- rootfs/usr/local/bin/entrypoint.sh:
1. The "start all services" gate
(`if [ "$START_SERVICES" = "yes" ] || [ -z "$1" ]`) always evaluated
true on a first-run container regardless of $1, because
START_SERVICES is force-set to "yes" whenever no PID file exists yet.
Any command passed to `docker run` — `exec ...`, `sh -c ...`,
`shell`, or an arbitrary program — was swallowed into the
service-start+monitor branch before reaching the `case "$1"`
statement that already handles those subcommands, hanging the
container as a daemon instead of running the given command. Changed
the condition to `if [ -z "$1" ]` so the daemon branch only fires
when no command was given at all.
2. The `*/bin/sh | */bin/bash | bash | sh | shell)` case branch
unconditionally shifted $1 before `__exec_command "$@"` (a bare
`exec "$@"`). For `docker run image sh -c 'cmd'` this turned the
exec into `exec -c cmd` (command not found, exit 127) instead of
`exec sh -c 'cmd'`. Split the branch: real interpreter names
(*/bin/sh, */bin/bash, bash, sh) now pass through unshifted; the
"shell" keyword (not a real interpreter) gets its own branch that
shifts and prepends "sh" to any remaining args, or falls back to a
bare `__exec_command` (exec bash -l) when none remain.
Verified `bash -n` passes. Found and fixed upstream in
dockersrc/go, confirmed identical in this repo's generated
entrypoint.sh, and mechanically applied here with the same patch.
opengist
A containerized OpenGist — a self-hosted pastebin powered by Git. Create, share, and fork code snippets with full Git history, HTTP clone, SSH push/pull, and OAuth2 login via GitHub, GitLab, Gitea, or OpenID Connect. Built on Alpine Linux with SQLite storage and no external database required.
📦 Install
Via dockermgr (recommended)
sudo bash -c "$(curl -q -LSsf "https://github.com/systemmgr/installer/raw/main/install.sh")"
sudo systemmgr --config && sudo systemmgr install scripts
dockermgr update opengist
Manual docker run
docker run -d \
--restart always \
--name casjaysdevdocker-opengist-latest \
--hostname opengist \
-e TZ=${TIMEZONE:-America/New_York} \
-v /srv/$USER/docker/casjaysdevdocker/opengist/latest/volumes/data:/data:z \
-v /srv/$USER/docker/casjaysdevdocker/opengist/latest/volumes/config:/config:z \
-p 172.17.0.1:80:80 \
-p 172.17.0.1:7823:7823 \
casjaysdevdocker/opengist:latest
docker-compose
services:
opengist:
image: casjaysdevdocker/opengist:latest
container_name: casjaysdevdocker-opengist
hostname: opengist
environment:
- TZ=America/New_York
volumes:
- "/srv/$USER/docker/casjaysdevdocker/opengist/latest/volumes/data:/data:z"
- "/srv/$USER/docker/casjaysdevdocker/opengist/latest/volumes/config:/config:z"
ports:
- "172.17.0.1:80:80"
- "172.17.0.1:7823:7823"
restart: always
⚙️ Configuration
Volumes
| Path | Purpose |
|---|---|
/config |
Runtime configuration (auto-generated on first start) |
/data |
Gist repositories, SQLite database, logs, and index |
Ports
| Port | Protocol | Purpose |
|---|---|---|
80 |
HTTP | Web UI and HTTP Git clone/pull |
7823 |
TCP | Built-in SSH server for Git push/pull |
Environment variables
| Variable | Default | Description |
|---|---|---|
TZ |
America/New_York |
Container timezone |
HOSTNAME |
casjaysdev-opengist |
Sets the external-url in opengist config |
SERVER_NAME / FULL_DOMAIN_NAME |
— | Override hostname for external URL |
OPENGIST_APPNAME_ENABLED |
yes |
Set to no to disable the service |
OPENGIST_ROOT_USER_NAME |
— | Initial admin username |
OPENGIST_ROOT_PASS_WORD |
— | Initial admin password |
OPENGIST_USER_NAME |
— | Initial normal user name |
OPENGIST_USER_PASS_WORD |
— | Initial normal user password |
DEBUGGER |
— | Set to on to enable shell-level debug tracing |
Runtime config overrides
Place a shell script at /config/env/opengist.sh inside the container (or mount it as a file) to override any variable at runtime without rebuilding the image. A template is written on first start.
OAuth2
After first start, edit /config/opengist/config.yaml to add OAuth2 credentials:
github.client-key: <your-key>
github.secret: <your-secret>
gitlab.client-key: <your-key>
gitlab.secret: <your-secret>
gitlab.url: https://gitlab.com/
gitea.client-key: <your-key>
gitea.secret: <your-secret>
gitea.url: https://your-gitea-instance/
oidc.client-key: <your-key>
oidc.secret: <your-secret>
oidc.discovery-url: https://auth.example.com/.well-known/openid-configuration
OAuth2 callback URLs must follow the pattern:
http://<opengist-url>/oauth/<github|gitlab|gitea|openid-connect>/callback
🛠️ Development
Prerequisites
- Docker with
buildxsupport git
Get source
git clone "https://github.com/casjaysdevdocker/opengist" \
"$HOME/Projects/github/casjaysdevdocker/opengist"
cd "$HOME/Projects/github/casjaysdevdocker/opengist"
Or via dockermgr:
dockermgr download src casjaysdevdocker/opengist
Build the image
buildx
The build downloads the latest OpenGist release binary from GitHub at build time and bundles it into the image.
📄 License
WTFPL — see LICENSE.md