Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Multi-arch Ragnar image (amd64 + arm64):
- # Headless by default (uses headlessRagnar.py)
- # No dependency on install_ragnar.sh (installs deps declaratively)
- # - Safe "sudo" behavior: no-op ONLY when already root (prevents password/TTY errors)
- # - Optional Pi hardware deps (RPi.GPIO/spidev) when ENABLE_PI_HARDWARE=1 on arm64
- #
- # Build examples:
- # docker buildx build --platform linux/amd64,linux/arm64 -t ragnar:latest .
- # docker buildx build --platform linux/arm64 -t ragnar:pi --build-arg ENABLE_PI_HARDWARE=1 .
- #
- # Run on Linux for visibility:
- # docker run --rm -p 8000:8000 --cap-add=NET_RAW --cap-add=NET_ADMIN --network host ragnar:latest
- #
- # Run with port publishing (no host networking):
- # docker run --rm -p 8000:8000 --cap-add=NET_RAW --cap-add=NET_ADMIN ragnar:latest
- FROM ubuntu:22.04
- ARG TARGETARCH
- ARG ENABLE_PI_HARDWARE=0
- ENV DEBIAN_FRONTEND=noninteractive \
- PYTHONDONTWRITEBYTECODE=1 \
- PYTHONUNBUFFERED=1 \
- HEADLESS_MODE=true
- # Base OS deps + common network tooling Ragnar tends to call
- RUN apt-get update && apt-get install -y --no-install-recommends \
- bash \
- ca-certificates \
- curl \
- git \
- python3 \
- python3-pip \
- python3-dev \
- build-essential \
- linux-libc-dev \
- iproute2 \
- iputils-ping \
- net-tools \
- nmap \
- arp-scan \
- tcpdump \
- sqlite3 \
- network-manager \
- sqlmap \
- nikto \
- whatweb \
- wireless-tools \
- bluez \
- bridge-utils \
- libopenblas-dev \
- hostapd \
- iproute2 \
- iputils-ping \
- rfkill \
- && rm -rf /var/lib/apt/lists/*
- WORKDIR /opt/ragnar
- # Clone Ragnar
- RUN git clone https://github.com/PierreGode/Ragnar.git . \
- && git submodule update --init --recursive
- # ---- Make "sudo" not break headless/container runs ----
- # Ragnar (or tools it calls) may prefix commands with sudo.
- # This shim:
- # - if already root: executes the command (acts like sudo)
- # - if not root: fails loudly (no insecure passwordless escalation)
- RUN cat >/usr/local/bin/sudo <<'SH' \
- && chmod +x /usr/local/bin/sudo
- #!/bin/sh
- if [ "$(id -u)" -eq 0 ]; then
- exec "$@"
- fi
- echo "sudo: this container is not running as root; start it with --user root (or add needed capabilities) instead." >&2
- exit 1
- SH
- # ---- Python deps ----
- # For headless/container, Pi hardware libs often aren't useful.
- # Optionally enable them on arm64 with ENABLE_PI_HARDWARE=1.
- RUN pip3 install --upgrade pip
- RUN if [ -f requirements.txt ]; then \
- if [ "$ENABLE_PI_HARDWARE" = "1" ] && [ "$TARGETARCH" = "arm64" ]; then \
- pip3 install --no-cache-dir -r requirements.txt ; \
- else \
- grep -vE '^(RPi\.GPIO|spidev)\b' requirements.txt > /tmp/requirements.docker.txt && \
- pip3 install --no-cache-dir -r /tmp/requirements.docker.txt ; \
- fi ; \
- fi
- # Ensure these exist even if upstream requirements change
- RUN pip3 install --no-cache-dir requests flask colorama netifaces
- # Simple import sanity check
- RUN python3 - <<'PY'
- import requests, flask, colorama, netifaces
- print("requests:", requests.__version__)
- print("flask:", flask.__version__)
- print("colorama:", getattr(colorama, "__version__", "unknown"))
- print("netifaces ok")
- PY
- # Data dir for cache/output if needed
- RUN mkdir -p /data
- EXPOSE 8000
- HEALTHCHECK --interval=30s --timeout=3s --start-period=20s --retries=3 \
- CMD curl -fsS http://localhost:8000/ || exit 1
- # Run as root by default (network tools often require it).
- # If you want non-root, add a user + drop privileges, but expect to need caps and to remove sudo usage.
- CMD ["python3", "headlessRagnar.py", "--host", "0.0.0.0"]
Advertisement