diff --git a/Dockerfile.runtime b/Dockerfile.runtime index c6eeb48..46e108c 100644 --- a/Dockerfile.runtime +++ b/Dockerfile.runtime @@ -21,6 +21,37 @@ RUN apt-get update \ && apt-get install -y --no-install-recommends "jellyfin-web=10.11.6+deb12" \ && rm -rf /var/lib/apt/lists/* +# ── Plugin stage ────────────────────────────────────────────────────────────── +# Download and verify the auth plugins, unpacked into versioned dirs baked into +# the image and synced into /config/plugins at start (docker-entrypoint.sh). +# Versions are the newest each plugin publishes whose targetAbi <= the pinned +# Jellyfin server version (10.11.6): +# LDAP Authentication 22.0.0.0 targetAbi 10.11.2.0 (v23 needs 10.11.9) +# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0 +# sha256 pins match each release's published .sha256 asset for reproducibility. +FROM --platform=linux/amd64 debian:bookworm-slim AS plugins + +RUN apt-get update \ + && apt-get install -y --no-install-recommends curl ca-certificates unzip \ + && rm -rf /var/lib/apt/lists/* + +ARG LDAP_URL=https://repo.jellyfin.org/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip +ARG LDAP_SHA256=c2386c001be439c9946280a02d62610f29e325d4094e83bd31221de3f7aa20ae +ARG SSO_URL=https://github.com/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip +ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107 + +WORKDIR /plugins +RUN set -eu; \ + curl -fsSL "$LDAP_URL" -o ldap.zip; \ + echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \ + mkdir -p "LDAP Authentication_22.0.0.0"; \ + unzip -oq ldap.zip -d "LDAP Authentication_22.0.0.0"; \ + curl -fsSL "$SSO_URL" -o sso.zip; \ + echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \ + mkdir -p "SSO Authentication_4.0.0.4"; \ + unzip -oq sso.zip -d "SSO Authentication_4.0.0.4"; \ + rm -f ldap.zip sso.zip + # ── Runtime stage ───────────────────────────────────────────────────────────── # .NET 9 runtime: matches the SDK 9.0 publish step (framework-dependent), so the # app's required Microsoft.NETCore.App 9.0 is present. Keep in lockstep with the @@ -42,6 +73,9 @@ WORKDIR /jellyfin COPY publish-output/ . # jellyfin-web client assets from the webclient stage. COPY --from=webclient /usr/share/jellyfin/web ./jellyfin-web/ +# Baked auth plugins; docker-entrypoint.sh syncs these into /config/plugins. +COPY --from=plugins /plugins /usr/share/jellyfin/plugins-baked +COPY --chmod=0755 docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh # Jellyfin default ports EXPOSE 8096 @@ -54,7 +88,4 @@ ENV JELLYFIN_DATA_DIR=/config \ JELLYFIN_CACHE_DIR=/cache \ JELLYFIN_LOG_DIR=/config/log -ENTRYPOINT ["./jellyfin", \ - "--datadir", "/config", \ - "--cachedir", "/cache", \ - "--webdir", "/jellyfin/jellyfin-web"] +ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"] diff --git a/docker-entrypoint.sh b/docker-entrypoint.sh new file mode 100644 index 0000000..8c7e85b --- /dev/null +++ b/docker-entrypoint.sh @@ -0,0 +1,29 @@ +#!/bin/sh +# Sync image-baked plugins into the /config (datadir) plugins directory on every +# start. /config is a PVC that overlays the image, so plugins baked into the +# image are invisible until copied in here. Removing any existing versioned dir +# of the same plugin first lets the image version win across restarts/downgrades. +set -eu + +BAKED_DIR=/usr/share/jellyfin/plugins-baked +PLUGIN_DIR=/config/plugins + +if [ -d "$BAKED_DIR" ]; then + mkdir -p "$PLUGIN_DIR" + for src in "$BAKED_DIR"/*; do + [ -d "$src" ] || continue + name=$(basename "$src") # e.g. "LDAP Authentication_22.0.0.0" + base=${name%_*} # plugin name without the trailing _ + for existing in "$PLUGIN_DIR/$base"_*; do + [ -e "$existing" ] && rm -rf "$existing" + done + rm -rf "$PLUGIN_DIR/$name" + cp -a "$src" "$PLUGIN_DIR/$name" + done +fi + +exec ./jellyfin \ + --datadir /config \ + --cachedir /cache \ + --webdir /jellyfin/jellyfin-web \ + "$@"