Compare commits
10 Commits
d52b173da5
...
testing
Author | SHA1 | Date | |
---|---|---|---|
|
7420297586 | ||
|
dec7bf5321 | ||
|
71a5ed9992 | ||
|
26dc8f6b4b | ||
|
29cdc18b4e | ||
|
59f372024b | ||
|
29780d29d9 | ||
|
fd7732dec2 | ||
|
01d32801e9 | ||
|
e4c5735966 |
70
Dockerfile
70
Dockerfile
@@ -1,70 +0,0 @@
|
|||||||
# Dockerfile
|
|
||||||
|
|
||||||
# Docker image for TYPO3 CMS
|
|
||||||
FROM php:8.2-apache
|
|
||||||
|
|
||||||
LABEL maintainer="Raphael Martin <raphy.martin@protonmail.ch>"
|
|
||||||
|
|
||||||
ENV APACHE_RUN_USER a2g-www
|
|
||||||
ENV TYPO3_VERSION 12.4.8
|
|
||||||
ENV TYPO3_SHA256CHECKSUM 8293b3441ec133fc8f9174fab5b88f450044ded0e188a0f12de37ad60a8bf8b3
|
|
||||||
|
|
||||||
# change apache user
|
|
||||||
RUN adduser --uid 1000 --gecos 'Apache User' --disabled-password $APACHE_RUN_USER \
|
|
||||||
&& chown -R "$APACHE_RUN_USER:$APACHE_RUN_USER" /var/lock/apache2 /var/run/apache2
|
|
||||||
|
|
||||||
# update system
|
|
||||||
RUN apt-get update -y && apt-get upgrade -y
|
|
||||||
|
|
||||||
# Install TYPO3
|
|
||||||
RUN apt-get install -y --no-install-recommends \
|
|
||||||
wget \
|
|
||||||
# Configure PHP
|
|
||||||
libxml2-dev libfreetype6-dev \
|
|
||||||
libjpeg62-turbo-dev \
|
|
||||||
libmcrypt-dev \
|
|
||||||
libpng-dev \
|
|
||||||
libpq-dev \
|
|
||||||
libzip-dev \
|
|
||||||
zlib1g-dev \
|
|
||||||
sendmail \
|
|
||||||
graphicsmagick && \
|
|
||||||
docker-php-ext-configure gd --with-libdir=/usr/include/ --with-jpeg --with-freetype && \
|
|
||||||
docker-php-ext-install -j$(nproc) mysqli soap gd zip opcache intl pgsql pdo_pgsql
|
|
||||||
|
|
||||||
# Clean
|
|
||||||
RUN apt-get -y purge \
|
|
||||||
libxml2-dev libfreetype6-dev \
|
|
||||||
libjpeg62-turbo-dev \
|
|
||||||
libmcrypt-dev \
|
|
||||||
libpng-dev \
|
|
||||||
libzip-dev \
|
|
||||||
zlib1g-dev && \
|
|
||||||
apt-get clean && \
|
|
||||||
rm -rf /var/lib/apt/lists/* /usr/src/*
|
|
||||||
|
|
||||||
RUN mkdir /usr/local/surf && \
|
|
||||||
curl -L https://github.com/TYPO3/Surf/releases/download/3.4.6/surf.phar -o /usr/local/surf/surf.phar && \
|
|
||||||
chmod +x /usr/local/surf/surf.phar && \
|
|
||||||
ln -s /usr/local/surf/surf.phar /usr/local/bin/surf
|
|
||||||
|
|
||||||
# Configure Apache as needed
|
|
||||||
RUN a2enmod rewrite
|
|
||||||
|
|
||||||
RUN cd /tmp && \
|
|
||||||
wget -O download.tar.gz https://get.typo3.org/${TYPO3_VERSION} && \
|
|
||||||
echo "${TYPO3_SHA256CHECKSUM} /tmp/download.tar.gz" > /tmp/download.tar.gz.sum
|
|
||||||
|
|
||||||
RUN sha256sum -c "/tmp/download.tar.gz.sum"
|
|
||||||
|
|
||||||
RUN tar -xzf /tmp/download.tar.gz -C /var/www/ && \
|
|
||||||
rm /tmp/download*
|
|
||||||
|
|
||||||
RUN cd /var/www/html && \
|
|
||||||
ln -s ../typo3_src-* typo3_src && \
|
|
||||||
ln -s typo3_src/index.php && \
|
|
||||||
ln -s typo3_src/typo3 && \
|
|
||||||
touch FIRST_INSTALL
|
|
||||||
|
|
||||||
RUN chown -R $APACHE_RUN_USER:$APACHE_RUN_USER /var/www/html && \
|
|
||||||
chown -R $APACHE_RUN_USER:$APACHE_RUN_USER /var/www/typo3_src-*
|
|
2
LICENSE
2
LICENSE
@@ -1,6 +1,6 @@
|
|||||||
MIT License
|
MIT License
|
||||||
|
|
||||||
Copyright (c) 2023 a2g_dockerized
|
Copyright (c) 2023 altogether
|
||||||
|
|
||||||
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
|
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
|
||||||
|
|
||||||
|
34
README.md
34
README.md
@@ -21,16 +21,48 @@ sample .env:
|
|||||||
|
|
||||||
PROJECT_DATA=./data
|
PROJECT_DATA=./data
|
||||||
|
|
||||||
|
If you want to make the first install steps uncomment following line in your docker-compose.yml in the volumes configuration from the TYPO3.
|
||||||
|
|
||||||
|
# - "./LICENSE:/var/www/html/FIRST_INSTALL:ro"
|
||||||
|
|
||||||
|
after your the installation you should comment this part again thet your ${PROJECT_DATA}/typo3conf/system/settings.php from the will not change.
|
||||||
|
|
||||||
|
the container has just sendmail installed to change this you should change the settings.php for your mail and secure for the reversproxy.
|
||||||
|
|
||||||
|
for development:
|
||||||
|
|
||||||
|
'transport_sendmail_command' => '/usr/sbin/sendmail -bs',
|
||||||
|
|
||||||
|
and append / set:
|
||||||
|
|
||||||
|
['SYS'][
|
||||||
|
...
|
||||||
|
'systemLocale' => 'de_AT.UTF-8',
|
||||||
|
'reverseProxyHeaderMultiValue' => 'first',
|
||||||
|
'reverseProxyIP' => '127.0.0.1',
|
||||||
|
'features' => [
|
||||||
|
...
|
||||||
|
'security.backend.enforceReferrer] => false,
|
||||||
|
'security.backend.enforceContentSecurityPolicy' => false,
|
||||||
|
]
|
||||||
|
]
|
||||||
|
|
||||||
|
because we are behind the reverse proxy.
|
||||||
|
|
||||||
|
|
||||||
then execute init with
|
then execute init with
|
||||||
|
|
||||||
./init
|
./init
|
||||||
|
|
||||||
|
|
||||||
|
use in the install wizard for the db connection "db" and the port 3306 and use pdo_mysql driver.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
now the typo3 first install should be accessable: https://${PROJECT_URL}
|
now the typo3 first install should be accessable: https://${PROJECT_URL}
|
||||||
if you use the sample .env: https://typo3.localhost
|
if you use the sample .env: https://typo3.localhost
|
||||||
|
|
||||||
use for the db connection "db"
|
|
||||||
|
|
||||||
|
|
||||||
after the install there is at the a error.
|
after the install there is at the a error.
|
||||||
|
395
apache-conf/.htaccess
Normal file
395
apache-conf/.htaccess
Normal file
@@ -0,0 +1,395 @@
|
|||||||
|
#####
|
||||||
|
#
|
||||||
|
# Example .htaccess file for TYPO3 CMS - for use with Apache Webserver
|
||||||
|
#
|
||||||
|
# This file includes settings for the following configuration options:
|
||||||
|
#
|
||||||
|
# - Compression
|
||||||
|
# - Caching
|
||||||
|
# - MIME types
|
||||||
|
# - Cross Origin requests
|
||||||
|
# - Rewriting and Access
|
||||||
|
# - Miscellaneous
|
||||||
|
# - PHP optimisation
|
||||||
|
#
|
||||||
|
# If you want to use it, you have to copy it to the root folder of your TYPO3 installation (if its
|
||||||
|
# not there already) and rename it to '.htaccess'. To make .htaccess files work, you might need to
|
||||||
|
# adjust the 'AllowOverride' directive in your Apache configuration file.
|
||||||
|
#
|
||||||
|
# IMPORTANT: You may need to change this file depending on your TYPO3 installation!
|
||||||
|
# Consider adding this file's content to your webserver's configuration directly for speed improvement
|
||||||
|
#
|
||||||
|
# Lots of the options are taken from https://github.com/h5bp/html5-boilerplate/blob/master/dist/.htaccess
|
||||||
|
#
|
||||||
|
####
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: Compression ###
|
||||||
|
|
||||||
|
# Compressing resource files will save bandwidth and so improve loading speed especially for users
|
||||||
|
# with slower internet connections. TYPO3 can compress the .js and .css files for you.
|
||||||
|
# *) Uncomment the following lines and
|
||||||
|
# *) Set $GLOBALS['TYPO3_CONF_VARS']['BE']['compressionLevel'] = 9 for the Backend
|
||||||
|
# *) Set $GLOBALS['TYPO3_CONF_VARS']['FE']['compressionLevel'] = 9 together with the TypoScript properties
|
||||||
|
# config.compressJs and config.compressCss for GZIP compression of Frontend JS and CSS files.
|
||||||
|
|
||||||
|
#<FilesMatch "\.js\.gz">
|
||||||
|
# AddType "text/javascript" .gz
|
||||||
|
#</FilesMatch>
|
||||||
|
#<FilesMatch "\.css\.gz">
|
||||||
|
# AddType "text/css" .gz
|
||||||
|
#</FilesMatch>
|
||||||
|
#AddEncoding x-gzip .gz
|
||||||
|
|
||||||
|
<IfModule mod_deflate.c>
|
||||||
|
# Force compression for mangled `Accept-Encoding` request headers
|
||||||
|
<IfModule mod_setenvif.c>
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
SetEnvIfNoCase ^(Accept-EncodXng|X-cept-Encoding|X{15}|~{15}|-{15})$ ^((gzip|deflate)\s*,?\s*)+|[X~-]{4,13}$ HAVE_Accept-Encoding
|
||||||
|
RequestHeader append Accept-Encoding "gzip,deflate" env=HAVE_Accept-Encoding
|
||||||
|
</IfModule>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# Compress all output labeled with one of the following media types.
|
||||||
|
#
|
||||||
|
# (!) For Apache versions below version 2.3.7 you don't need to
|
||||||
|
# enable `mod_filter` and can remove the `<IfModule mod_filter.c>`
|
||||||
|
# and `</IfModule>` lines as `AddOutputFilterByType` is still in
|
||||||
|
# the core directives.
|
||||||
|
#
|
||||||
|
# https://httpd.apache.org/docs/current/mod/mod_filter.html#addoutputfilterbytype
|
||||||
|
|
||||||
|
<IfModule mod_filter.c>
|
||||||
|
AddOutputFilterByType DEFLATE application/atom+xml \
|
||||||
|
application/javascript \
|
||||||
|
application/json \
|
||||||
|
application/ld+json \
|
||||||
|
application/manifest+json \
|
||||||
|
application/rdf+xml \
|
||||||
|
application/rss+xml \
|
||||||
|
application/schema+json \
|
||||||
|
application/vnd.geo+json \
|
||||||
|
application/geo+json \
|
||||||
|
application/vnd.ms-fontobject \
|
||||||
|
application/x-font-ttf \
|
||||||
|
application/x-javascript \
|
||||||
|
application/x-web-app-manifest+json \
|
||||||
|
application/xhtml+xml \
|
||||||
|
application/xml \
|
||||||
|
font/eot \
|
||||||
|
font/opentype \
|
||||||
|
font/otf \
|
||||||
|
font/ttf \
|
||||||
|
image/bmp \
|
||||||
|
image/svg+xml \
|
||||||
|
image/vnd.microsoft.icon \
|
||||||
|
image/x-icon \
|
||||||
|
text/cache-manifest \
|
||||||
|
text/css \
|
||||||
|
text/html \
|
||||||
|
text/javascript \
|
||||||
|
text/plain \
|
||||||
|
text/vcard \
|
||||||
|
text/vnd.rim.location.xloc \
|
||||||
|
text/vtt \
|
||||||
|
text/x-component \
|
||||||
|
text/x-cross-domain-policy \
|
||||||
|
text/xml
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
<IfModule mod_mime.c>
|
||||||
|
AddEncoding gzip svgz
|
||||||
|
</IfModule>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
### End: Compression ###
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: Browser caching of resource files ###
|
||||||
|
|
||||||
|
# This affects Frontend and Backend and increases performance.
|
||||||
|
<IfModule mod_expires.c>
|
||||||
|
|
||||||
|
ExpiresActive On
|
||||||
|
ExpiresDefault "access plus 1 month"
|
||||||
|
|
||||||
|
ExpiresByType text/css "access plus 1 year"
|
||||||
|
|
||||||
|
ExpiresByType application/json "access plus 0 seconds"
|
||||||
|
ExpiresByType application/ld+json "access plus 0 seconds"
|
||||||
|
ExpiresByType application/schema+json "access plus 0 seconds"
|
||||||
|
ExpiresByType application/vnd.geo+json "access plus 0 seconds"
|
||||||
|
ExpiresByType application/geo+json "access plus 0 seconds"
|
||||||
|
ExpiresByType application/xml "access plus 0 seconds"
|
||||||
|
ExpiresByType text/xml "access plus 0 seconds"
|
||||||
|
|
||||||
|
ExpiresByType image/vnd.microsoft.icon "access plus 1 week"
|
||||||
|
ExpiresByType image/x-icon "access plus 1 week"
|
||||||
|
|
||||||
|
ExpiresByType text/x-component "access plus 1 month"
|
||||||
|
|
||||||
|
ExpiresByType text/html "access plus 0 seconds"
|
||||||
|
|
||||||
|
ExpiresByType application/javascript "access plus 1 year"
|
||||||
|
ExpiresByType application/x-javascript "access plus 1 year"
|
||||||
|
ExpiresByType text/javascript "access plus 1 year"
|
||||||
|
|
||||||
|
ExpiresByType application/manifest+json "access plus 1 week"
|
||||||
|
ExpiresByType application/x-web-app-manifest+json "access plus 0 seconds"
|
||||||
|
ExpiresByType text/cache-manifest "access plus 0 seconds"
|
||||||
|
|
||||||
|
ExpiresByType audio/ogg "access plus 1 month"
|
||||||
|
ExpiresByType image/apng "access plus 1 month"
|
||||||
|
ExpiresByType image/avif "access plus 1 month"
|
||||||
|
ExpiresByType image/avif-sequence "access plus 1 month"
|
||||||
|
ExpiresByType image/bmp "access plus 1 month"
|
||||||
|
ExpiresByType image/gif "access plus 1 month"
|
||||||
|
ExpiresByType image/jpeg "access plus 1 month"
|
||||||
|
ExpiresByType image/jxl "access plus 1 month"
|
||||||
|
ExpiresByType image/png "access plus 1 month"
|
||||||
|
ExpiresByType image/svg+xml "access plus 1 month"
|
||||||
|
ExpiresByType image/webp "access plus 1 month"
|
||||||
|
ExpiresByType video/mp4 "access plus 1 month"
|
||||||
|
ExpiresByType video/ogg "access plus 1 month"
|
||||||
|
ExpiresByType video/webm "access plus 1 month"
|
||||||
|
|
||||||
|
ExpiresByType application/atom+xml "access plus 1 hour"
|
||||||
|
ExpiresByType application/rdf+xml "access plus 1 hour"
|
||||||
|
ExpiresByType application/rss+xml "access plus 1 hour"
|
||||||
|
|
||||||
|
ExpiresByType font/collection "access plus 1 month"
|
||||||
|
ExpiresByType application/vnd.ms-fontobject "access plus 1 month"
|
||||||
|
ExpiresByType font/eot "access plus 1 month"
|
||||||
|
ExpiresByType font/opentype "access plus 1 month"
|
||||||
|
ExpiresByType font/otf "access plus 1 month"
|
||||||
|
ExpiresByType application/x-font-ttf "access plus 1 month"
|
||||||
|
ExpiresByType font/ttf "access plus 1 month"
|
||||||
|
ExpiresByType application/font-woff "access plus 1 month"
|
||||||
|
ExpiresByType application/x-font-woff "access plus 1 month"
|
||||||
|
ExpiresByType font/woff "access plus 1 month"
|
||||||
|
ExpiresByType application/font-woff2 "access plus 1 month"
|
||||||
|
ExpiresByType font/woff2 "access plus 1 month"
|
||||||
|
|
||||||
|
ExpiresByType text/x-cross-domain-policy "access plus 1 week"
|
||||||
|
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
### End: Browser caching of resource files ###
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: MIME types ###
|
||||||
|
|
||||||
|
# Proper MIME types for all files
|
||||||
|
<IfModule mod_mime.c>
|
||||||
|
# Security configuration
|
||||||
|
RemoveType .html .htm
|
||||||
|
<FilesMatch ".+\.html?$">
|
||||||
|
AddType text/html .html .htm
|
||||||
|
</FilesMatch>
|
||||||
|
|
||||||
|
RemoveType .svg .svgz
|
||||||
|
<FilesMatch ".+\.svgz?$">
|
||||||
|
AddType image/svg+xml .svg .svgz
|
||||||
|
</FilesMatch>
|
||||||
|
|
||||||
|
# Data interchange
|
||||||
|
AddType application/atom+xml atom
|
||||||
|
AddType application/json json map topojson
|
||||||
|
AddType application/ld+json jsonld
|
||||||
|
AddType application/rss+xml rss
|
||||||
|
AddType application/vnd.geo+json geojson
|
||||||
|
AddType application/xml rdf xml
|
||||||
|
|
||||||
|
# JavaScript
|
||||||
|
AddType application/javascript js
|
||||||
|
|
||||||
|
# Manifest files
|
||||||
|
AddType application/manifest+json webmanifest
|
||||||
|
AddType application/x-web-app-manifest+json webapp
|
||||||
|
AddType text/cache-manifest appcache
|
||||||
|
|
||||||
|
# Media files
|
||||||
|
|
||||||
|
AddType audio/mp4 f4a f4b m4a
|
||||||
|
AddType audio/ogg oga ogg opus
|
||||||
|
AddType image/avif avif
|
||||||
|
AddType image/avif-sequence avifs
|
||||||
|
AddType image/bmp bmp
|
||||||
|
AddType image/jxl jxl
|
||||||
|
AddType image/webp webp
|
||||||
|
AddType video/mp4 f4v f4p m4v mp4
|
||||||
|
AddType video/ogg ogv
|
||||||
|
AddType video/webm webm
|
||||||
|
AddType video/x-flv flv
|
||||||
|
AddType image/x-icon cur ico
|
||||||
|
|
||||||
|
# Web fonts
|
||||||
|
AddType font/woff woff
|
||||||
|
AddType font/woff2 woff2
|
||||||
|
AddType application/vnd.ms-fontobject eot
|
||||||
|
AddType font/ttf ttc ttf
|
||||||
|
AddType font/otf otf
|
||||||
|
|
||||||
|
# Other
|
||||||
|
AddType application/octet-stream safariextz
|
||||||
|
AddType application/x-bb-appworld bbaw
|
||||||
|
AddType application/x-chrome-extension crx
|
||||||
|
AddType application/x-opera-extension oex
|
||||||
|
AddType application/x-xpinstall xpi
|
||||||
|
AddType text/vcard vcard vcf
|
||||||
|
AddType text/vnd.rim.location.xloc xloc
|
||||||
|
AddType text/vtt vtt
|
||||||
|
AddType text/x-component htc
|
||||||
|
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# UTF-8 encoding
|
||||||
|
AddDefaultCharset utf-8
|
||||||
|
<IfModule mod_mime.c>
|
||||||
|
AddCharset utf-8 .atom .css .js .json .manifest .rdf .rss .vtt .webapp .webmanifest .xml
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
### End: MIME types ###
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: Cross Origin ###
|
||||||
|
|
||||||
|
# Send the CORS header for images when browsers request it.
|
||||||
|
<IfModule mod_setenvif.c>
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
<FilesMatch "\.(avifs?|bmp|cur|gif|ico|jpe?g|png|svgz?|webp)$">
|
||||||
|
SetEnvIf Origin ":" IS_CORS
|
||||||
|
Header set Access-Control-Allow-Origin "*" env=IS_CORS
|
||||||
|
</FilesMatch>
|
||||||
|
</IfModule>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# Allow cross-origin access to web fonts.
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
<FilesMatch "\.(eot|otf|tt[cf]|woff2?)$">
|
||||||
|
Header set Access-Control-Allow-Origin "*"
|
||||||
|
</FilesMatch>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
### End: Cross Origin ###
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: Rewriting and Access ###
|
||||||
|
|
||||||
|
<IfModule mod_rewrite.c>
|
||||||
|
|
||||||
|
# Enable URL rewriting
|
||||||
|
RewriteEngine On
|
||||||
|
|
||||||
|
# Store the current location in an environment variable CWD to use
|
||||||
|
# mod_rewrite in .htaccess files without knowing the RewriteBase
|
||||||
|
RewriteCond $0#%{REQUEST_URI} ([^#]*)#(.*)\1$
|
||||||
|
RewriteRule ^.*$ - [E=CWD:%2]
|
||||||
|
|
||||||
|
# Rules to set ApplicationContext based on hostname
|
||||||
|
#RewriteCond %{HTTP_HOST} ^dev\.example\.com$
|
||||||
|
#RewriteRule .? - [E=TYPO3_CONTEXT:Development]
|
||||||
|
#RewriteCond %{HTTP_HOST} ^staging\.example\.com$
|
||||||
|
#RewriteRule .? - [E=TYPO3_CONTEXT:Production/Staging]
|
||||||
|
#RewriteCond %{HTTP_HOST} ^www\.example\.com$
|
||||||
|
#RewriteRule .? - [E=TYPO3_CONTEXT:Production]
|
||||||
|
|
||||||
|
# Rule for versioned static files, configured through:
|
||||||
|
# - $GLOBALS['TYPO3_CONF_VARS']['BE']['versionNumberInFilename']
|
||||||
|
# - $GLOBALS['TYPO3_CONF_VARS']['FE']['versionNumberInFilename']
|
||||||
|
# IMPORTANT: This rule has to be the very first RewriteCond in order to work!
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-f
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-d
|
||||||
|
RewriteRule ^(.+)\.(\d+)\.(php|js|css|png|jpg|gif|gz)$ %{ENV:CWD}$1.$3 [L]
|
||||||
|
|
||||||
|
# Access block for folders
|
||||||
|
RewriteRule _(?:recycler|temp)_/ - [F]
|
||||||
|
RewriteRule fileadmin/templates/.*\.(?:txt|ts)$ - [F]
|
||||||
|
RewriteRule ^(?:vendor|typo3_src|typo3temp/var) - [F]
|
||||||
|
RewriteRule (?:typo3conf/ext|typo3/sysext|typo3/ext)/[^/]+/(?:Configuration|Resources/Private|Tests?|Documentation|docs?)/ - [F]
|
||||||
|
|
||||||
|
# Block access to all hidden files and directories with the exception of
|
||||||
|
# the visible content from within the `/.well-known/` hidden directory (RFC 5785).
|
||||||
|
RewriteCond %{REQUEST_URI} "!(^|/)\.well-known/([^./]+./?)+$" [NC]
|
||||||
|
RewriteCond %{SCRIPT_FILENAME} -d [OR]
|
||||||
|
RewriteCond %{SCRIPT_FILENAME} -f
|
||||||
|
RewriteRule (?:^|/)\. - [F]
|
||||||
|
|
||||||
|
# Stop rewrite processing, if we are in any other known directory
|
||||||
|
# NOTE: Add your additional local storages here
|
||||||
|
RewriteRule ^(?:fileadmin/|typo3conf/|typo3temp/|uploads/) - [L]
|
||||||
|
|
||||||
|
# If the file/symlink/directory does not exist but is below /typo3/, redirect to the TYPO3 Backend entry point.
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-f
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-d
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-l
|
||||||
|
RewriteRule ^typo3/(.*)$ %{ENV:CWD}typo3/index.php [QSA,L]
|
||||||
|
|
||||||
|
# If the file/symlink/directory does not exist => Redirect to index.php.
|
||||||
|
# For httpd.conf, you need to prefix each '%{REQUEST_FILENAME}' with '%{DOCUMENT_ROOT}'.
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-f
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-d
|
||||||
|
RewriteCond %{REQUEST_FILENAME} !-l
|
||||||
|
RewriteRule ^.*$ %{ENV:CWD}index.php [QSA,L]
|
||||||
|
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# Access block for files
|
||||||
|
# Apache < 2.3
|
||||||
|
<IfModule !mod_authz_core.c>
|
||||||
|
<FilesMatch "(?i:^\.|^#.*#|^(?:ChangeLog|ToDo|Readme|License)(?:\.md|\.txt)?|^composer\.(?:json|lock)|^ext_conf_template\.txt|^ext_typoscript_constants\.txt|^ext_typoscript_setup\.txt|flexform[^.]*\.xml|locallang[^.]*\.(?:xml|xlf)|\.(?:bak|co?nf|cfg|ya?ml|ts|typoscript|tsconfig|dist|fla|in[ci]|log|sh|sql(?:\..*)?|sqlite(?:\..*)?|sw[op]|git.*|rc)|.*~)$">
|
||||||
|
Order allow,deny
|
||||||
|
Deny from all
|
||||||
|
Satisfy All
|
||||||
|
</FilesMatch>
|
||||||
|
</IfModule>
|
||||||
|
# Apache ≥ 2.3
|
||||||
|
<IfModule mod_authz_core.c>
|
||||||
|
<If "%{REQUEST_URI} =~ m#(?i:/\.|/\x23.*\x23|/(?:ChangeLog|ToDo|Readme|License)(?:\.md|\.txt)?|/composer\.(?:json|lock)|/ext_conf_template\.txt|/ext_typoscript_constants\.txt|/ext_typoscript_setup\.txt|flexform[^.]*\.xml|locallang[^.]*\.(?:xml|xlf)|\.(?:bak|co?nf|cfg|ya?ml|ts|typoscript|tsconfig|dist|fla|in[ci]|log|sh|sql(?:\..*)?|sqlite(?:\..*)?|sw[op]|git.*|rc)|.*~)$#">
|
||||||
|
Require all denied
|
||||||
|
</If>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# Block access to vcs directories
|
||||||
|
<IfModule mod_alias.c>
|
||||||
|
RedirectMatch 404 /\.(?:git|svn|hg)/
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
### End: Rewriting and Access ###
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
### Begin: Miscellaneous ###
|
||||||
|
|
||||||
|
# 404 error prevention for non-existing redirected folders
|
||||||
|
Options -MultiViews
|
||||||
|
|
||||||
|
# Make sure that directory listings are disabled.
|
||||||
|
<IfModule mod_autoindex.c>
|
||||||
|
Options -Indexes
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
# Force IE to render pages in the highest available mode
|
||||||
|
Header set X-UA-Compatible "IE=edge"
|
||||||
|
<FilesMatch "\.(appcache|avifs?|crx|css|eot|gif|htc|ico|jpe?g|js|m4a|m4v|manifest|mp4|oex|oga|ogg|ogv|otf|pdf|png|safariextz|svgz?|ttf|vcf|webapp|webm|webp|woff2?|xml|xpi)$">
|
||||||
|
Header unset X-UA-Compatible
|
||||||
|
</FilesMatch>
|
||||||
|
|
||||||
|
# Reducing MIME type security risks
|
||||||
|
Header set X-Content-Type-Options "nosniff"
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
# ETag removal
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
Header unset ETag
|
||||||
|
</IfModule>
|
||||||
|
FileETag None
|
||||||
|
|
||||||
|
### End: Miscellaneous ###
|
||||||
|
|
||||||
|
|
||||||
|
# Add your own rules here.
|
32
apache-conf/sites-enabled/typo3.localhost.conf
Normal file
32
apache-conf/sites-enabled/typo3.localhost.conf
Normal file
@@ -0,0 +1,32 @@
|
|||||||
|
<Directory /var/www/html>
|
||||||
|
Options FollowSymLinks
|
||||||
|
AllowOverride All
|
||||||
|
Require all granted
|
||||||
|
</Directory>
|
||||||
|
|
||||||
|
<IfModule mod_mime.c>
|
||||||
|
RemoveType .html .htm
|
||||||
|
<FilesMatch ".+\.html?$">
|
||||||
|
AddType text/html .html
|
||||||
|
AddType text/html .htm
|
||||||
|
</FilesMatch>
|
||||||
|
|
||||||
|
RemoveType .svg .svgz
|
||||||
|
<FilesMatch ".+\.svgz?$">
|
||||||
|
AddType image/svg+xml .svg
|
||||||
|
AddType image/svg+xml .svgz
|
||||||
|
</FilesMatch>
|
||||||
|
<IfModule mod_headers.c>
|
||||||
|
#Header set Content-Security-Policy "default-src 'self' 'unsafe-inline'; img-src * data:; font-src 'self' data:;"
|
||||||
|
</IfModule>
|
||||||
|
</IfModule>
|
||||||
|
|
||||||
|
<VirtualHost *:80>
|
||||||
|
DocumentRoot /var/www/html
|
||||||
|
UseCanonicalName On
|
||||||
|
</VirtualHost>
|
||||||
|
|
||||||
|
<VirtualHost *:443>
|
||||||
|
DocumentRoot /var/www/html
|
||||||
|
UseCanonicalName On
|
||||||
|
</VirtualHost>
|
@@ -1,10 +1,9 @@
|
|||||||
version: '1'
|
version: '3.8'
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
default:
|
default:
|
||||||
name: "${PROJECT_NAME}_typo3_db_net"
|
name: "${PROJECT_NAME}_typo3_db_net"
|
||||||
external: false
|
external: false
|
||||||
|
|
||||||
traefik:
|
traefik:
|
||||||
name: "${TRAEFIK_NETWORK}"
|
name: "${TRAEFIK_NETWORK}"
|
||||||
external: true
|
external: true
|
||||||
@@ -13,46 +12,53 @@ services:
|
|||||||
typo3:
|
typo3:
|
||||||
container_name: "${PROJECT_NAME}_typo3"
|
container_name: "${PROJECT_NAME}_typo3"
|
||||||
hostname: "${PROJECT_URL}"
|
hostname: "${PROJECT_URL}"
|
||||||
build: .
|
image: "altogether/typo3:12.4.8-apache"
|
||||||
|
user: "1000"
|
||||||
networks:
|
networks:
|
||||||
- "traefik"
|
- "traefik"
|
||||||
|
- "default"
|
||||||
volumes:
|
volumes:
|
||||||
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/fileadmin:/var/www/html/fileadmin"
|
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/fileadmin:/var/www/html/fileadmin"
|
||||||
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/typo3conf:/var/www/html/typo3conf"
|
|
||||||
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/uploads:/var/www/html/uploads"
|
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/uploads:/var/www/html/uploads"
|
||||||
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/protected:/var/www/protected"
|
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/protected:/var/www/protected"
|
||||||
|
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/typo3conf:/var/www/html/typo3conf"
|
||||||
|
- "./apache-conf/sites-enabled:/etc/apache2/sites-enabled"
|
||||||
|
- "./apache-conf/.htaccess:/var/www/html/.htaccess"
|
||||||
- "./php-conf/php.ini:/usr/local/etc/php/php.ini:ro"
|
- "./php-conf/php.ini:/usr/local/etc/php/php.ini:ro"
|
||||||
|
## use for the first install
|
||||||
|
#- "./LICENSE:/var/www/html/FIRST_INSTALL:ro"
|
||||||
- "/etc/timezone:/etc/timezone:ro"
|
- "/etc/timezone:/etc/timezone:ro"
|
||||||
- "/etc/localtime:/etc/localtime:ro"
|
- "/etc/localtime:/etc/localtime:ro"
|
||||||
depends_on:
|
depends_on:
|
||||||
- "db"
|
- "db"
|
||||||
labels:
|
labels:
|
||||||
# Watchtower add to auto update
|
# Watchtower add to auto update
|
||||||
- "com.centurylinklabs.watchtower.enable=true"
|
- "com.centurylinklabs.watchtower.enable=false"
|
||||||
# traefik
|
# traefik
|
||||||
- "traefik.enable=true"
|
- "traefik.enable=true"
|
||||||
- "traefik.docker.network=${TRAEFIK_NETWORK}"
|
- "traefik.docker.network=${TRAEFIK_NETWORK}"
|
||||||
- "traefik.http.routers.${PROJECT_NAME}_typo3.rule=Host(`${PROJECT_URL}`)"
|
- "traefik.http.routers.${PROJECT_NAME}_typo3.rule=Host(`${PROJECT_URL}`)"
|
||||||
- "traefik.http.routers.${PROJECT_NAME}_typo3.entrypoints=websecure"
|
- "traefik.http.routers.${PROJECT_NAME}_typo3.entrypoints=websecure"
|
||||||
- "traefik.http.routers.${PROJECT_NAME}_typo3.tls=true"
|
- "traefik.http.routers.${PROJECT_NAME}_typo3.tls=true"
|
||||||
- "traefik.http.services.${PROJECT_NAME}_typo3.loadbalancer.server.port=80"
|
- "traefik.http.services.${PROJECT_NAME}_typo3.loadbalancer.server.port=443"
|
||||||
|
# Use the special Traefik service api@internal with the web UI/Dashboard
|
||||||
|
# - traefik.http.routers.${PROJECT_NAME}_typo3.service=api@internal
|
||||||
|
# Use the "le" (Let's Encrypt) resolver created below
|
||||||
|
# - traefik.http.routers.${PROJECT_NAME}_typo3.tls.certresolver=le
|
||||||
db:
|
db:
|
||||||
image: "mariadb:latest"
|
image: "mariadb:latest"
|
||||||
container_name: "${PROJECT_NAME}_typo3_db"
|
container_name: "${PROJECT_NAME}_typo3_db"
|
||||||
restart: "unless-stopped"
|
restart: "unless-stopped"
|
||||||
|
networks:
|
||||||
|
- "default"
|
||||||
command:
|
command:
|
||||||
- "--character-set-server=utf8mb4"
|
- "--character-set-server=utf8mb4"
|
||||||
- "--collation-server=utf8mb4_unicode_ci"
|
- "--collation-server=utf8mb4_unicode_ci"
|
||||||
env_file: ".env"
|
env_file: ".env"
|
||||||
volumes:
|
volumes:
|
||||||
- "db:/var/lib/mysql"
|
- "${PROJECT_DATA}/${PROJECT_NAME}-typo3/db:/var/lib/mysql"
|
||||||
# - "${PROJECT_DATA}/${PROJECT_NAME}-typo3/db:/var/lib/mysql"
|
|
||||||
|
|
||||||
labels:
|
labels:
|
||||||
# Watchtower add to auto update
|
# Watchtower add to auto update
|
||||||
- "com.centurylinklabs.watchtower.enable=true"
|
- "com.centurylinklabs.watchtower.enable=true"
|
||||||
# traefik
|
# traefik
|
||||||
- "traefik.enable=false"
|
- "traefik.enable=false"
|
||||||
volumes:
|
|
||||||
db:
|
|
||||||
name: "${PROJECT_NAME}_db"
|
|
3
init
3
init
@@ -2,11 +2,10 @@
|
|||||||
|
|
||||||
source ./.env
|
source ./.env
|
||||||
|
|
||||||
|
|
||||||
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/fileadmin
|
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/fileadmin
|
||||||
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/typo3conf
|
|
||||||
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/uploads
|
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/uploads
|
||||||
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/protected
|
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/protected
|
||||||
|
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/typo3conf
|
||||||
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/db
|
mkdir -p ${PROJECT_DATA}/${PROJECT_NAME}-typo3/db
|
||||||
|
|
||||||
docker network create $TRAEFIK_NETWORK
|
docker network create $TRAEFIK_NETWORK
|
||||||
|
Reference in New Issue
Block a user