Commit Graph

131 Commits (81ad21afb3c026abca74ee3beb77f5a8cc644f5d)

Author SHA1 Message Date
Andre Henn 81ad21afb3
Merge branch 'master' into tomcat-base-image 2024-02-20 14:32:50 +01:00
André Henn bba764fe9a
Update Dockerfile
Co-authored-by: Mark Prins <1165786+mprins@users.noreply.github.com>
2024-02-20 14:23:45 +01:00
Nils Bühner 4eb3cdab3b
Merge pull request #51 from buehner/set-tomcat-version
fix: set tomcat version as environment variable
2024-02-20 14:15:43 +01:00
Nils Bühner a3f89c5797 fix: set tomcat version as environment variable 2024-02-20 14:13:30 +01:00
Nils Bühner 7db7ead9ad
Merge pull request #50 from mprins/patch-1
Update TOMCAT_VERSION to 9.0.86
2024-02-20 11:29:23 +01:00
Mark Prins 5e9b7ea122
Update TOMCAT_VERSION to 9.0.86
see https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.86_(remm)
2024-02-20 11:19:43 +01:00
Nils Bühner afb06f07d7
Merge pull request #44 from jkroepke/patch-1
Support custom web.xml
2024-02-14 10:59:00 +01:00
Jan-Otto Kröpke 16fe5727d1
Update README.md 2024-02-10 01:04:48 +01:00
Andre Henn 577a428c9c
perform cleanup before geoserver user is set as current user 2024-02-09 10:00:28 +01:00
Andre Henn 2de74a9bd1
use JDK rather than JRE 2024-02-09 09:59:56 +01:00
Andre Henn ecda91badd
bump version to current stable 2.24.2 2024-02-09 09:54:08 +01:00
Andre Henn 71ea072fd2
update readme regarding base image 2024-02-09 09:54:08 +01:00
Andre Henn eeb400a0b1
fix: typos 2024-02-09 09:54:07 +01:00
Andre Henn b374d93b20
switch to official tomcat 9 - jre 11 base image 2024-02-09 09:53:59 +01:00
Jan-Otto Kröpke 1d4bc77faf
Merge branch 'master' into patch-1 2024-02-09 09:35:51 +01:00
Nils Bühner 3727938ec0
Merge pull request #39 from ahennr/tomcat-hardening-cis
Docker image and Tomcat configuration hardening
2024-02-09 09:21:48 +01:00
Nils Bühner 2490a96a8c docs: update readme regarding config overwrite 2024-02-07 15:04:19 +01:00
Nils Bühner 09f1dfec0c refactor: use function to avoid duplicate code 2024-02-07 14:49:03 +01:00
Nils Bühner 4a68744113 feat: allow use of custom server.xml 2024-02-07 14:29:46 +01:00
Nils Bühner e1677a9e75
Merge pull request #46 from ahennr/trivy-format
fix: use sarif format in trivy results
2024-02-07 14:24:09 +01:00
Andre Henn 9aaf0e6aa4
fix: use sarif format in trivy results 2024-02-07 13:52:29 +01:00
Andre Henn 9ff2eb405e
adds documentation for usage of custom server.xml 2024-02-07 12:59:21 +01:00
Andre Henn 733dde3e77
fix: set user id of geoserver user to 2000 2024-02-07 12:44:37 +01:00
Jan-Otto Kröpke 906cab1267
Update README.md 2024-01-29 23:20:17 +01:00
Jan-Otto Kröpke d744517e76
Update startup.sh 2024-01-29 11:14:05 +01:00
Jan-Otto Kröpke c691b3578b
Update startup.sh
Co-authored-by: Reinout van Rees <reinout@vanrees.org>
2024-01-29 11:12:25 +01:00
Jan-Otto Kröpke e725d75cd9
Support custom web.xml 2024-01-29 09:50:18 +01:00
Nils Bühner 0966018436
Merge pull request #43 from ahennr/trivy-results
Configure trivy action to upload results to security tab
2024-01-02 10:16:40 +01:00
Andre Henn 8eb35730e3
configure trivy action to upload results to security tab 2023-12-20 16:39:52 +01:00
Nils Bühner 4343dca5d3
Merge pull request #42 from buehner/no-fail-with-vulns
chore: do not fail with known vulns
2023-12-20 14:25:00 +01:00
Nils Bühner 0dc467eb59 chore: do not fail with known vulns
For the time being it should be fine to have this action as a background
info.
2023-12-20 14:17:08 +01:00
Nils Bühner b8d6dc43db
Merge pull request #41 from buehner/latest-versions
chore: use latest versions
2023-12-20 14:01:50 +01:00
Nils Bühner aa19de31d8 chore: use latest versions 2023-12-20 14:01:07 +01:00
Nils Bühner 8f9edd5503
Merge pull request #38 from ahennr/docker-setup-hardening
Introduce health checks for GeoServer (and postgis db in demo)
2023-12-20 13:41:50 +01:00
Andre Henn 9b80e8c410
feat: adds health check (default values) to docker-compose file 2023-12-20 12:30:10 +01:00
Nils Bühner 1402569b5a
Merge pull request #40 from hwbllmnn/trivy-scan
Add trivy scan
2023-12-20 11:43:48 +01:00
Andreas Schmitz 681267fcb6 Add trivy scan 2023-12-13 15:35:40 +01:00
Andre Henn 626b4775ba
Remove setuid and setgid permissions in the images to prevent privilege escalation attacks within containers 2023-12-12 14:42:59 +01:00
Andre Henn b108b4be06
introduce geoserver user as docker user 2023-12-12 14:31:00 +01:00
Andre Henn 4bc82ce2ba
Apply some CIS Apache Tomcat benchmark recommendations 2023-12-12 14:24:03 +01:00
Andre Henn 4d96f6f19c
introduce health checks for GeoServer and postgis 2023-12-11 14:20:01 +01:00
Nils Bühner 493e819734
Merge pull request #37 from ahennr/tomcat-update
Update tomcat version to v9.0.83 - Fix for CVE-2023-46589
2023-12-11 13:36:26 +01:00
Andre Henn 7bd08f9734
use current geoserver stable release v2.24.1 2023-12-11 10:55:23 +01:00
Andre Henn 1b9b033dee
increase tomcat version to v9.0.83 2023-12-11 10:36:04 +01:00
jashan 7c087d2f46 - Added reference to JAVA and CATALINA docs
- Added reference to the osgeo repository
2023-12-02 11:09:54 +09:00
jashan 6e80acf8cd - Separate table for non-configurable Vars 2023-12-02 11:09:54 +09:00
jashan 5c44368b20 Updated README.md with env vars 2023-12-02 11:09:54 +09:00
Nils Bühner ec6273055a
Merge pull request #31 from mbosecke/jndi
Added support for a PostgreSQL JNDI resource.
2023-11-13 16:06:42 +01:00
Mitchell Bösecke 8be469744c Fixed default value for JNDI resource.
In Apache tomcat we have to name it "jdbc/postgres" while in Geoserver we have to name it "java:comp/env/jdbc/postgres".
2023-11-09 10:04:28 -07:00
Mitchell Bösecke 70d948e7c8 Increasing default max size of JNDI connection pool from 8 to 25. It just feels like a more reasonable default value. 2023-11-09 08:59:33 -07:00