europe/London."}
2320
param_usage_include_vols: true
2421
param_volumes:
2522
- {vol_path: "/config", vol_host_path: "/path/to/config", desc: "Users home directory in the container, stores program settings and images"}
2623
param_usage_include_ports: true
2724
param_ports:
2825
- {external_port: "3000", internal_port: "3000", port_desc: "Darktable desktop gui HTTP, must be proxied."}
2926
- {external_port: "3001", internal_port: "3001", port_desc: "Darktable desktop gui HTTPS."}
30-
opt_security_opt_param: true
31-
opt_security_opt_param_vars:
32-
- {run_var: "seccomp=unconfined", compose_var: "seccomp:unconfined", desc: "For Docker Engine only, many modern gui apps need this to function on older hosts as syscalls are unknown to Docker."}
27+
custom_params:
28+
- {name: "shm-size", name_compose: "shm_size", value: "1gb", desc: "Recommended for all desktop images."}
3329
# Selkies blurb settings
3430
selkies_blurb: true
3531
show_nvidia: true

0 commit comments

Comments
 (0)