diff --git a/.devcontainer/Dockerfile b/.devcontainer/Dockerfile index 005031c8..58635286 100644 --- a/.devcontainer/Dockerfile +++ b/.devcontainer/Dockerfile @@ -37,9 +37,9 @@ RUN apt install -y \ RUN apt install -y \ mediainfo -# Configure Docker-in-Docker +# Configure Docker-from-Docker COPY ./.devcontainer/library-scripts /tmp/library-scripts/ -RUN /bin/bash /tmp/library-scripts/docker-in-docker-debian.sh true vscode false +RUN /bin/bash /tmp/library-scripts/docker-debian.sh true "/var/run/docker-host.sock" "/var/run/docker.sock" vscode false # Run as vscode user USER vscode diff --git a/.devcontainer/devcontainer.json b/.devcontainer/devcontainer.json index 7089ef56..b303981a 100644 --- a/.devcontainer/devcontainer.json +++ b/.devcontainer/devcontainer.json @@ -2,8 +2,9 @@ "name": "Flood development container", "context": "..", "dockerFile": "./Dockerfile", - "runArgs": ["--init", "--privileged"], - "postCreateCommand": "/usr/local/share/docker-init.sh", + "runArgs": ["--init"], + "initializeCommand": "umask 077 && mkdir -p ~/.docker ~/.gnupg ~/.ssh && umask 177 && touch ~/.git-credentials ~/.npmrc ~/.zsh_history", + "postCreateCommand": "npm install && bash /usr/local/share/docker-init.sh", "settings": { "terminal.integrated.shell.linux": "/bin/zsh" }, @@ -18,5 +19,15 @@ "streetsidesoftware.code-spell-checker", "visualstudioexptteam.vscodeintellicode" ], - "forwardPorts": [3000, 4200] + "forwardPorts": [3000, 4200], + "remoteUser": "vscode", + "mounts": [ + "source=/var/run/docker.sock,target=/var/run/docker-host.sock,type=bind", + "source=${localEnv:HOME}/.docker,target=/home/vscode/.docker,type=bind", + "source=${localEnv:HOME}/.gnupg,target=/home/vscode/.gnupg,type=bind", + "source=${localEnv:HOME}/.ssh,target=/home/vscode/.ssh,type=bind", + "source=${localEnv:HOME}/.git-credentials,target=/home/vscode/.git-credentials,type=bind", + "source=${localEnv:HOME}/.npmrc,target=/home/vscode/.npmrc,type=bind", + "source=${localEnv:HOME}/.zsh_history,target=/home/vscode/.zsh_history,type=bind" + ] } diff --git a/.devcontainer/library-scripts/docker-in-docker-debian.sh b/.devcontainer/library-scripts/docker-debian.sh similarity index 61% rename from .devcontainer/library-scripts/docker-in-docker-debian.sh rename to .devcontainer/library-scripts/docker-debian.sh index 410fc7d9..99199035 100644 --- a/.devcontainer/library-scripts/docker-in-docker-debian.sh +++ b/.devcontainer/library-scripts/docker-debian.sh @@ -4,13 +4,15 @@ # Licensed under the MIT License. See https://go.microsoft.com/fwlink/?linkid=2090316 for license information. #------------------------------------------------------------------------------------------------------------- # -# Docs: https://github.com/microsoft/vscode-dev-containers/blob/master/script-library/docs/docker-in-docker.md +# Docs: https://github.com/microsoft/vscode-dev-containers/blob/master/script-library/docs/docker.md # -# Syntax: ./docker-in-docker-debian.sh [enable non-root docker access flag] [non-root user] [use moby] +# Syntax: ./docker-debian.sh [enable non-root docker socket access flag] [source socket] [target socket] [non-root user] [use moby] ENABLE_NONROOT_DOCKER=${1:-"true"} -USERNAME=${2:-"automatic"} -USE_MOBY=${3:-"true"} +SOURCE_SOCKET=${2:-"/var/run/docker-host.sock"} +TARGET_SOCKET=${3:-"/var/run/docker.sock"} +USERNAME=${4:-"automatic"} +USE_MOBY=${5:-"true"} set -e @@ -50,19 +52,15 @@ apt-get-update-if-needed() # Ensure apt is in non-interactive to avoid prompts export DEBIAN_FRONTEND=noninteractive -# Install docker/dockerd dependencies if missing -if ! dpkg -s apt-transport-https curl ca-certificates lsb-release lxc pigz iptables > /dev/null 2>&1 || ! type gpg > /dev/null 2>&1; then +# Install apt-transport-https, curl, lsb-release, gpg if missing +if ! dpkg -s apt-transport-https curl ca-certificates lsb-release > /dev/null 2>&1 || ! type gpg > /dev/null 2>&1; then apt-get-update-if-needed - apt-get -y install --no-install-recommends apt-transport-https curl ca-certificates lsb-release lxc pigz iptables gnupg2 + apt-get -y install --no-install-recommends apt-transport-https curl ca-certificates lsb-release gnupg2 fi -# Swap to legacy iptables for compatibility -update-alternatives --set iptables /usr/sbin/iptables-legacy -update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy - # Install Docker / Moby CLI if not already installed -if type docker > /dev/null 2>&1 && type dockerd > /dev/null 2>&1; then - echo "Docker / Moby CLI and Engine already installed." +if type docker > /dev/null 2>&1; then + echo "Docker / Moby CLI already installed." else if [ "${USE_MOBY}" = "true" ]; then DISTRO=$(lsb_release -is | tr '[:upper:]' '[:lower:]') @@ -70,17 +68,15 @@ else curl -s https://packages.microsoft.com/keys/microsoft.asc | (OUT=$(apt-key add - 2>&1) || echo $OUT) echo "deb [arch=amd64] https://packages.microsoft.com/repos/microsoft-${DISTRO}-${CODENAME}-prod ${CODENAME} main" > /etc/apt/sources.list.d/microsoft.list apt-get update - apt-get -y install --no-install-recommends moby-cli moby-engine + apt-get -y install --no-install-recommends moby-cli else curl -fsSL https://download.docker.com/linux/$(lsb_release -is | tr '[:upper:]' '[:lower:]')/gpg | (OUT=$(apt-key add - 2>&1) || echo $OUT) echo "deb [arch=amd64] https://download.docker.com/linux/$(lsb_release -is | tr '[:upper:]' '[:lower:]') $(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list apt-get update - apt-get -y install --no-install-recommends docker-ce-cli docker-ce + apt-get -y install --no-install-recommends docker-ce-cli fi fi -echo "Finished installing docker / moby" - # Install Docker Compose if not already installed if type docker-compose > /dev/null 2>&1; then echo "Docker Compose already installed." @@ -92,19 +88,28 @@ fi # If init file already exists, exit if [ -f "/usr/local/share/docker-init.sh" ]; then - echo "/usr/local/share/docker-init.sh already exists, so exiting." exit 0 fi -echo "docker-init doesnt exist..." -# Add user to the docker group -if [ "${ENABLE_NONROOT_DOCKER}" = "true" ]; then - if ! getent group docker > /dev/null 2>&1; then - groupadd docker - fi - usermod -aG docker ${USERNAME} +# By default, make the source and target sockets the same +if [ "${SOURCE_SOCKET}" != "${TARGET_SOCKET}" ]; then + touch "${SOURCE_SOCKET}" + ln -s "${SOURCE_SOCKET}" "${TARGET_SOCKET}" fi +# Add a stub if not adding non-root user access, user is root +if [ "${ENABLE_NONROOT_DOCKER}" = "false" ] || [ "${USERNAME}" = "root" ]; then + echo '/usr/bin/env bash -c "\$@"' > /usr/local/share/docker-init.sh + chmod +x /usr/local/share/docker-init.sh + exit 0 +fi + +# If enabling non-root access and specified user is found, setup socat and add script +chown -h "${USERNAME}":root "${TARGET_SOCKET}" +if ! dpkg -s socat > /dev/null 2>&1; then + apt-get-update-if-needed + apt-get -y install socat +fi tee /usr/local/share/docker-init.sh > /dev/null \ << EOF #!/usr/bin/env bash @@ -113,6 +118,13 @@ tee /usr/local/share/docker-init.sh > /dev/null \ # Licensed under the MIT License. See https://go.microsoft.com/fwlink/?linkid=2090316 for license information. #------------------------------------------------------------------------------------------------------------- +set -e + +SOCAT_PATH_BASE=/tmp/vscr-docker-from-docker +SOCAT_LOG=\${SOCAT_PATH_BASE}.log +SOCAT_PID=\${SOCAT_PATH_BASE}.pid + +# Wrapper function to only use sudo if not already root sudoIf() { if [ "\$(id -u)" -ne 0 ]; then @@ -122,51 +134,36 @@ sudoIf() fi } -# explicitly remove dockerd and containerd PID file to ensure that it can start properly if it was stopped uncleanly -# ie: docker kill -sudoIf find /run /var/run -iname 'docker*.pid' -delete || : -sudoIf find /run /var/run -iname 'container*.pid' -delete || : +# Log messages +log() +{ + echo -e "[\$(date)] \$@" | sudoIf tee -a \${SOCAT_LOG} > /dev/null +} -set -e +echo -e "\n** \$(date) **" | sudoIf tee -a \${SOCAT_LOG} > /dev/null +log "Ensuring ${USERNAME} has access to ${SOURCE_SOCKET} via ${TARGET_SOCKET}" -## Dind wrapper script from docker team -# Maintained: https://github.com/moby/moby/blob/master/hack/dind - -export container=docker - -if [ -d /sys/kernel/security ] && ! sudoIf mountpoint -q /sys/kernel/security; then - sudoIf mount -t securityfs none /sys/kernel/security || { - echo >&2 'Could not mount /sys/kernel/security.' - echo >&2 'AppArmor detection and --privileged mode might break.' - } +# If enabled, try to add a docker group with the right GID. If the group is root, +# fall back on using socat to forward the docker socket to another unix socket so +# that we can set permissions on it without affecting the host. +if [ "${ENABLE_NONROOT_DOCKER}" = "true" ] && [ "${SOURCE_SOCKET}" != "${TARGET_SOCKET}" ] && [ "${USERNAME}" != "root" ] && [ "${USERNAME}" != "0" ]; then + # Enable proxy if not already running + if [ ! -f "\${SOCAT_PID}" ] || ! ps -p \$(cat \${SOCAT_PID}) > /dev/null; then + log "Enabling socket proxy." + log "Proxying ${SOURCE_SOCKET} to ${TARGET_SOCKET} for vscode" + sudoIf rm -rf ${TARGET_SOCKET} + (sudoIf socat UNIX-LISTEN:${TARGET_SOCKET},fork,mode=660,user=${USERNAME} UNIX-CONNECT:${SOURCE_SOCKET} 2>&1 | sudoIf tee -a \${SOCAT_LOG} > /dev/null & echo "\$!" | sudoIf tee \${SOCAT_PID} > /dev/null) + else + log "Socket proxy already running." + fi + log "Success" fi -# Mount /tmp (conditionally) -if ! sudoIf mountpoint -q /tmp; then - sudoIf mount -t tmpfs none /tmp -fi - -# cgroup v2: enable nesting -if [ -f /sys/fs/cgroup/cgroup.controllers ]; then - # move the init process (PID 1) from the root group to the /init group, - # otherwise writing subtree_control fails with EBUSY. - sudoIf mkdir -p /sys/fs/cgroup/init - sudoIf echo 1 > /sys/fs/cgroup/init/cgroup.procs - # enable controllers - sudoIf sed -e 's/ / +/g' -e 's/^/+/' < /sys/fs/cgroup/cgroup.controllers \ - > /sys/fs/cgroup/cgroup.subtree_control -fi -## Dind wrapper over. - -# Start docker/moby engine -( sudoIf dockerd > /tmp/dockerd.log 2>&1 ) & - -set +e - # Execute whatever commands were passed in (if any). This allows us # to set this script to ENTRYPOINT while still executing the default CMD. +set +e exec "\$@" EOF - chmod +x /usr/local/share/docker-init.sh chown ${USERNAME}:root /usr/local/share/docker-init.sh +echo "Done!"