Edit history

fluxer-static: Strip CAP_NET_BIND_SERVICE from Caddy binary to allow running container with dropped capabilities has not been edited, so there are no earlier versions.

Current version | Original by Rex
Show

fluxer-static: Strip CAP_NET_BIND_SERVICE from Caddy binary to allow running container with dropped capabilities

Observed behaviour

Caddy on build sets following capability to main binary: CAP_NET_BIND_SERVICE which allows it to bind to privileged ports - ref: https://github.com/caddyserver/caddy-docker/blob/master/Dockerfile.builder.tmpl#L15 This unfortunately prevents anyone from running the image with all capabilities dropped as kernel will prevent exection of any binary with file capabilities not present in the bounding set. It also won't solve the core problem of requiring a specific sysctl outside the container to bind to such ports anyway as this capability only exists and lives within the container.
fluxer-static:
(...)
   cap_drop:
      - ALL
Running following configuration above will make fluxer-static container fail to launch with exec /usr/bin/caddy: operation not permitted. It's possible to strip it from stock Caddy image by simply including following snippet anywhere in fluxer-static Dockerfile
RUN setcap -r /usr/bin/caddy
Note
Now that after I wrote everything below, I realized that this won't be needed at all since fluxer-static runs on port 8080 which is unprivileged.
I'll just leave it for information purposes I guess. Current edge from docker-compose.yaml also suffers from the same problem but it would need to be turned into a custom image to counter it since it uses base Caddy image and such modifications are only permitted during container build. If binding to lower ports desired, it is miles better using sysctl instead. This will work for both rootful and rootless[1] Docker and also Podman without requiring the user to add back that capability. (Sysctl=net.ipv4.ip_unprivileged_port_start=80 for quadlet) Docker Compose documentation reference [1] - Host will also need this tunable, not 100% sure since Docker daemon still runs rootful even under rootless mode
  static-proxy:
    <<: *fluxer-service
    image: ${FLUXER_REGISTRY:-ghcr.io/${FLUXER_REGISTRY_OWNER:-fluxerapp}}/fluxer-static:${FLUXER_IMAGE_TAG:-v1}
    deploy:
      resources:
        limits:
          memory: ${FLUXER_STATIC_PROXY_MEMORY_LIMIT:-256mb}
+   sysctls:
+     - net.ipv4.ip_unprivileged_port_start=80
    healthcheck:
      test: ["CMD", "wget", "-q", "-O", "/dev/null", "http://127.0.0.1:8080/avatars/0.png"]
      interval: 10s
      timeout: 5s
      retries: 10
Hopefully I'm not too annoying with my issues. They're rather specific and mostly tailored to my use case of running everything with least privileges possible.

Reproduction steps

  1. Try to run fluxer-static with cap_drop set to - ALL
  2. Watch as everything collapses

Build information

Stable Web 2026.906.221621, Windows NT 10.0 (x64), Firefox 155.0, Locale pl

Platform

Self-hosting

Evidence

wrz 08 02:28:22 sm-fluxer podman[484941]: 2026-09-08 02:28:22.621819882 +0200 CEST m=+0.996198685 container start <container_id>
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: {
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]:   "msg": "exec container process `/usr/bin/caddy`: Operation not permitted",
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]:   "level": "error",
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]:   "time": "2026-09-08T00:28:22.625752Z"
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[485112]: }
wrz 08 02:28:22 sm-fluxer fluxer-static-proxy[484941]: <container_id>
wrz 08 02:28:22 sm-fluxer podman[485136]: 2026-09-08 02:28:22.85081943 +0200 CEST m=+0.194098338 container died <container_id>
wrz 08 02:28:23 sm-fluxer podman[485136]: 2026-09-08 02:28:23.315419424 +0200 CEST m=+0.658698331 container remove <container_id>
wrz 08 02:28:23 sm-fluxer systemd[723]: fluxer-static-proxy.service: Main process exited, code=exited, status=1/FAILURE
░░ Subject: Proces jednostki zakończył działanie
░░ Defined-By: systemd
░░ Support: https://www.debian.org/support
░░
░░ Proces ExecStart= należący do jednostki UNIT zakończył działanie.
░░
░░ Kod wyjścia procesu: „exited”, jego stan wyjścia: 1.
wrz 08 02:28:23 sm-fluxer systemd[723]: fluxer-static-proxy.service: Failed with result 'exit-code'.