mirror of
https://github.com/UNITRONIX/BetterDesk.git
synced 2026-10-05 12:55:05 +00:00
923602d679
Add a device verification/enrollment workflow so new registrations are held for operator review instead of connecting silently. Go server (signal + api): - Signal-mode pending: in 'managed' mode, unknown stock RustDesk clients are queued (pending_device_<id>) instead of being silently rejected. - Rich approve: handleApproveDevice accepts display_name, sync_mode and normalized tags; handleRejectDevice supports an optional ban. Node.js console: - registrations.ejs approve modal (name, sync mode, tags, folder) and reject modal with ban option; betterdeskApi + routes wire display_name, sync_mode, tags and folder assignment through to the Go server. - EN/PL/ZH i18n for all new strings. Installers (managed default for FRESH installs only; existing installs stay on the Go default 'open' or their DB-persisted mode): - betterdesk.sh / betterdesk.ps1 write ENROLLMENT_MODE=managed to the server env only when no existing database is detected (FRESH_INSTALL). - Docker single + multi container entrypoints detect fresh volumes via a sentinel plus id_ed25519/db_v2.sqlite3 presence and default to managed; ENROLLMENT_MODE is now passed through supervisord and all compose files. This commit was made possible thanks to Insolve.
130 lines
4.5 KiB
YAML
130 lines
4.5 KiB
YAML
# =============================================================================
|
|
# BetterDesk Console - Quick Start (Pre-built Images)
|
|
# =============================================================================
|
|
# NO BUILD REQUIRED - uses pre-built images from GitHub Container Registry
|
|
#
|
|
# Usage:
|
|
# curl -fsSL https://raw.githubusercontent.com/UNITRONIX/Rustdesk-FreeConsole/main/docker-compose.quick.yml -o docker-compose.yml
|
|
# docker compose up -d
|
|
#
|
|
# Web Console: http://localhost:5000
|
|
# Default credentials are written to the shared credentials file:
|
|
# docker compose exec console sh -c 'cat /opt/rustdesk/.admin_credentials 2>/dev/null || cat /app/data/.admin_credentials'
|
|
#
|
|
# TROUBLESHOOTING: If you get "denied" or "pull access denied" error,
|
|
# images may not be published yet. Build from source instead:
|
|
# git clone https://github.com/UNITRONIX/Rustdesk-FreeConsole.git
|
|
# cd Rustdesk-FreeConsole && docker compose -f docker-compose.yml up -d --build
|
|
# =============================================================================
|
|
|
|
services:
|
|
# BetterDesk Server (Go) — handles signal, relay, and API
|
|
server:
|
|
image: ghcr.io/unitronix/betterdesk-server:latest
|
|
container_name: betterdesk-server
|
|
hostname: betterdesk-server
|
|
command: ["/usr/local/bin/betterdesk-server", "-mode", "all", "-api-port", "21121", "-key-file", "/opt/rustdesk/id_ed25519"]
|
|
ports:
|
|
- "21121:21121" # HTTP API (RustDesk client + REST, WAN-facing)
|
|
- "21115:21115" # NAT type test
|
|
- "21116:21116/tcp" # Signal TCP
|
|
- "21116:21116/udp" # Signal UDP
|
|
- "21117:21117" # Relay TCP
|
|
- "21118:21118" # WebSocket Signal
|
|
- "21119:21119" # WebSocket Relay
|
|
volumes:
|
|
- betterdesk-data:/opt/rustdesk
|
|
environment:
|
|
- ENCRYPTED_ONLY=1
|
|
# Set this when clients are outside the Docker network. Use the host's
|
|
# public IP/DNS, or the host LAN IP for LAN-only deployments.
|
|
# Example: RELAY_SERVERS=203.0.113.10:21117 docker compose up -d
|
|
- RELAY_SERVERS=${RELAY_SERVERS:-}
|
|
- SIGNAL_RATE_LIMIT_PER_IP=${SIGNAL_RATE_LIMIT_PER_IP:-20}
|
|
# Enrollment policy. Fresh volumes default to "managed" (operator approves
|
|
# new devices); pre-existing volumes keep their current mode. Override with
|
|
# "open", "managed", or "locked".
|
|
- ENROLLMENT_MODE=${ENROLLMENT_MODE:-}
|
|
networks:
|
|
- betterdesk-net
|
|
restart: unless-stopped
|
|
# SECURITY (audit fix L-02, 2026-04-10): drop all capabilities except
|
|
# those needed by the entrypoint to chown volumes + su-exec to non-root.
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|
|
cap_add:
|
|
- SETUID
|
|
- SETGID
|
|
- CHOWN
|
|
- FOWNER
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-q", "--spider", "http://localhost:21121/api/health"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 15s
|
|
|
|
# BetterDesk Console — Web Management Interface
|
|
console:
|
|
image: ghcr.io/unitronix/betterdesk-console:latest
|
|
container_name: betterdesk-console
|
|
hostname: betterdesk-console
|
|
ports:
|
|
- "5000:5000" # Web console (admin panel)
|
|
volumes:
|
|
- betterdesk-data:/opt/rustdesk
|
|
- console-data:/app/data
|
|
environment:
|
|
- NODE_ENV=production
|
|
- PORT=5000
|
|
- HOST=0.0.0.0
|
|
- API_HOST=0.0.0.0
|
|
- API_ENABLED=false
|
|
- SERVER_BACKEND=betterdesk
|
|
- BETTERDESK_API_URL=http://betterdesk-server:21121/api
|
|
- RUSTDESK_PATH=/opt/rustdesk
|
|
- DATA_DIR=/app/data
|
|
- DB_PATH=/app/data/db_v2.sqlite3
|
|
- PUB_KEY_PATH=/opt/rustdesk/id_ed25519.pub
|
|
- API_KEY_PATH=/opt/rustdesk/.api_key
|
|
- WS_HBBS_HOST=betterdesk-server
|
|
- WS_HBBS_PORT=21116
|
|
- WS_HBBR_HOST=betterdesk-server
|
|
- WS_HBBR_PORT=21117
|
|
- DOCKER=true
|
|
networks:
|
|
- betterdesk-net
|
|
depends_on:
|
|
server:
|
|
condition: service_healthy
|
|
restart: unless-stopped
|
|
# L-02: drop caps + no privilege escalation for Node.js console.
|
|
# SETUID/SETGID needed by su-exec; CHOWN/FOWNER for volume permissions.
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
cap_drop:
|
|
- ALL
|
|
cap_add:
|
|
- SETUID
|
|
- SETGID
|
|
- CHOWN
|
|
- FOWNER
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-q", "--spider", "http://localhost:5000/login"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 20s
|
|
|
|
networks:
|
|
betterdesk-net:
|
|
driver: bridge
|
|
|
|
volumes:
|
|
betterdesk-data:
|
|
name: betterdesk-data
|
|
console-data:
|
|
name: betterdesk-console-data
|