diff --git a/bitnami/drupal/11/debian-12/Dockerfile b/bitnami/drupal/11/debian-12/Dockerfile index a54ee7e763f7..fdf91b02b0c5 100644 --- a/bitnami/drupal/11/debian-12/Dockerfile +++ b/bitnami/drupal/11/debian-12/Dockerfile @@ -7,7 +7,7 @@ ARG DOWNLOADS_URL="downloads.bitnami.com/files/stacksmith" ARG TARGETARCH LABEL org.opencontainers.image.base.name="docker.io/bitnami/minideb:bookworm" \ - org.opencontainers.image.created="2026-05-20T20:50:09Z" \ + org.opencontainers.image.created="2026-05-22T13:19:32Z" \ org.opencontainers.image.description="Application packaged by Broadcom, Inc." \ org.opencontainers.image.documentation="https://github.com/bitnami/containers/tree/main/bitnami/drupal/README.md" \ org.opencontainers.image.source="https://github.com/bitnami/containers/tree/main/bitnami/drupal" \ @@ -29,7 +29,7 @@ RUN --mount=type=secret,id=downloads_url,env=SECRET_DOWNLOADS_URL \ mkdir -p /tmp/bitnami/pkg/cache/ ; cd /tmp/bitnami/pkg/cache/ || exit 1 ; \ COMPONENTS=( \ "render-template-1.0.9-165-linux-${OS_ARCH}-debian-12" \ - "php-8.4.21-2-linux-${OS_ARCH}-debian-12" \ + "php-8.4.21-3-linux-${OS_ARCH}-debian-12" \ "mysql-client-12.2.2-0-linux-${OS_ARCH}-debian-12" \ "libphp-8.4.21-0-linux-${OS_ARCH}-debian-12" \ "postgresql-lib-18.4.0-0-linux-${OS_ARCH}-debian-12" \ @@ -61,7 +61,7 @@ ENV APACHE_HTTPS_PORT_NUMBER="" \ APACHE_HTTP_PORT_NUMBER="" \ APP_VERSION="11.3.10" \ BITNAMI_APP_NAME="drupal" \ - IMAGE_REVISION="0" \ + IMAGE_REVISION="1" \ LD_LIBRARY_PATH="/opt/bitnami/postgresql/lib:$LD_LIBRARY_PATH" \ PATH="/opt/bitnami/common/bin:/opt/bitnami/php/bin:/opt/bitnami/php/sbin:/opt/bitnami/mysql/bin:/opt/bitnami/apache/bin:/opt/bitnami/drupal/vendor/bin:$PATH" diff --git a/bitnami/drupal/11/debian-12/docker-compose.yml b/bitnami/drupal/11/debian-12/docker-compose.yml index fcae9491700e..5dce650ef81d 100644 --- a/bitnami/drupal/11/debian-12/docker-compose.yml +++ b/bitnami/drupal/11/debian-12/docker-compose.yml @@ -17,6 +17,7 @@ services: - '80:8080' - '443:8443' environment: + - DRUPAL_PASSWORD=bitnami - DRUPAL_DATABASE_HOST=mariadb - DRUPAL_DATABASE_PORT_NUMBER=3306 - DRUPAL_DATABASE_USER=bn_drupal diff --git a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/drupal-env.sh b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/drupal-env.sh index 92e7e7d46d39..6f24caa485ad 100644 --- a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/drupal-env.sh +++ b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/drupal-env.sh @@ -87,7 +87,7 @@ export DRUPAL_HASH_SALT="${DRUPAL_HASH_SALT:-}" # only used during the first ini # Drupal credentials export DRUPAL_USERNAME="${DRUPAL_USERNAME:-user}" # only used during the first initialization -export DRUPAL_PASSWORD="${DRUPAL_PASSWORD:-bitnami}" # only used during the first initialization +export DRUPAL_PASSWORD="${DRUPAL_PASSWORD:-}" # only used during the first initialization export DRUPAL_EMAIL="${DRUPAL_EMAIL:-user@example.com}" # only used during the first initialization # Drupal SMTP credentials diff --git a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libapache.sh b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libapache.sh index d6eb686df3f6..0e1a4818ccc7 100644 --- a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libapache.sh +++ b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libapache.sh @@ -803,6 +803,10 @@ apache_create_password_file() { local -r username="${2:?missing username}" local -r password="${3:?missing password}" - "${APACHE_BIN_DIR}/htpasswd" -bc "$file" "$username" "$password" - am_i_root && configure_permissions_ownership "$file" --file-mode "600" --user "$APACHE_DAEMON_USER" --group "$APACHE_DAEMON_GROUP" + # The -B flag uses bcrypt to hash the password, which is more secure than legacy APR1 (1000-iteration MD5) hash + # The -C flag computing time used for the bcrypt algorithm (default is 5) + "${APACHE_BIN_DIR}/htpasswd" -Bbc -C 12 "$file" "$username" "$password" + am_i_root && configure_permissions_ownership "$file" --user "$APACHE_DAEMON_USER" --group "$APACHE_DAEMON_GROUP" + # We can set strong permissions regardless the container is running as root or not + chmod 0600 "$file" } diff --git a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libdrupal.sh b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libdrupal.sh index 9efbf2f8d407..117fbbb9a54e 100644 --- a/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libdrupal.sh +++ b/bitnami/drupal/11/debian-12/rootfs/opt/bitnami/scripts/libdrupal.sh @@ -50,6 +50,12 @@ drupal_validate() { fi } + check_empty_value() { + if is_empty_value "${!1}"; then + print_validation_error "${1} must be set" + fi + } + check_yes_no_value() { if ! is_yes_no_value "${!1}" && ! is_true_false_value "${!1}"; then print_validation_error "The allowed values for ${1} are: yes no" @@ -85,12 +91,11 @@ drupal_validate() { check_mounted_file "DRUPAL_DATABASE_TLS_CA_FILE" # Validate database credentials + check_empty_value "DRUPAL_PASSWORD" if is_boolean_yes "$ALLOW_EMPTY_PASSWORD"; then warn "You set the environment variable ALLOW_EMPTY_PASSWORD=${ALLOW_EMPTY_PASSWORD}. For safety reasons, do not use this flag in a production environment." else - for empty_env_var in "DRUPAL_DATABASE_PASSWORD" "DRUPAL_PASSWORD"; do - is_empty_value "${!empty_env_var}" && print_validation_error "The ${empty_env_var} environment variable is empty or not set. Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow a blank password. This is only recommended for development environments." - done + is_empty_value "$DRUPAL_DATABASE_PASSWORD" && print_validation_error "The DRUPAL_DATABASE_PASSWORD environment variable is empty or not set. Set the environment variable ALLOW_EMPTY_PASSWORD=yes to allow a blank password. This is only recommended for development environments." fi # Validate SMTP credentials @@ -283,11 +288,23 @@ drupal_site_install() { PHP_OPTIONS="-d sendmail_path=$(which true)" export PHP_OPTIONS + # Avoid passing Drupal & database password as arguments to drush, to avoid leaking them given + # given a local observer with /proc read access can read them + # Instead, we can read them from temporary files + local drush_password_file database_url_file + drush_password_file="$(mktemp)" + database_url_file="$(mktemp)" + chmod 0600 "$drush_password_file" "$database_url_file" + echo "$DRUPAL_PASSWORD" > "$drush_password_file" + echo "mysql://${DRUPAL_DATABASE_USER}:${DRUPAL_DATABASE_PASSWORD}@${DRUPAL_DATABASE_HOST}:${DRUPAL_DATABASE_PORT_NUMBER}/${DRUPAL_DATABASE_NAME}" > "$database_url_file" + # shellcheck disable=SC2064 + trap "rm -f $drush_password_file $database_url_file" RETURN ERR INT TERM + drush_execute "site:install" \ - "--db-url=mysql://${DRUPAL_DATABASE_USER}:${DRUPAL_DATABASE_PASSWORD}@${DRUPAL_DATABASE_HOST}:${DRUPAL_DATABASE_PORT_NUMBER}/${DRUPAL_DATABASE_NAME}" \ + "--db-url=$(<"$database_url_file")" \ "--account-name=${DRUPAL_USERNAME}" \ "--account-mail=${DRUPAL_EMAIL}" \ - "--account-pass=${DRUPAL_PASSWORD}" \ + "--account-pass=$(<"$drush_password_file")" \ "--site-name=${DRUPAL_SITE_NAME}" \ "--site-mail=${DRUPAL_EMAIL}" \ "-y" "$DRUPAL_PROFILE" diff --git a/bitnami/drupal/README.md b/bitnami/drupal/README.md index 943cdff2cf01..4cc691cf3882 100644 --- a/bitnami/drupal/README.md +++ b/bitnami/drupal/README.md @@ -86,7 +86,7 @@ The following tables list the main variables you can set. | `DRUPAL_CONFIG_SYNC_DIR` | Drupal sync configuration directory location. Only used when `DRUPAL_SKIP_BOOTSTRAP` is enabled. | `nil` | | `DRUPAL_HASH_SALT` | Drupal string used to generate random values. Only used when `DRUPAL_SKIP_BOOTSTRAP` is enabled. | `nil` | | `DRUPAL_USERNAME` | Drupal user name. | `user` | -| `DRUPAL_PASSWORD` | Drupal user password. | `bitnami` | +| `DRUPAL_PASSWORD` | Drupal user password. | `nil` | | `DRUPAL_EMAIL` | Drupal user e-mail address. | `user@example.com` | | `DRUPAL_SMTP_HOST` | Drupal SMTP server host. | `nil` | | `DRUPAL_SMTP_PORT_NUMBER` | Drupal SMTP server port number. | `25` | diff --git a/bitnami/drupal/docker-compose.yml b/bitnami/drupal/docker-compose.yml index fcae9491700e..5dce650ef81d 100644 --- a/bitnami/drupal/docker-compose.yml +++ b/bitnami/drupal/docker-compose.yml @@ -17,6 +17,7 @@ services: - '80:8080' - '443:8443' environment: + - DRUPAL_PASSWORD=bitnami - DRUPAL_DATABASE_HOST=mariadb - DRUPAL_DATABASE_PORT_NUMBER=3306 - DRUPAL_DATABASE_USER=bn_drupal