Self-hosting deployment with podman(docker) all-in-one

Overview


Linux containers can be thought as lightweight disposable virtual machine since they provide a way to virtualize software with less resource usage than full-featured virtual machines as containers share the same kernel and are based on process isolation rather than hardware emulation. By using containers, server software, including MWiki can be deployed isolated from the host machine in a secure fashion without causing disruptions or breaking changes. Moreover, as containers are sandboxed by default, they are able to mitigate and limit the reach of security vulnerabilities in the host machine if any container is ever compromised.

The all-in-one container provides an easy and lightweight approach to deploy MWiki with everything pre configured, including Mwiki server and Caddy web server in a single docker or podman container. Caddy web server is used for serving static files and providing TLS (Transport Layer Security), also known as SSL - Socket Layer Security, by encrypting the network traffic between the server and a client web browser.

Installation


Disable SELinux

Since SELinux may cause podman to fail with the error [Errno 13] Permission denied: ..., it may be worth to disable SELinux by using

sudo setenforce 0

for temporarily disabling SELinux.

See

Build the Podman Container Image

Clone the repository and enter its root folder.

git clone https://github.com/caiorss/mwiki && cd mwiki

Build the container image using podman (recommended).

podman build -t mwiki  --file docker/all-in-one.Dockerfile .

Build the container image using docker.

docker build -t mwiki  --file docker/all-in-one.Dockerfile .

Open Firewall Ports

In some Linux distributions or other operating systems, TCP and UDP ports are blocked by default for security reasons. As a result, it may be necessary to open TCP ports by changing the firewall settings in order to be able to access MWiki or any other web server from other computers or devices.

Microsoft Windows: Open port 80 (http) and 443 (https) in Microsoft Windows (requires opening a terminal with administrator privilegees).

netsh firewall add portopening TCP 80 "MWIki server port"
netsh firewall add portopening TCP 443 "MWIki server port"

Linux / IPtables: Open TCP ports 80 and 443 in Linux with Iptables (Default Linux firewall, all other Linux firewalls are wrappers around Iptables).

sudo iptables -A INPUT -p tcp --dport 80 -j ACCEPT
sudo iptables -A INPUT -p tcp --dport 443 -j ACCEPT

Linux / UFW: Open port 80 and 443 in Linux with UFW (Uncomplicated Firewall), mostly used by Debian and Ubuntu derived Linux distributions.

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Linux / Firewalld: Open port 80 and 443 in Linux with firewalld.

sudo firewall-cmd --add-port=80/tcp --permanent
sudo firewall-cmd --add-port=443/tcp --permanent
sudo firewall-cmd --reload

See also

Set the environment variables.

export MWIKI_WEBSISTE="https://mydomain.com"
export MWIKI_URL="https://mydomain.com"
export MWIKI_FOLDER=/home/username/wiki

If the websiste is not public use

export MWIKI_PUBLIC=false

If the website is public (anyone can view), set the environment variable MWIKI_PUBLIC to true. The default value of this setting is false.

export MWIKI_PUBLIC=true

Set the Wiki name (website name).

export MWIKI_SITENAME=MBook

Create the container

This step creates podman container, which is equivalent to a lightweight virtual machine, detached from the terminal.

podman run --name=mwiki --detach  \
    --publish=80:80 --publish=443:443  \
    --env MWIKI_URL=$MWIKI_URL \
    --env=MWIKI_SITENAME=$MWIKI_SITENAME \
    --env=MWIKI_PUBLIC=$MWIKI_PUBLIC \
    --env MWIKI_WEBSITE="$MWIKI_WEBSITE" \
    --volume $MWIKI_FOLDER:/wiki mwiki

Now, the website will be available at

To deploy on local host set the website environment variable to

export MWIKI_WEBSITE="localhost http://[MACHINE-HOSTNAME].local"

The machine hostname can be obtained using the commmand $ hostname on Windows, Linux and other Unix-like operating systems.

$ hostname
dummy

So, the url of this dummy machine on the local network would be

Logging in / Authentication

It is possible to log in without password by using a temporary magic hyperlink using the command

podman exec -it mwiki mwiki-auth

Output:

Copy and paste the following URL in the web browser to authenticate.

  https://mydomain.com/auth?token=eyJ1c2VyIjogImFkbWluIiwgInNhbHQiOiAxNzQsICJleHBpcmF0aW9uIjogMTc2OTA4MDU0NiwgInNpZ25hdHVyZSI6ICIxNTVlZDYxOTRhYTE5MTNmMzhkYWMzODI3ZTJiZTdiNzdiNGQ0NzVhYzVjMmJlNDU2ZTY5ZmViNTRiOTg0OGU4In0%3D

Or paste the following token in the log in form https://mydomain.com

 eyJ1c2VyIjogImFkbWluIiwgInNhbHQiOiAxNzQsICJleHBpcmF0aW9uIjogMTc2OTA4MDU0NiwgInNpZ25hdHVyZSI6ICIxNTVlZDYxOTRhYTE5MTNmMzhkYWMzODI3ZTJiZTdiNzdiNGQ0NzVhYzVjMmJlNDU2ZTY5ZmViNTRiOTg0OGU4In0=

NOTE: This URL is only valid for 20 seconds.
NOTE: If MWiki URL is not correct, set the environment variable $MWIKI_URL to the app URL.For instance, in bash Unix shell $ export MWIKI_URL=https://mydomain.com before running this comamnd again.

Then, copy this url to the web browser to log in. Note that the magic login link is valid only for 20 seconds. After this step, the user can set the administrator password. MWiki does not use a hardcoded default password, instead it generates a random default password for every wiki.

Common Operations

The previous command for creating the container needs to be run only once. After the last step, the following commands can be used for managing the container.

View the MWiki container's logs:

podman logs --tail=50 -f mwiki

Stop the MWiki container:

podman stop mwiki

Start the MWiki container:

podman start mwiki

Delete MWiki container[1]:

podman rm mwiki

Further Reading