瀏覽代碼

Don't disable network access from outside

Christoph Knittel 10 年之前
父節點
當前提交
039a7ffcf9
共有 2 個文件被更改,包括 4 次插入12 次删除
  1. 4 6
      image/Dockerfile
  2. 0 6
      image/service/install.sh

+ 4 - 6
image/Dockerfile

@@ -12,13 +12,11 @@ RUN apt-get -y update && /sbin/enable-service ssl-kit \
 	&& LC_ALL=C DEBIAN_FRONTEND=noninteractive apt-get install -y --force-yes --no-install-recommends slapd ldap-utils \
 	&& rm -rf /var/lib/ldap
 
-# Add install script and OpenLDAP assets
-ADD service/install.sh /tmp/install.sh
+# Add OpenLDAP assets
 ADD service/slapd/assets /osixia/slapd
 
-# Run install script and clean all
-RUN ./tmp/install.sh \
-    && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
+# Clean all
+RUN apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/*
 
 # Add default env variables
 ADD env.yml /etc/env.yml
@@ -31,4 +29,4 @@ ADD service/slapd/daemon.sh /etc/service/slapd/run
 VOLUME ["/var/lib/ldap", "/etc/ldap/slapd.d"]
 
 # Expose ldap default port
-EXPOSE 389
+EXPOSE 389

+ 0 - 6
image/service/install.sh

@@ -1,6 +0,0 @@
-#!/bin/bash -e
-# this script is run during the image build
-
-# Enable access only from docker default network and localhost
-echo "slapd: 172.17.0.0/255.255.0.0 127.0.0.1 : ALLOW" >> /etc/hosts.allow
-echo "slapd: ALL : DENY" >> /etc/hosts.allow