mirror of
https://github.com/coollabsio/coolify.git
synced 2026-03-11 08:55:47 +00:00
feat: add --pids-limit to custom docker run options whitelist
Add support for --pids-limit option in CustomDockerRunOptions to allow limiting the number of processes that can be created within a container. This provides an additional security hardening option for deployments. - Add --pids-limit to the mapping in convertDockerRunToCompose() - Add parsing logic for both --pids-limit=value and --pids-limit value formats - Add tests for the new option
This commit is contained in:
parent
c4e15d4e1b
commit
c0100a3edd
2 changed files with 24 additions and 1 deletions
|
|
@ -1010,6 +1010,7 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
|
|||
'--hostname' => 'hostname',
|
||||
'--entrypoint' => 'entrypoint',
|
||||
'--runtime' => 'runtime',
|
||||
'--pids-limit' => 'pids_limit',
|
||||
]);
|
||||
foreach ($matches as $match) {
|
||||
$option = $match[1];
|
||||
|
|
@ -1040,6 +1041,16 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
|
|||
$options[$option] = array_unique($options[$option]);
|
||||
}
|
||||
}
|
||||
if ($option === '--pids-limit') {
|
||||
// Match --pids-limit=value or --pids-limit value (e.g., --pids-limit=256, --pids-limit 1024)
|
||||
$regexForParsingPidsLimit = '/--pids-limit(?:=|\s+)([^\s]+)/';
|
||||
preg_match($regexForParsingPidsLimit, $custom_docker_run_options, $pids_limit_matches);
|
||||
$value = $pids_limit_matches[1] ?? null;
|
||||
if ($value && ! empty(trim($value))) {
|
||||
$options[$option][] = $value;
|
||||
$options[$option] = array_unique($options[$option]);
|
||||
}
|
||||
}
|
||||
if ($option === '--entrypoint') {
|
||||
$value = null;
|
||||
// Match --entrypoint=value or --entrypoint value
|
||||
|
|
@ -1108,7 +1119,7 @@ function convertDockerRunToCompose(?string $custom_docker_run_options = null)
|
|||
}
|
||||
});
|
||||
$compose_options->put($mapping[$option], $ulimits);
|
||||
} elseif ($option === '--shm-size' || $option === '--hostname' || $option === '--runtime') {
|
||||
} elseif ($option === '--shm-size' || $option === '--hostname' || $option === '--runtime' || $option === '--pids-limit') {
|
||||
if (! is_null($value) && is_array($value) && count($value) > 0 && ! empty(trim($value[0]))) {
|
||||
$compose_options->put($mapping[$option], $value[0]);
|
||||
}
|
||||
|
|
|
|||
|
|
@ -223,3 +223,15 @@ test('RuntimeWithOtherOptions', function () {
|
|||
->and($output['cap_drop'])->toBe(['ALL'])
|
||||
->and($output['security_opt'])->toBe(['no-new-privileges']);
|
||||
});
|
||||
|
||||
test('PidsLimitWithEquals', function () {
|
||||
$input = '--pids-limit=1024';
|
||||
$output = convertDockerRunToCompose($input);
|
||||
expect($output)->toBe(['pids_limit' => '1024']);
|
||||
});
|
||||
|
||||
test('PidsLimitWithoutEquals', function () {
|
||||
$input = '--pids-limit 256';
|
||||
$output = convertDockerRunToCompose($input);
|
||||
expect($output)->toBe(['pids_limit' => '256']);
|
||||
});
|
||||
|
|
|
|||
Loading…
Reference in a new issue