Author SHA1 Message Date
snyk-bot c695a66506 fix: Dockerfile to reduce vulnerabilities
The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-ALPINE322-OPENSSL-10597997
- https://snyk.io/vuln/SNYK-ALPINE322-OPENSSL-10597997
2025-07-21 09:03:57 +00:00
Swarup Sengupta 25e08e3bda updated the readme 2025-06-29 03:46:52 +05:30
Swarup Sengupta 02fe2a0c63 Pulled build script out of Dockerfile to facilitate native builds, changed the base image from alpine-s6 to alpine and used tini as entrypoint 2025-06-29 03:34:37 +05:30
Swarup Sengupta 1e6b14afba Pulled build script out of Dockerfile to facilitate native builds, changed the base image from alpine-s6 to alpine and used tini as entrypoint 2025-06-29 03:34:15 +05:30
Swarup Sengupta e12ac86da7 Updated README with few steps 2025-04-05 03:09:36 +05:30
Swarup Sengupta d62b101336 Updated Dockerfile to use heredoc syntax, make.bash for latest psiphon release 2025-04-05 03:03:10 +05:30
swarupsengupta2007 b2d368dedd updated readme 2024-12-27 22:28:53 +05:30
swarupsengupta2007 5652183e5c updated readme 2024-12-27 22:28:12 +05:30
swarupsengupta2007 f72f5ddbea updated readme 2024-12-27 22:27:00 +05:30
swarupsengupta2007 044298117f removed default psiphon version, use make.bash instead 2024-12-27 22:09:35 +05:30
swarupsengupta2007 ac82876e54 Added heath-check to containers, upgraded psiphon to 2.0.31 2024-12-27 21:37:40 +05:30
swarupsengupta2007 f64df60fe0 updated README to include helper script decumentation 2024-05-04 20:25:11 +05:30
swarupsengupta2007 2065b1d62e updated README to include helper script decumentation 2024-05-04 20:24:40 +05:30
swarupsengupta2007 a464d3b418 updated README to include helper script decumentation 2024-05-04 20:23:54 +05:30
swarupsengupta2007 4fd631a9d3 modified make.bash to take arguments as environemt variables 2024-05-04 19:32:40 +05:30
swarupsengupta2007 33b0888580 modified Dockerfile to accept go version as build arg 2024-05-04 01:54:41 +05:30
swarupsengupta2007 5a1caa3f40 bumped go to 1.20, psiphon to 2.0.30 2024-05-04 01:43:14 +05:30
swarupsengupta2007 b7c19a8c13 added exitcode for container restart on psiphon restart 2023-06-28 22:47:41 +05:30
9 changed files with 391 additions and 61 deletions
+35 -32
View File
@@ -1,40 +1,43 @@
ARG BUILDPLATFORM=$BUILDPLATFORM
FROM --platform=$BUILDPLATFORM golang:1.18 AS psiphon_builder
ARG GO_VERSION=1.24.1
FROM --platform=$BUILDPLATFORM golang:$GO_VERSION AS psiphon_builder
WORKDIR /go
LABEL stage=builder
ARG VERSION=2.0.23
ARG BUILDOS
ARG BUILDARCH
ARG TARGETS
ENV DIR=/go/src/github.com/Psiphon-Labs/psiphon-tunnel-core \
GO111MODULE=off \
CGO_ENABLED=0
SHELL ["/bin/bash", "-c"]
RUN TARGET_PALTFORMS=${TARGETS:-"$BUILDOS/$BUILDARCH"} && \
mkdir -p ${DIR} && \
curl -sL https://github.com/Psiphon-Labs/psiphon-tunnel-core/archive/refs/tags/v${VERSION}.tar.gz | \
tar xz -C ${DIR} --strip-components=1 && \
(IFS=','; for PLATFORM in $TARGET_PALTFORMS; \
do \
OS=${PLATFORM%%/*} && \
ARCH=${PLATFORM#*/} && \
ARCH=${ARCH%/*} && \
VERSION=${PLATFORM##*/} && \
TARGETVARIANT=${VERSION/$ARCH/} && \
VERSION=${TARGETVER/v/} && \
GOOS=${OS} GOARCH=${ARCH} go install -a -tags netgo \
-ldflags '-w -extldflags "-static"' \
github.com/Psiphon-Labs/psiphon-tunnel-core/ConsoleClient && \
BINARY=$(find /go/bin/* -name "ConsoleClient*") && \
mv ${BINARY} /go/psiphon_${OS}_${ARCH}_${TARGETVARIANT}; \
done)
ARG PSIPHON_VERSION
ADD build.sh latest_version.sh /go/
RUN <<__SCRIPT__
ARGS=""
if [ -n "${TARGETS}" ]; then
ARGS="${ARGS} --targets ${TARGETS}"
fi
if [ -n "${PSIPHON_VERSION}" ]; then
ARGS="${ARGS} --version ${PSIPHON_VERSION}"
fi
/go/build.sh ${ARGS}
__SCRIPT__
FROM swarupsengupta2007/alpine-s6:3.16.0
FROM alpine:3.22.1
ARG TARGETOS
ARG TARGETARCH
ARG TARGETVARIANT
COPY base/ /
COPY psiphon.config ${DEF_DEFAULTS}
COPY --from=psiphon_builder /go/psiphon_${TARGETOS}_${TARGETARCH}_${TARGETVARIANT} ${DEF_APP}/psiphon
EXPOSE 8080 1080
VOLUME /config
RUN --mount=type=bind,from=psiphon_builder,source=/go/dist,target=/tmp/psiphon \
--mount=type=bind,source=./assets,target=/tmp/assets \
<<__SCRIPT__
apk add --no-cache tini
cp /tmp/assets/start-psiphon /usr/local/bin/start-psiphon
cp /tmp/assets/healtcheck /usr/local/bin/healtcheck
mkdir -p /etc/psiphon
cp /tmp/assets/psiphon.config /etc/psiphon/psiphon.config
if [ -z "${TARGETVARIANT}" ]; then
cp /tmp/psiphon/psiphon_${TARGETOS}_${TARGETARCH} /usr/local/bin/psiphon
else
cp /tmp/psiphon/psiphon_${TARGETOS}_${TARGETARCH}_${TARGETVARIANT} /usr/local/bin/psiphon
fi
chmod +x /usr/local/bin/start-psiphon
chmod +x /usr/local/bin/healtcheck
chmod +x /usr/local/bin/psiphon
__SCRIPT__
ENTRYPOINT ["/sbin/tini", "--"]
CMD ["/usr/local/bin/start-psiphon"]
HEALTHCHECK --interval=30s --timeout=5s --start-period=2m --retries=3 CMD healtcheck
+31 -14
View File
@@ -7,7 +7,6 @@ This docker image runs the ConsoleClient from the [psiphon-tunnel-core](https://
> This build uses `docker buildx` plugin with `docker-container` driver. <br>
> Docker image available at [swarupsengupta2007/psiphon](https://hub.docker.com/r/swarupsengupta2007/psiphon "swarupsengupta2007/psiphon"). <br>
> This is built on base image from [swarupsengupta2007/apine-s6-docker](https://github.com/swarupsengupta2007/alpine-s6-docker "swarupsengupta2007/apine-s6-docker")
```bash
# Clone this repo
@@ -29,16 +28,19 @@ docker buildx create --name cross-platform --platform ${TARGETS} --use
# Build for current platform and load to docker image
docker buildx build -t <your_tag> . --load
# build for multi-arch and push to registry
docker buildx build --build-arg TARGETS=${TARGETS} -t <your_username>/<your_tag> \
--platform ${TARGETS} . --push
# If not already done, install the required cross-platform emulators
docker run --privileged --rm tonistiigi/binfmt --install all
# run the script, this will build the image for current platform and load it to docker
./make.bash --load
```
Build-args available
|build-arg|default|Description|
|build-arg|Description|Default|
|--|--|--|
|VERSION|2.0.23|psiphon-tunnel-core release version|
|TARGETS|\<BUIDLOS\>/\<BUILDARCH\>|Targets for cross-compilation for the build stage|
|VERSION|psiphon-tunnel-core release version|latest|
|TARGETS|\<BUIDLOS\>/\<BUILDARCH\> (Targets for cross-compilation for the build stage)|current platform|
|GO_VERSION|Go version to use for building the psiphon-tunnel-core binary|1.22.7|
---
# Usage
@@ -53,6 +55,10 @@ services:
environment:
- PUID=1000
- PGID=1000
- HTTP_PORT=8080
- SOCKS_PORT=1080
- DEVICE_REGION=IN
- EGRESS_REGION=SG
volumes:
- /path/to/psiphon/config:/config
ports:
@@ -68,19 +74,30 @@ docker run -d \
--restart=unless-stopped \
-p 8080:8080 \
-p 1080:1080 \
-e HTTP_PORT=8080 \
-e SOCKS_PORT=1080 \
-e DEVICE_REGION=IN \
-e EGRESS_REGION=SG \
-v /home/swarup/psiphon/config/:/config \
swarupsengupta2007/psiphon
```
The following Environment var are available<br>
The following Environment var are available (only applicable when running for the first tome with no psiphon.config in the mounted config directory)<br>
|ENV variable|Description|Default|
|--|--|--|
|PUID|The UID for psiphon process|1000|
|PGID|The GID for psiphon process|1000|
|HTTP_PORT|The HTTP proxy port|8080|
|SOCKS_PORT|The SOCKS proxy port|1080|
|DEVICE_REGION|The device region for psiphon client|IN|
|EGRESS_REGION|The egress region for psiphon client|SG|
Following ports and volumes are available
|Option|switch|Description|Default|
|--|--|--|--|
|HTTP PORT|-p <host_port>:8080|http proxy port|8080|
|SOCKS PORT|-p <host_port>:1080|socks proxy port|1080|
|VOLUME|-v /path/to/config:/config|The container storage|/config|
# Configuration
The psiphon client configuration is stored in the mounted config directory. /config must be mounted and writable by the psiphon process. <br>
# Healthcheck
The container has a healthcheck script that checks if the psiphon client is running and healthy. <br>
You can check the health status of the container using the following command:
```bash
docker inspect --format='{{json .State.Health}}' psiphon
```
+12
View File
@@ -0,0 +1,12 @@
#/bin/sh
if [ ! -d /config ]; then
exit 1
fi
if [ ! -f /config/psiphon.config ]; then
exit 1
else
HTTP_PORT=$(sed -n -E 's/.*"LocalHttpProxyPort"[[:space:]]*:[[:space:]]*([0-9]+).*/\1/p' /config/psiphon.config)
netstat -ltn | grep ${HTTP_PORT} || exit 1
fi
@@ -1,6 +1,7 @@
{
"DataRootDirectory": "/config/",
"DeviceRegion": "IN",
"EgressRegion": "SG",
"MigrateDataStoreDirectory": "/config",
"ListenInterface": "any",
"LocalHttpProxyPort": 8080,
+46
View File
@@ -0,0 +1,46 @@
#!/bin/sh
if [ ! -d /config ]; then
echo "/config directory not mounted, exiting..."
exit 1
fi
if [ ! -f /config/psiphon.config ]; then
cp /etc/psiphon/psiphon.config /config/psiphon.config
if [ -n "${HTTP_PORT}" ]; then
sed -i -E 's/"LocalHttpProxyPort"[[:space:]]*:[[:space:]]*[0-9]+/"LocalHttpProxyPort": '${HTTP_PORT}'/' /config/psiphon.config
fi
if [ -n "${SOCKS_PORT}" ]; then
sed -i -E 's/"LocalSocksProxyPort"[[:space:]]*:[[:space:]]*[0-9]+/"LocalSocksProxyPort": '${SOCKS_PORT}'/' /config/psiphon.config
fi
if [ -n "${DEVICE_REGION}" ]; then
sed -i -E 's/"DeviceRegion"[[:space:]]*:[[:space:]]*"[^"]*"/"DeviceRegion": "'${DEVICE_REGION}'"/' /config/psiphon.config
fi
if [ -n "${EGRESS_REGION}" ]; then
sed -i -E 's/"EgressRegion"[[:space:]]*:[[:space:]]*"[^"]*"/"EgressRegion": "'${EGRESS_REGION}'"/' /config/psiphon.config
fi
fi
id psiphon > /dev/null 2>&1
if [ $? -ne 0 ]; then
adduser -DH psiphon psiphon
fi
UID=$(id -u psiphon)
GID=$(id -g psiphon)
PUID=${PUID:-${UID}}
PGID=${PGID:-${GID}}
if [ "${PUID}" != "${UID}" ] || [ "${PGID}" != "${GID}" ]; then
deluser psiphon >/dev/null 2>&1 || true
delgroup psiphon >/dev/null 2>&1 || true
addgroup -g ${PGID} psiphon
adduser -DH -u ${PUID} -G psiphon psiphon
fi
chown -R psiphon:psiphon /config
su -s /bin/sh psiphon <<EOF
psiphon -config /config/psiphon.config
EOF
-7
View File
@@ -1,7 +0,0 @@
#!/usr/bin/with-contenv sh
[[ ! -f ${DEF_CONFIG}/psiphon.config ]] && cp ${DEF_DEFAULTS}/psiphon.config ${DEF_CONFIG}/
chown -R ${DEF_USER}:${DEF_USER} ${DEF_CONFIG}
exec s6-setuidgid ${DEF_USER} ${DEF_APP}/psiphon -config ${DEF_CONFIG}/psiphon.config
Executable
+97
View File
@@ -0,0 +1,97 @@
#!/usr/bin/env bash
set -euo pipefail
IFS=$'\n\t'
GO=${GO:-go}
PSIPHON_VERSION=""
TARGETS=""
function help_message() {
echo "Usage: $0 [OPTIONS] <psiphon_version>"
echo "Options:"
echo " --targets <targets> Comma-separated list of target platforms (default: current platform)"
echo " --version <version> Psiphon version to build (default: latest)"
exit ${1:-1}
}
while [[ $# -gt 0 ]]; do
case $1 in
--help|-h)
help_message 0
;;
--targets=*)
TARGETS="${1#*=}"
shift
;;
-t | --targets)
TARGETS="${2}"
shift 2
;;
--version=*)
PSIPHON_VERSION="${1#*=}"
shift
;;
-v | --version)
PSIPHON_VERSION="${2}"
shift 2
;;
*)
echo "Unknown option: $1"
help_message
;;
esac
done
MYPATH=$(dirname "$(readlink -f "$0")")
source "${MYPATH}/latest_version.sh"
if [[ -z "${PSIPHON_VERSION}" ]]; then
PSIPHON_VERSION=$(get_latest_version)
else
if ! validate_version_format "${PSIPHON_VERSION}"; then
echo "Invalid Psiphon version format. Please use 'X.Y.Z' or 'vX.Y.Z' format."
exit 1
fi
fi
PSIPHON_VERSION=$(normalize_version "${PSIPHON_VERSION}")
ALL_TARGETS="linux/amd64,linux/386,linux/arm64,linux/arm/v7,linux/arm/v6,windows/amd64,windows/386,darwin/amd64,darwin/arm64"
CURRENT_TARGET="$(go env GOOS)/$(go env GOARCH)"
TARGETS=${TARGETS:-"current"}
TARGETS=$(decipher_targets "${TARGETS}")
TARGETS=${TARGETS//,/ }
BUILD_DIR=$(pwd)/tmp_build_$$
rm -rf "${BUILD_DIR}"
mkdir -p "${BUILD_DIR}"
trap 'rm -rf "${BUILD_DIR}"' EXIT
BIN_DIR="$(pwd)/dist"
rm -rf "${BIN_DIR}"
mkdir -p "${BIN_DIR}"
curl -sL https://github.com/Psiphon-Labs/psiphon-tunnel-core/archive/refs/tags/${PSIPHON_VERSION}.tar.gz | tar xz --strip-components=1 -C "${BUILD_DIR}"
pushd "${BUILD_DIR}/ConsoleClient" > /dev/null
export CGO_ENABLED=0
for PLATFORM in ${TARGETS}
do
IFS='/' read -r OS ARCH VARIANT <<< "${PLATFORM}"
export GOOS=${OS}
export GOARCH=${ARCH}
if [[ -n "${VARIANT}" ]]; then
export GOARM=${VARIANT#v}
fi
GOEXT=""
if [[ "${OS}" == "windows" ]]; then
GOEXT=".exe"
fi
${GO} build -a -tags netgo -ldflags "-s -w -extldflags '-static'" -o "${BIN_DIR}/psiphon_${PLATFORM//\//_}${GOEXT}"
unset GOOS GOARCH GOARM
done
popd > /dev/null
+63
View File
@@ -0,0 +1,63 @@
#!/usr/bin/env bash
set -euo pipefail
IFS=$'\n\t'
# This file can only be sourced, not executed directly.
if [[ "${BASH_SOURCE[0]}" == "${0}" ]]; then
echo "This script is intended to be sourced, not executed directly." >&2
exit 1
fi
function validate_version_format() {
local v="$1"
[[ "${v}" =~ ^v?[0-9]+\.[0-9]+\.[0-9]+$ ]]
}
function get_latest_version() {
local json version
json="$(curl -fsSL https://api.github.com/repos/Psiphon-Labs/psiphon-tunnel-core/releases/latest)"
if command -v jq >/dev/null 2>&1; then
version="$(printf '%s' "${json}" | jq -r .tag_name)"
else
version="$(printf '%s' "${json}" \
| grep -m1 '"tag_name":' \
| sed -E 's/.*"tag_name": ?"([^"]+)".*/\1/')"
fi
if ! validate_version_format "${version}"; then
echo "I tried to get the latest version of Psiphon without jq but it didn't work." >&2
echo "Please install jq or specify the version manually." >&2
exit 1
fi
printf '%s\n' "${version}"
}
function normalize_version() {
local v="$1"
if [[ "${v}" =~ ^v ]]; then
echo "${v}"
else
echo "v${v}"
fi
}
function get_supported_targets() {
echo "linux/amd64,linux/386,linux/arm64,linux/arm/v7,linux/arm/v6"
}
function get_current_target() {
echo "$(go env GOOS)/$(go env GOARCH)"
}
function decipher_targets() {
local targets="$1"
if [[ "${targets}" == "current" ]]; then
echo "$(get_current_target)"
elif [[ "${targets}" == "all" ]]; then
echo "$(get_supported_targets)"
else
echo "${targets}"
fi
}
+106 -8
View File
@@ -1,11 +1,109 @@
#!/bin/bash
#!/usr/bin/env bash
TARGETS="linux/amd64,linux/386,linux/arm64,linux/arm/v7,linux/arm/v6"
VERSION=2.0.29
set -euo pipefail
IFS=$'\n\t'
sudo docker buildx build \
--build-arg TARGETS=${TARGETS} \
--build-arg VERSION=${VERSION} \
-t swarupsengupta2007/psiphon:${VERSION} \
function help_message() {
echo "Usage: $0 [OPTIONS]"
echo "Options:"
echo " --targets, -t <targets> Comma-separated list of target platforms (default: current, use 'all' for all supported targets)"
echo " --version, -v <version> Psiphon version to build (default: 2.0.32)"
echo " --go, -g <version> Go version to use (default: 1.22.7)"
echo " --help, -h Show this help message and exit"
echo " --supported-targets Show supported targets and exit"
exit ${1:-1}
}
EXTRA_BUILD_ARGS=""
VERSION=""
while [[ $# -gt 0 ]]; do
case "$1" in
--help|-h)
help_message 0
;;
--targets=*)
TARGETS="${1#*=}"
shift
;;
-t | --targets)
TARGETS="$2"
shift 2
;;
--version=*)
VERSION="${1#*=}"
shift
;;
-v | --version)
VERSION="$2"
shift 2
;;
--go=*)
GO_VERSION="${1#*=}"
shift
;;
-g | --go)
GO_VERSION="$2"
shift 2
;;
--supported-targets)
echo "Supported targets: $(get_supported_targets)"
exit 0
;;
--current-target)
echo "Current target: $(get_current_target)"
exit 0
;;
-l | --load)
if [[ -n ${EXTRA_BUILD_ARGS} && ${EXTRA_BUILD_ARGS} == *"--push"* ]]; then
echo "Error: --load and --push cannot be used together." >&2
exit 1
fi
EXTRA_BUILD_ARGS="--load"
shift
;;
-p | --push)
if [[ -n ${EXTRA_BUILD_ARGS} && ${EXTRA_BUILD_ARGS} == *"--load"* ]]; then
echo "Error: --load and --push cannot be used together." >&2
exit 1
fi
EXTRA_BUILD_ARGS="--push"
shift
;;
*)
echo "Error: Unknown option '$1'" >&2
help_message
;;
esac
done
TARGETS=${TARGETS:-"current"}
GO_VERSION=${GO_VERSION:-1.22.7}
MYPATH=$(dirname "$(readlink -f "$0")")
source "${MYPATH}/latest_version.sh"
DOCKER_BUILD_ARGS=()
if [[ -n "${TARGETS}" ]]; then
DOCKER_BUILD_ARGS+=(--build-arg TARGETS=${TARGETS})
fi
if [[ -z "${VERSION}" ]]; then
VERSION=$(get_latest_version)
fi
if [[ -n "${VERSION}" ]]; then
VERSION=$(normalize_version "${VERSION}")
DOCKER_BUILD_ARGS+=(--build-arg PSIPHON_VERSION=${VERSION})
fi
if [[ -n "${GO_VERSION}" ]]; then
DOCKER_BUILD_ARGS+=(--build-arg GO_VERSION=${GO_VERSION})
fi
DECIPHERED_TARGETS=$(decipher_targets "${TARGETS}")
docker buildx build \
"${DOCKER_BUILD_ARGS[@]}" \
-t swarupsengupta2007/psiphon:"${VERSION#v}" \
-t swarupsengupta2007/psiphon:latest \
--platform ${TARGETS} . $1
--platform "${DECIPHERED_TARGETS}" . \
${EXTRA_BUILD_ARGS}