7 Commits
Author SHA1 Message Date
Djeex b197fd5977 Merge pull request 'Fix ci release template' (#16) from fix-ci-release-template into main
CI / build-and-scan (push) Successful in 28s
Reviewed-on: #16
2026-08-23 23:24:41 +02:00
Djeex 13926f2e9f Link each commit in the release changelog to its own commit page
CI / build-and-scan (pull_request) Successful in 23s
COMMIT_LIST only rendered the bare subject line per commit, with no
way to jump to that specific commit — only the triggering commit
(Source:) had a link. Each line now reads
"- [<short-sha>](<repo>/commit/<sha>) <subject>", matching the same
link style already used for Source.
2026-08-23 23:20:45 +02:00
Djeex ae16862a11 Align release changelog with the commit-list template used on the sibling repos
CI / build-and-scan (pull_request) Successful in 26s
2026-08-23 22:57:01 +02:00
Djeex 6ac20e25e3 Merge pull request 'Run container as non-root via PUID/PGID / Move environment configuration to a .env file' (#14) from dev-v2 into main
CI / build-and-scan (push) Successful in 32s
Reviewed-on: #14
2026-08-23 15:17:00 +02:00
Djeex 620d00134c Move environment configuration to a .env file
CI / build-and-scan (pull_request) Successful in 47s
2026-08-23 15:11:22 +02:00
Djeex d13f79ed82 Bump version to 1.5.0 for non-root support 2026-08-23 14:15:20 +02:00
Djeex cf96acda92 Run container as non-root via PUID/PGID with a startup entrypoint banner and logs 2026-08-23 14:14:54 +02:00
8 changed files with 160 additions and 22 deletions
+22
View File
@@ -0,0 +1,22 @@
# User/group id the process runs as, matches ownership of the /adguard mount
PUID=1000
PGID=1000
# Timezone of the container
TZ=Europe/Paris
# Country codes for CIDR lists, comma separated. Prefix with ! to exclude instead of include.
# Full lists here: https://github.com/vulnebify/cidre/tree/main/output/cidr/ipv4
BLOCK_COUNTRIES=cn,ru
# Scheduling: daily or weekly
BLOCKLIST_CRON_TYPE=daily
# If weekly, choose the day: mon, tue, wed, thu, fri, sat, sun
BLOCKLIST_CRON_DAY=mon
# Time of day to run the update, 24h HH:MM format
BLOCKLIST_CRON_TIME=06:00
# Docker API URL used to restart the AdGuard container (via socket-proxy)
DOCKER_API_URL=http://socket-proxy-adguard:2375
# Name of the AdGuard Home container to restart
ADGUARD_CONTAINER_NAME=adguardhome
+9 -6
View File
@@ -70,10 +70,11 @@ jobs:
run: |
BEFORE="${{ github.event.before }}"
if [ -n "$BEFORE" ] && [ "$BEFORE" != "0000000000000000000000000000000000000000" ] && git cat-file -e "$BEFORE" 2>/dev/null; then
CHANGED=$(git diff --name-only "$BEFORE" "${{ github.sha }}")
BASE_REF="$BEFORE"
else
CHANGED=$(git diff --name-only HEAD~1 HEAD)
BASE_REF="HEAD~1"
fi
CHANGED=$(git diff --name-only "$BASE_REF" "${{ github.sha }}")
echo "Changed files:"
echo "$CHANGED"
@@ -146,9 +147,9 @@ jobs:
fi
fi
CHANGED_LIST=$(echo "$CHANGED" | sed 's/^/- /')
REPO_URL="https://git.djeex.fr/Djeex/adguard-cidre"
COMMIT_LIST=$(git log --no-merges --format="- [%h](${REPO_URL}/commit/%H) %s" "$BASE_REF".."${{ github.sha }}")
SHORT_SHA=$(echo "${{ github.sha }}" | cut -c1-7)
SOURCE_LINE="[${SHORT_SHA}](${REPO_URL}/commit/${{ github.sha }})"
if [ -n "$PR_NUM" ]; then
@@ -157,15 +158,17 @@ jobs:
BODY=$(cat <<EOF
## Changelog
---
### ${CATEGORY}
---
${CHANGE_TITLE}
**Source:** ${SOURCE_LINE}
**Image:** \`${IMAGE}:${VERSION}\`
**Changed files:**
${CHANGED_LIST}
**Commits:**
${COMMIT_LIST}
EOF
)
+4 -3
View File
@@ -2,7 +2,7 @@ FROM python:3.14.7-alpine AS base
ENV TZ=Europe/Paris
RUN apk add --no-cache tzdata curl \
RUN apk add --no-cache tzdata curl su-exec \
&& cp /usr/share/zoneinfo/$TZ /etc/localtime \
&& echo $TZ > /etc/timezone
@@ -11,7 +11,8 @@ WORKDIR /app
COPY requirements.txt .
RUN pip install --no-cache-dir -r requirements.txt
COPY blocklist_scheduler.py .
COPY blocklist_scheduler.py entrypoint.sh VERSION ./
RUN chmod +x entrypoint.sh
FROM base AS test
RUN pip install --no-cache-dir pytest==9.1.1
@@ -19,4 +20,4 @@ COPY tests/ tests/
COPY pytest.ini .
FROM base
ENTRYPOINT ["python3", "blocklist_scheduler.py"]
ENTRYPOINT ["./entrypoint.sh"]
+9 -4
View File
@@ -31,6 +31,8 @@
| Variable | Description | Example | Possible Values |
|--------------------------|--------------------------------------------------------------------------|-----------------------------|---------------------------------------------|
| `PUID` | User ID the process runs as (drops root at startup) | `1000` | Any valid numeric UID |
| `PGID` | Group ID the process runs as | `1000` | Any valid numeric GID |
| `TZ` | Timezone of the container to correctly schedule updates | `Europe/Paris` | Any valid timezone (e.g., `UTC`, `America/New_York`, etc.) |
| `BLOCK_COUNTRIES` | List of country codes for CIDR lists, separated by commas. You can also define an exclude list (all countries except the specified ones) by prefixing each country code with !. Mixing inclusion and exclusion codes is not supported. | including list : `cn,ru,ir`, excluding list : `!cn,!ru,!ir` | ISO 2-letter country codes |
| `BLOCKLIST_CRON_TYPE` | Scheduling type: `daily` or `weekly` | `daily` | `daily`, `weekly` |
@@ -64,6 +66,8 @@
container_name: adguard-cidre
restart: unless-stopped
environment:
- PUID=1000 # user id the process runs as, matches ownership of the /adguard mount
- PGID=1000 # group id the process runs as
- TZ=Europe/Paris # change to your timezone
- BLOCK_COUNTRIES=cn,ru # choose countries listed IP to block. Full lists here https://github.com/vulnebify/cidre/tree/main/output/cidr/ipv4
- BLOCKLIST_CRON_TYPE=daily # daily or weekly
@@ -121,11 +125,12 @@
git clone https://git.djeex.fr/Djeex/adguard-cidre
cd adguard-cidre
```
2. **Modify docker-compose.yml**
2. **Edit the `.env` file**
- Set `BLOCK_COUNTRIES` environment variable with the countries you want to block.
- Adjust `BLOCKLIST_CRON` variables if you want a different update frequency.
- Bind mount your adguard configuration folder (wich contains `AdGuardHome.yaml`) to `/adguard`
- A `.env` file is included at the repo root with all environment variables (see [Environment Variables](#environment-variables)). Edit values there instead of `docker-compose.yml`.
- Set `BLOCK_COUNTRIES` with the countries you want to block.
- Adjust `BLOCKLIST_CRON_*` variables if you want a different update frequency.
- Bind mount your adguard configuration folder (wich contains `AdGuardHome.yaml`) to `/adguard` in `docker-compose.yml`.
- (optionnally) create and edit `manually_blocked_ips.conf` file in your adguard configuration folder to add other IPs you want to block. Only valid IP or CIDR entries will be processed, for exemple :
```bash
+1 -1
View File
@@ -1 +1 @@
1.4.1
1.5.0
+1 -1
View File
@@ -11,7 +11,7 @@ from pathlib import Path
logging.basicConfig(
level=logging.INFO,
format='[blocklist] %(levelname)s: %(message)s',
format="%(asctime)s [%(levelname)s] %(message)s",
stream=sys.stdout,
)
+9 -7
View File
@@ -5,14 +5,16 @@ services:
container_name: adguard-cidre
restart: unless-stopped
environment:
- TZ=Europe/Paris # change to your timezone
- BLOCK_COUNTRIES=cn,ru # choose countries listed IP to block. Full lists here https://github.com/vulnebify/cidre/tree/main/output/cidr/ipv4
- BLOCKLIST_CRON_TYPE=daily # daily or weekly
- PUID=${PUID} # user id the process runs as, matches ownership of the /adguard mount
- PGID=${PGID} # group id the process runs as
- TZ=${TZ} # change to your timezone
- BLOCK_COUNTRIES=${BLOCK_COUNTRIES} # choose countries listed IP to block. Full lists here https://github.com/vulnebify/cidre/tree/main/output/cidr/ipv4
- BLOCKLIST_CRON_TYPE=${BLOCKLIST_CRON_TYPE} # daily or weekly
# if weekly, choose the day
# - BLOCKLIST_CRON_DAY=mon
- BLOCKLIST_CRON_TIME=06:00
- DOCKER_API_URL=http://socket-proxy-adguard:2375 # docker socket proxy
- ADGUARD_CONTAINER_NAME=adguardhome # adguard container name
- BLOCKLIST_CRON_DAY=${BLOCKLIST_CRON_DAY}
- BLOCKLIST_CRON_TIME=${BLOCKLIST_CRON_TIME}
- DOCKER_API_URL=${DOCKER_API_URL} # docker socket proxy
- ADGUARD_CONTAINER_NAME=${ADGUARD_CONTAINER_NAME} # adguard container name
volumes:
- /path/to/adguard/confdir:/adguard
Executable
+105
View File
@@ -0,0 +1,105 @@
#!/bin/sh
set -e
CYAN="\033[1;36m"
NC="\033[0m"
log() { echo "$(date '+%Y-%m-%d %H:%M:%S') $*"; }
fail() { echo "$(date '+%Y-%m-%d %H:%M:%S') [!] $*" >&2; exit 1; }
print_banner() {
version=$(cat VERSION 2>/dev/null || echo "unknown")
title="AdGuard CIDRe - Version ${version}"
lines="Source: https://git.djeex.fr/Djeex/adguard-cidre
Mirror: https://github.com/Djeex/adguard-cidre"
width=${#title}
old_ifs=$IFS
IFS='
'
for l in $lines; do
[ ${#l} -gt "$width" ] && width=${#l}
done
IFS=$old_ifs
width=$((width + 2))
border=""
i=0
while [ "$i" -lt "$width" ]; do
border="${border}"
i=$((i + 1))
done
printf "${CYAN}╭%s╮${NC}\n" "$border"
total_pad=$((width - ${#title}))
left=$((total_pad / 2))
right=$((total_pad - left))
printf "${CYAN}${NC}%*s%s%*s${CYAN}${NC}\n" "$left" "" "$title" "$right" ""
printf "${CYAN}├%s┤${NC}\n" "$border"
IFS='
'
for l in $lines; do
printf "${CYAN}${NC} %-*s${CYAN}${NC}\n" "$((width - 1))" "$l"
done
IFS=$old_ifs
printf "${CYAN}╰%s╯${NC}\n" "$border"
}
print_banner
PUID=${PUID:-911}
PGID=${PGID:-911}
case "$PGID" in
''|*[!0-9]*) fail "PGID '$PGID' is not a valid numeric group id." ;;
esac
case "$PUID" in
''|*[!0-9]*) fail "PUID '$PUID' is not a valid numeric user id." ;;
esac
[ -d /adguard ] || fail "/adguard is not mounted — check the volume mapping in docker-compose.yml."
log "[i] Requested PUID=$PUID, PGID=$PGID"
log "[~] Checking group for GID $PGID..."
GROUP_NAME=$(getent group "$PGID" | cut -d: -f1 || true)
if [ -z "$GROUP_NAME" ]; then
log "[→] No existing group with GID $PGID, creating 'appgroup'."
addgroup -g "$PGID" appgroup || fail "Failed to create group with GID $PGID (addgroup exited $?)."
GROUP_NAME=appgroup
else
log "[i] Reusing existing group '$GROUP_NAME' (GID $PGID)."
fi
log "[✓] Group ready: $GROUP_NAME"
log "[~] Checking user for UID $PUID..."
USER_NAME=$(getent passwd "$PUID" | cut -d: -f1 || true)
if [ -z "$USER_NAME" ]; then
log "[→] No existing user with UID $PUID, creating 'appuser'."
adduser -D -u "$PUID" -G "$GROUP_NAME" appuser || fail "Failed to create user with UID $PUID (adduser exited $?)."
USER_NAME=appuser
else
log "[i] Reusing existing user '$USER_NAME' (UID $PUID)."
fi
log "[✓] User ready: $USER_NAME"
# Grant write access to the shared AdGuard config directory and to the files
# this script manages, without touching anything else AdGuardHome owns in
# there (its own db/certs/stats). AdGuardHome itself runs as root, so this is
# a one-way grant: it keeps full access regardless of what we chown here.
log "[~] Setting ownership of /adguard to $USER_NAME:$GROUP_NAME..."
chown "$USER_NAME:$GROUP_NAME" /adguard || fail "chown on /adguard failed — check that the host directory permissions allow it."
log "[✓] Ownership set on /adguard"
for f in AdGuardHome.yaml AdGuardHome.yaml.first-start.bak AdGuardHome.yaml.last-update.bak AdGuardHome.yaml.tmp; do
if [ -e "/adguard/$f" ]; then
chown "$USER_NAME:$GROUP_NAME" "/adguard/$f" || fail "chown on /adguard/$f failed."
log "[✓] chown OK: /adguard/$f"
fi
done
log "[→] Dropping privileges to $USER_NAME:$GROUP_NAME and starting blocklist_scheduler.py"
exec su-exec "$USER_NAME:$GROUP_NAME" python3 blocklist_scheduler.py "$@"