This container uses standard clamav binaries but with additional community driven signatures from sanesecurity.com, sigs.interserver.net, rfxn.com and urlhaus.abuse.ch that will improve detection rates.
Updates to clamav binaries and signatures are done automatically, the app files_antivirus is installed and configured automatically. There is no backup of the volume because it does only hold current signatures.
This is a follow up to discussion #6563
Signed-off-by: derStephan <derStephan@users.noreply.github.com>
- reduce redundancy and help to prevent errors for newly added redirections
- Add sections for geoblocking, IP allow lists, custom configuration and proxy protocol
- Add table of supported community containers with geoblocking, IP allow list and authentication support
- Add configuration examples for custom caddy configurations
- Fix minor language issues
Signed-off-by: derStephan <derStephan@users.noreply.github.com>
dnsmasq runs in host network mode and auto-detects the host's LAN IP. On
Docker Desktop (Windows/macOS) containers run inside a Linux VM isolated
from the real host LAN, so detection yields the wrong IP and local DNS
resolution does not work. Call this out in the dnsmasq readme and the
in-app deSEC domain notice.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
- caddy.json: pass DESEC_TOKEN to the caddy container so it can solve the DNS-01
challenge for the registered dedyn.io domain.
- community-containers.twig: when the domain was registered via deSEC, explain
that caddy and dnsmasq were enabled automatically and link the required dnsmasq
router change, with a caution to disable dnsmasq on publicly reachable hosts.
- compose.yaml: mention the built-in deSEC free domain option alongside Tailscale
in the reverse-proxy hint.
Co-Authored-By: szaimen <42591237+szaimen@users.noreply.github.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Add AzuraCast community container
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* Update Caddy readme to mention AzuraCast
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: consolidate storage/* volumes into single storage volume
Replace seven granular mounts under /var/azuracast/storage with a single
nextcloud_aio_azuracast_storage volume, matching AzuraCast's official
docker-compose layout. Remove nextcloud_aio_azuracast_uploads from
backup_volumes (media files are captured via stations and AzuraCast's
own backup archives in /var/azuracast/backups).
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: change HTTP/HTTPS ports to 10080/10443, expose on host
Use ports recommended by AzuraCast docs for reverse proxy deployments.
Expose port 10080 (HTTP) with %APACHE_IP_BINDING% following the vaultwarden
pattern, and port 10443 (HTTPS) on all interfaces for direct access.
Update readme accordingly.
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: replace shared volume with %NEXTCLOUD_MOUNT%, document filesystem sharing
Replace the named volume nextcloud_aio_azuracast_shared with the AIO-native
%NEXTCLOUD_MOUNT% mechanism. The volume is silently skipped if NEXTCLOUD_MOUNT
is not configured in AIO.
Update readme.md:
- Document NEXTCLOUD_MOUNT as the advanced file sharing approach, with setup
instructions and a comparison to the SFTP approach
- Clarify default access behavior: files (mode 644) are world-readable by both
processes; some AzuraCast directories (mode 700) require intervention
- Document POSIX ACL commands for unlocking read-only or bidirectional access
on specific paths, with a note that they must be re-run after structural
changes by AzuraCast
- Minor wording and formatting improvements throughout
Tested on a live AzuraCast instance: rename and bidirectional move confirmed
working after ACL application; containers start correctly without UMASK override.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* Update community-containers/azuracast/azuracast.json
Do not expose internal HTTP port 10080 on host.
Co-authored-by: Simon L. <szaimen@e.mail.de>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* azuracast: add to community containers overview diagram
Add AzuraCast entry to the Media group of the mermaid overview
diagram in community-containers/readme.md, as requested by szaimen.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
* fix the json
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Apply suggestion from @szaimen
Signed-off-by: Simon L. <szaimen@e.mail.de>
* Apply suggestion from @szaimen
Signed-off-by: Simon L. <szaimen@e.mail.de>
---------
Signed-off-by: Nicolas Binette <biguenique@nuee.cc>
Signed-off-by: Simon L. <szaimen@e.mail.de>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: Simon L. <szaimen@e.mail.de>