enable ping in docker container for non-root user

add libcap and setcap cap_net_raw+p on /bin/ping so ICMP works
without container-level capabilities. add NET_RAW cap_add to
docker-compose.example.yml as fallback.
This commit is contained in:
Graham McIntire 2026-02-11 10:58:30 -06:00
parent 894dcb18e4
commit 39641b73d4
No known key found for this signature in database
2 changed files with 4 additions and 1 deletions

View file

@ -10,7 +10,8 @@ RUN --mount=type=cache,target=/go/pkg/mod \
CGO_ENABLED=0 go build -ldflags="-s -w -X main.version=${VERSION}" -o towerops-agent .
FROM alpine:3.23
RUN apk add --no-cache ca-certificates iputils
RUN apk add --no-cache ca-certificates iputils libcap && \
setcap cap_net_raw+p /bin/ping
COPY --from=builder /app/towerops-agent /usr/local/bin/towerops-agent
RUN adduser -D -u 1000 towerops && chown towerops /usr/local/bin/towerops-agent
USER towerops

View file

@ -3,6 +3,8 @@ services:
image: ghcr.io/towerops-app/towerops-agent:latest
container_name: towerops-agent
restart: unless-stopped
cap_add:
- NET_RAW
environment:
# Required: Agent authentication token (from Towerops web UI)