Fix FTP proxy port 990 permission denied in Docker

cap_add: NET_BIND_SERVICE in docker-compose.yml doesn't reliably
propagate to the Python process when combined with the user: directive
(depends on ambient capability support in the container runtime).
Set the file capability directly on the Python binary via setcap in
the Dockerfile, which the kernel honors regardless of runtime config.
This commit is contained in:
maziggy
2026-02-27 10:25:48 +01:00
parent 55c332d91a
commit d91d95a1ec
2 changed files with 7 additions and 0 deletions
+6
View File
@@ -23,8 +23,14 @@ ENV DEBIAN_FRONTEND=noninteractive
RUN apt-get update && apt-get install -y --no-install-recommends \
curl \
ffmpeg \
libcap2-bin \
&& rm -rf /var/lib/apt/lists/*
# Allow binding to privileged ports (e.g. 990/FTPS) as non-root user.
# File capabilities are more reliable than Docker cap_add with user: directive,
# which depends on ambient capability support in the container runtime.
RUN setcap cap_net_bind_service=+ep "$(readlink -f /usr/local/bin/python3)"
# Install Python dependencies with cache mount
COPY requirements.txt ./
RUN --mount=type=cache,target=/root/.cache/pip \