The Docker image is ready to use:
docker run -d --rm -p 8080:8080/tcp ghcr.io/ammnt/freenginx:latest
or
docker run -d --rm -p 8080:8080/tcp ammnt/freenginx:latest
- Based on latest version of Alpine Linux - low size (~4 MB);
- BoringSSL with HTTP/3 and QUIC support:
https://boringssl.googlesource.com/boringssl - HTTP/2 with ALPN support;
- TLS 1.3 and 0-RTT support;
- TLS 1.2 and TCP Fast Open (TFO) support;
- Built using hardening GCC flags;
- NJS and Brotli support;
- PCRE with JIT compilation;
- zlib-ng library latest version;
- Rootless master process - unprivileged container;
- Async I/O threads module;
- "Distroless" image - shell removed from the image;
- Removed unnecessary modules;
- Added OCI labels and annotations;
- No excess ENTRYPOINT in the image;
- Slimmed version by Docker Slim tool;
- Scanned efficiency result with Dive tool;
- Scanned by vulnerability scanners: GitHub, Docker Scout, Snyk, Grype, Clair and Syft;
- Anonymous signature - removed "Server" header ("banner"):
https://github.com/ammnt/freenginx/blob/main/Dockerfile
Feel free to contact me with more security improvements🙋