Observed behaviour
Caddy on build sets following capability to main binary:
Running following configuration above will make fluxer-static container fail to launch with
I'll just leave it for information purposes I guess. Current
Hopefully I'm not too annoying with my issues. They're rather specific and mostly tailored to my use case of running everything with least privileges possible.
CAP_NET_BIND_SERVICE which allows it to bind to privileged ports - ref: https://github.com/caddyserver/caddy-docker/blob/master/Dockerfile.builder.tmpl#L15
This unfortunately prevents anyone from running the image with all capabilities dropped as kernel will prevent exection of any binary with file capabilities not present in the bounding set. It also won't solve the core problem of requiring a specific sysctl outside the container to bind to such ports anyway as this capability only exists and lives within the container.
fluxer-static :
(...)
cap_drop:
- ALLexec /usr/bin/caddy: operation not permitted.
It's possible to strip it from stock Caddy image by simply including following snippet anywhere in fluxer-static Dockerfile
RUN setcap -r /usr/bin/caddyNote
Now that after I wrote everything below, I realized that this won't be needed at all since fluxer-static runs on port
8080 which is unprivileged.edge from docker-compose.yaml also suffers from the same problem but it would need to be turned into a custom image to counter it since it uses base Caddy image and such modifications are only permitted during container build.
If binding to lower ports desired, it is miles better using sysctl instead.
This will work for both rootful and rootless[1] Docker and also Podman without requiring the user to add back that capability. (Sysctl=net.ipv4.ip_unprivileged_port_start=80 for quadlet)
Docker Compose documentation reference
[1] - Host will also need this tunable, not 100% sure since Docker daemon still runs rootful even under rootless mode
static-proxy:
<<: *fluxer-service
image: ${FLUXER_REGISTRY:-ghcr.io/${FLUXER_REGISTRY_OWNER:-fluxerapp}}/fluxer-static:${FLUXER_IMAGE_TAG:-v1}
deploy:
resources:
limits:
memory: ${FLUXER_STATIC_PROXY_MEMORY_LIMIT:-256mb}
+ sysctls:
+ - net.ipv4.ip_unprivileged_port_start=80
healthcheck:
test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/avatars/0.png"]
interval: 10s
timeout: 5s
retries: 10Reproduction steps
- Try to run
fluxer-staticwithcap_dropset to- ALL - Watch as everything collapses
Build information
Stable Web 2026.906.221621, Windows NT 10.0 (x64), Firefox 155.0, Locale pl
Platform
Self-hosting
Evidence
wrz 08 02:28:22 sm-fluxer podman[484941]: 2026-09-08 02:28:22.621819882 +0200 CEST m=+0.996198685 container start < container_id>
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: {
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: "msg" : "exec container process ` /usr/bin/caddy ` : Operation not permitted" ,
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: "level" : "error" ,
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: "time" : "2026-09-08T00:28:22.625752Z"
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: }
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[484941]: < container_id>
wrz 08 02:28:22 sm-fluxer podman[485136]: 2026-09-08 02:28:22.85081943 +0200 CEST m=+0.194098338 container died < container_id>
wrz 08 02:28:23 sm-fluxer podman[485136]: 2026-09-08 02:28:23.315419424 +0200 CEST m=+0.658698331 container remove < container_id>
wrz 08 02:28:23 sm-fluxer systemd[723]: fluxer-static-proxy.service: Main process exited, code=exited, status=1/FAILURE
░░ Subject: Proces jednostki zakończył działanie
░░ Defined-By: systemd
░░ Support: https://www.debian.org/support
░░
░░ Proces ExecStart= należący do jednostki UNIT zakończył działanie.
░░
░░ Kod wyjścia procesu: „exited”, jego stan wyjścia: 1.
wrz 08 02:28:23 sm-fluxer systemd[723]: fluxer-static-proxy.service: Failed with result 'exit-code' .
2 comments
Comment by Hampus
Comment by @MrRubberDucky