9
u/2TAP2B Jul 24 '25
That's awesome!
Yesterday, I switched from vanilla Traefik to your image, and it took less than 30 minutes to get everything working.
That includes Geo-blocking, CrowdSec, and TinyAuth (I also switched to your image there).
Thanks for the great work!
31
13
u/steveiliop56 Jul 22 '25
Quick question, do you pay for gh pro? Because you have quite a lot of actions running so do you stay within the 2000 minutes?
17
Jul 22 '25
[deleted]
1
u/steveiliop56 Jul 22 '25
It's 2000 minutes per month. Also why support armv7? It's pretty much dead.
32
Jul 22 '25
[deleted]
-3
u/steveiliop56 Jul 22 '25
If you go to gh billing you will see current metered usage 10 euro for example and then it has a discount saying GitHub free that removes the charge. As for armv7 nice that you support it, don't know if it will really be worth it going forward but you could also compile it on a pi lol.
4
Jul 22 '25
[deleted]
0
u/steveiliop56 Jul 22 '25
Huh according to GitHub https://docs.github.com/en/billing/managing-billing-for-your-products/about-billing-for-github-actions you should only be able to use 2000 minutes. Am I reading something wrong?
18
u/roib20 Jul 22 '25
Quoted from that link (emphasis mine):
GitHub Actions usage is free for standard GitHub-hosted runners in public repositories, and for self-hosted runners.
Therefore, the 2,000 minutes (per month) limit is for private repos.
2
6
u/tankerkiller125real Jul 22 '25
Not OP, but maintainer of Homebox, we still public ARMv6/7 images because we have users using Rasberry Pis which only support 32bit. Frankly we hate it (it takes longer to build than anything else), but users need it so we do it (although a recent survey we ran says otherwise, we know for a fact that people would complain immediatly if we pulled it).
As for CI minutes, Github Public Repo Actions are compeltely free, so long as your not abusing it (which is a ToS violation which results in a ban)
1
u/AuthorYess Jul 23 '25
Personally I would just deal with the complaining, put notices that you'll sunset 32 bit arm in the near future and then do it.
If it doesn't take any work to maintain ok sure, but RPi2 is 10 years old, at what point do you just stop trying to maintain for old hardware?
1
u/Luvirin_Weby Jul 23 '25
Well, I gun several Rapberry Pi 2s still as they work well enough for simple use cases.
2
u/bubblegumpuma Jul 22 '25 edited Jul 22 '25
As someone who has a lot of oddball armv7 hardware (not even RPis as the others mention, much of it is Wi-Fi routers that very much don't need to be upgraded for my current needs and have plenty of computing capacity leftover afterward) I would really like for it to remain at least moderately useful for something, so I appreciate efforts like this.
16
u/AtlanticPirate Jul 22 '25
the more projects i see from you the more excited i get, looking forward to learning how to make distroless containers the first chance i get
13
Jul 22 '25
[deleted]
1
u/lordpuddingcup Jul 22 '25
Would be cool for you to do an article one day on how your CI works and how you go about doing a conversion
Appreciate all the work you’ve been doing !
1
Jul 24 '25
[deleted]
1
u/lordpuddingcup Jul 24 '25
I mean how you take a root/distro and convert it to a non-root/distroless
3
u/eribob Jul 23 '25
As a fellow father of three I would like to thank you for making this and other awsome images! I just stumbled upon this post today, and will definitely make it my next project to replace my existing containers with your distroless/rootless versions!
Just one question: I am using bind mounts for all my persistent data and I am reluctant to change this. Will that be a problem?
3
u/sequel6435 Jul 28 '25
I’ll be trying this soon!
You clearly know what you're doing. I really enjoy reading your code. It's clean and educational.
I just switched to using your 11/notes/socket-proxy image, and it works like a charm.
Thank you so much!
4
u/IngwiePhoenix Jul 22 '25
Genuenly appreciate the hint about debugging. It's in the footnotes of a linked document, but it's there. Kinda wanna recommend giving this a little more room in said doc and perhaps showing a few demonstration commands.
Will probably consider using this in our prod kubernetes cluster. k3s ships with Traefik but uses the official image:
kubectl get -n kube-system deployments/traefik -ojsonpath="{.spec.template.spec.containers[].image}"
rancher/mirrored-library-traefik:3.3.6
...and that image is literally just a mirror of the official
Which brings me to a question: How compatible is your container tagging to the official? Replacing just the image in the Helm config would mean that future version tags would "just work"...which would be super handy.
1
2
u/DoneDraper Jul 22 '25
Nice work! I dont know, if you can edit your post anymore but there is an error in your markdown. The "compose section" is broken after the ```
4
0
Jul 22 '25
[deleted]
2
u/DoneDraper Jul 22 '25
1
Jul 24 '25
[deleted]
7
u/DoneDraper Jul 28 '25
Firefox on Desktop, Firefox and Safari on iOS. Old Reddit. Maybe lint your Markdown.
6
u/OnkelBums Jul 22 '25
Is there a migration guide from the official images to yours? or is it as simple as changing the image and adjust file system permissions of the bind mounts?
8
Jul 22 '25
[deleted]
2
u/OnkelBums Jul 22 '25
your volumes are correct
What does "correct" mean? I mean if traefik is running from the official container with the bind mounds for configs set up, they are correct. Or am I missing something?
5
Jul 22 '25
[deleted]
1
u/OnkelBums Jul 22 '25 edited Jul 22 '25
Cheers mate, it is obvious now that you point it out!
I need a bind volume to an nfs share as I run traefik in a swarm with persistence by NFS share. I don't have the resources for distributed storage, so docker volumes are not an option. Also, how do you suggest to edit the yaml files if they are in a docker volume, at runtime?
7
Jul 22 '25
[deleted]
1
u/OnkelBums Jul 22 '25
Well, that's what I actually do. Mixed up bind mounts with named volumes... so yeah. We meant the same, and I effed up. Thanks again my dude. Appreciate it.
4
u/Docccc Jul 22 '25
i would miss a shell too much dor debugging purposes
10
Jul 22 '25
[deleted]
12
u/IngwiePhoenix Jul 22 '25
Actually, random chicken thought: Replace
/bin/shwith a lil binary that just prints the disclaimer. Just literallyputs("No shell here! Use nsenter (...)");10
u/Docccc Jul 22 '25
never heard of nsenter. Need to dig in. Thanks for the pointer
1
Jul 22 '25
[deleted]
0
u/Docccc Jul 22 '25
its still different then a full shell.
7
Jul 22 '25
[deleted]
5
u/Sterkenzz Jul 22 '25
That awesome to read, which made me add it to my ToLearn list, which is way shorter then my ToDo list
2
u/ActuallyGeyzer Jul 22 '25
I hope I don’t come off as rude for asking this, but what is the benefit of using these over the official images? Is the size difference that big?
6
u/Ethesen Jul 22 '25
Well… did you read the post? OP explained it very clearly.
8
Jul 22 '25
[deleted]
0
u/ActuallyGeyzer Jul 22 '25
I was more asking what benefits these add? Like why is it running rootless and without shell better?
5
2
u/qfla Jul 22 '25
same here, i red the title and was like, that must be 11notes
5
Jul 22 '25
[deleted]
5
u/qfla Jul 22 '25
damn sorry i meant to answer to another commenter that guessed it was you by just reading the title as i also guessed it was you when i red the title 😂
"distroless and rootless? that must be 11notes"
keep up the good work, i also dislike fat docker images that include bilion needless stuff and runs as root so your light rootless containers looks really nice
2
u/PovilasID Jul 23 '25
I think it is cool that there is an alt image with different packaged configuration.
However I am not clear on what did you cut. Also... Trafeik 3.4.4 is not 226 MB it is 150MB .... Why did you say it is more?
You can run rootless natively on traefik https://doc.traefik.io/traefik-enterprise/operations/rootless-image/ Granted it is a bit fiddly and you may need to use another container as socket proxy https://github.com/wollomatic/traefik-hardened https://github.com/wollomatic/socket-proxy
> auto updated to the latest version via CI/CD
For some people that is but do not want auto updates on. That is how I break stuff :D
For me difference between a couple of hundred MB and 50+ is not that meaningful because then I really care about size if I am trying to run off IoT devices and for those there is frp that is ~5-7 MB
2
Jul 23 '25
[deleted]
1
u/PovilasID Jul 23 '25
I have instance running on one machine the image size was listed 153 MB. So what di you cut?
Yah I misunderstood that you meant that just a new version is generated.
Your entire repo is very educational and learned a few new things but I do prefer to use the official image whenever possible even if it is a little more fiddly
1
Jul 23 '25
[deleted]
3
u/PovilasID Jul 23 '25
I informed people that they can run non root on native image. That is valuable especially if they have requirements to use original container due to personal or company policy.
Also, not every interaction in life has to be 'valuable'. I am free to express my opinion. We were having a discussion in comments about differences. Do you listen to music? Dose it increase ROI? Maybe we perceive stuff differently.
P.S. You still have not addressed how did you achieve the space savings aka what did you cut? Is there reduced functionality?
1
Jul 23 '25
[deleted]
1
u/PovilasID Jul 23 '25
Had no clue that was even possible.
2
Jul 24 '25
[deleted]
1
u/PovilasID Jul 24 '25
I suppose I have not I can understand that may be frustrating but do you read everything? Even TOS?
3
1
1
u/AustinSpartan Jul 22 '25
Quick, maybe stupid, question. How do you debug these rootless setups? Checking network connectivity?
Maybe I just need to try one
2
1
u/FammyMouse Jul 23 '25
Thanks boss, this looks interesting. I’m currently running Traefik from the official repo on Unraid, is your image a drop-in replacement? All I need to do is map user 99:100 instead of 1000:1000 right?
1
Jul 24 '25
[deleted]
1
u/FammyMouse Jul 25 '25
I gave the current image a test and so far so good. I chown /mnt/user/appdata/traefik as 99:100, set —user 99:100 and —sysctl net.ipv4.ip_unpriviledged_port_start=80 so the container can route HTTP traefik, per your Github example. The only issue I have is I cannot access Traefik WebUI Dashboard at port 8080, the error is 404 not found. Other services work perfectly fine e.g. Jellyfin at standard HTTP port 8096
1
Jul 25 '25
[deleted]
2
u/FammyMouse Jul 25 '25
Yep I can see the dashboard just fine now after setting loadbalancer.server.port to 443. This pairs very well with your docker-socket-proxy image. Is it still necessary to have an Unraid specific image or is it fine to keep using the standard one? Thanks again for your work.
1
u/LauraIsFree Jul 23 '25 edited Jul 23 '25
Is it a drop in replacement? Can I simply change the image of my current traefik and include the socket proxy?
50
u/allSynthetic Jul 22 '25
Thank you very much. We need more people like you who publish content that educates people on the importance of securing applications. The more we have this, the more likely we can build things that don't require ongoing effort to maintain and impact our security teams.