redo vlan logic
This commit is contained in:
parent
230988d2dd
commit
41a058cd16
2 changed files with 26 additions and 15 deletions
|
|
@ -20,14 +20,12 @@ COPY --from=builder /mdns-repeater /usr/local/bin/
|
|||
COPY --chmod=755 entrypoint.sh /
|
||||
COPY --chmod=755 healthcheck.sh /usr/local/bin/
|
||||
|
||||
RUN apk add --no-cache libcap iproute2 \
|
||||
RUN apk add --no-cache libcap iproute2 su-exec \
|
||||
&& adduser -D -s /sbin/nologin mdns \
|
||||
&& setcap 'cap_net_raw,cap_net_bind_service=+ep' /usr/local/bin/mdns-repeater \
|
||||
&& mkdir -p /tmp \
|
||||
&& chown mdns:mdns /tmp
|
||||
|
||||
USER mdns
|
||||
|
||||
HEALTHCHECK --interval=15s --timeout=5s --start-period=5s --retries=3 \
|
||||
CMD /usr/local/bin/healthcheck.sh
|
||||
|
||||
|
|
|
|||
|
|
@ -1,27 +1,40 @@
|
|||
#!/bin/sh
|
||||
# entrypoint.sh — mdns-reflector container entrypoint
|
||||
#
|
||||
# Expects interface names via env var INTERFACES (space-separated),
|
||||
# or falls back to all non-loopback interfaces.
|
||||
# Runs as root to set up VLAN subinterfaces (if VLAN_IDS is set),
|
||||
# then drops privileges to 'mdns' user for the repeater process.
|
||||
#
|
||||
# For RouterOS: VLAN_IDS="10 20 30" bridges those VLANs.
|
||||
# Without VLAN_IDS: bridges all visible non-loopback interfaces.
|
||||
|
||||
set -e
|
||||
|
||||
if [ $# -gt 0 ]; then
|
||||
# Use CLI arguments (from docker run ... or CMD)
|
||||
:
|
||||
elif [ -n "$INTERFACES" ]; then
|
||||
# shellcheck disable=SC2086
|
||||
set -- $INTERFACES
|
||||
else
|
||||
# Auto-detect: all 'up' interfaces except loopback
|
||||
# Auto-detect the container's main interface (the one with the default route)
|
||||
MAIN_IFACE=$(ip -o route show default | awk '{print $5}')
|
||||
if [ -z "$MAIN_IFACE" ]; then
|
||||
MAIN_IFACE=$(ip -o link show up | awk -F': ' '!/lo/{print $2}' | cut -d@ -f1 | head -1)
|
||||
fi
|
||||
|
||||
if [ -n "$VLAN_IDS" ]; then
|
||||
echo "[entrypoint] Creating VLAN subinterfaces on $MAIN_IFACE..."
|
||||
IFACES=""
|
||||
for vid in $VLAN_IDS; do
|
||||
iface="${MAIN_IFACE}.${vid}"
|
||||
ip link add link "$MAIN_IFACE" name "$iface" type vlan id "$vid"
|
||||
ip link set "$iface" up
|
||||
IFACES="$IFACES $iface"
|
||||
done
|
||||
set -- $IFACES
|
||||
elif [ -n "$MAIN_IFACE" ]; then
|
||||
set -- $(ip -o link show up | awk -F': ' '!/lo/{print $2}' | cut -d@ -f1)
|
||||
fi
|
||||
|
||||
if [ $# -eq 0 ]; then
|
||||
echo "ERROR: No interfaces found. Set INTERFACES env var or attach interfaces."
|
||||
echo "ERROR: No interfaces found."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
echo "[entrypoint] Starting mdns-repeater on: $*"
|
||||
exec /usr/local/bin/mdns-repeater "$@"
|
||||
|
||||
# Drop privileges before running the repeater
|
||||
exec su-exec mdns /usr/local/bin/mdns-repeater "$@"
|
||||
|
|
|
|||
Loading…
Reference in a new issue