Merge pull request 'Bake LDAP + SSO auth plugins into the image' (#8) from benvin/auth-plugins into main
ci/woodpecker/tag/docker Pipeline was successful

Reviewed-on: #8
This commit was merged in pull request #8.
This commit is contained in:
2026-08-29 12:03:44 +10:00
2 changed files with 67 additions and 4 deletions
+38 -4
View File
@@ -21,6 +21,40 @@ RUN apt-get update \
&& apt-get install -y --no-install-recommends "jellyfin-web=10.11.6+deb12" \ && apt-get install -y --no-install-recommends "jellyfin-web=10.11.6+deb12" \
&& rm -rf /var/lib/apt/lists/* && rm -rf /var/lib/apt/lists/*
# ── Plugin stage ──────────────────────────────────────────────────────────────
# Download and verify the auth plugins, unpacked into versioned dirs baked into
# the image and synced into /config/plugins at start (docker-entrypoint.sh).
# Versions are the newest each plugin publishes whose targetAbi <= the pinned
# Jellyfin server version (10.11.6):
# LDAP Authentication 22.0.0.0 targetAbi 10.11.2.0 (v23 needs 10.11.9)
# SSO Authentication 4.0.0.4 targetAbi 10.11.0.0
# sha256 pins match each release's published .sha256 asset for reproducibility.
FROM --platform=linux/amd64 debian:bookworm-slim AS plugins
RUN apt-get update \
&& apt-get install -y --no-install-recommends curl ca-certificates unzip \
&& rm -rf /var/lib/apt/lists/*
ARG LDAP_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/jellyfin/files/plugin/ldap-authentication/ldap-authentication_22.0.0.0.zip
ARG LDAP_SHA256=c2386c001be439c9946280a02d62610f29e325d4094e83bd31221de3f7aa20ae
# LDAP is served through artifactapi remote. SSO is served through the artifactapi
# github proxy, which the CI build network can reach (github is not directly reachable).
# SHA256 pins match each release's published asset for reproducibility and integrity.
ARG SSO_URL=http://artifactapi.k8s.syd1.au.unkin.net/api/v1/remote/github/9p4/jellyfin-plugin-sso/releases/download/v4.0.0.4/sso-authentication_4.0.0.4.zip
ARG SSO_SHA256=c09f16ba31059a434ddd7f811e4f9608d4b4c4514cc80a5bf1ca33bee61e1107
WORKDIR /plugins
RUN set -eu; \
curl -fsSL "$LDAP_URL" -o ldap.zip; \
echo "$LDAP_SHA256 ldap.zip" | sha256sum -c -; \
mkdir -p "LDAP Authentication_22.0.0.0"; \
unzip -oq ldap.zip -d "LDAP Authentication_22.0.0.0"; \
curl -fsSL "$SSO_URL" -o sso.zip; \
echo "$SSO_SHA256 sso.zip" | sha256sum -c -; \
mkdir -p "SSO Authentication_4.0.0.4"; \
unzip -oq sso.zip -d "SSO Authentication_4.0.0.4"; \
rm -f ldap.zip sso.zip
# ── Runtime stage ───────────────────────────────────────────────────────────── # ── Runtime stage ─────────────────────────────────────────────────────────────
# .NET 9 runtime: matches the SDK 9.0 publish step (framework-dependent), so the # .NET 9 runtime: matches the SDK 9.0 publish step (framework-dependent), so the
# app's required Microsoft.NETCore.App 9.0 is present. Keep in lockstep with the # app's required Microsoft.NETCore.App 9.0 is present. Keep in lockstep with the
@@ -42,6 +76,9 @@ WORKDIR /jellyfin
COPY publish-output/ . COPY publish-output/ .
# jellyfin-web client assets from the webclient stage. # jellyfin-web client assets from the webclient stage.
COPY --from=webclient /usr/share/jellyfin/web ./jellyfin-web/ COPY --from=webclient /usr/share/jellyfin/web ./jellyfin-web/
# Baked auth plugins; docker-entrypoint.sh syncs these into /config/plugins.
COPY --from=plugins /plugins /usr/share/jellyfin/plugins-baked
COPY --chmod=0755 docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
# Jellyfin default ports # Jellyfin default ports
EXPOSE 8096 EXPOSE 8096
@@ -54,7 +91,4 @@ ENV JELLYFIN_DATA_DIR=/config \
JELLYFIN_CACHE_DIR=/cache \ JELLYFIN_CACHE_DIR=/cache \
JELLYFIN_LOG_DIR=/config/log JELLYFIN_LOG_DIR=/config/log
ENTRYPOINT ["./jellyfin", \ ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
"--datadir", "/config", \
"--cachedir", "/cache", \
"--webdir", "/jellyfin/jellyfin-web"]
+29
View File
@@ -0,0 +1,29 @@
#!/bin/sh
# Sync image-baked plugins into the /config (datadir) plugins directory on every
# start. /config is a PVC that overlays the image, so plugins baked into the
# image are invisible until copied in here. Removing any existing versioned dir
# of the same plugin first lets the image version win across restarts/downgrades.
set -eu
BAKED_DIR=/usr/share/jellyfin/plugins-baked
PLUGIN_DIR=/config/plugins
if [ -d "$BAKED_DIR" ]; then
mkdir -p "$PLUGIN_DIR"
for src in "$BAKED_DIR"/*; do
[ -d "$src" ] || continue
name=$(basename "$src") # e.g. "LDAP Authentication_22.0.0.0"
base=${name%_*} # plugin name without the trailing _<version>
for existing in "$PLUGIN_DIR/$base"_*; do
[ -e "$existing" ] && rm -rf "$existing"
done
rm -rf "$PLUGIN_DIR/$name"
cp -a "$src" "$PLUGIN_DIR/$name"
done
fi
exec ./jellyfin \
--datadir /config \
--cachedir /cache \
--webdir /jellyfin/jellyfin-web \
"$@"