Skip to content

Add MistServer 3.11 - #20366

Open
junojense wants to merge 2 commits into
docker-library:masterfrom
DDVTECH:new-image
Open

Add MistServer 3.11#20366
junojense wants to merge 2 commits into
docker-library:masterfrom
DDVTECH:new-image

Conversation

@junojense

@junojense junojense commented Nov 26, 2025

Copy link
Copy Markdown

Checklist for Review

NOTE: This checklist is intended for the use of the Official Images maintainers both to track the status of your PR and to help inform you and others of where we're at. As such, please leave the "checking" of items to the repository maintainers. If there is a point below for which you would like to provide additional information or note completion, please do so by commenting on the PR. Thanks! (and thanks for staying patient with us ❤️)

Extra Information

I am associated with upstream, the forked repository is contained in the official MistServer organisation. Our software is public domain, and is "licensed" under the unlicense. The current image on Docker hub builds off alpine and can be found here. The tests seem to be passing. I have also created a documentation PR which passes the markdown formatter.

@github-actions

This comment has been minimized.

@junojense

junojense commented Dec 3, 2025

Copy link
Copy Markdown
Author

Using a Docker-specific repository now that contains Dockerfiles for different versions, instead of directly including the source leading to jobs failing. The PR should be ready for review.

@junojense junojense changed the title Add MistServer 3.8 Add MistServer 3.9 Dec 3, 2025
@junojense

Copy link
Copy Markdown
Author

Hi again, can this PR be looked at?

@tianon

tianon commented Jan 31, 2026

Copy link
Copy Markdown
Member

I've taken a first pass at review, and these are my very high-level notes from it:

At first glance, the multi-stage build doesn't seem to be one of the cases in https://github.com/docker-library/faq#multi-stage-builds (using apk add --virtual and something like scanelf to find the runtime deps and keep them afterwards would probably work really well).

That's a lot of ARG - are all these really meaningful? Should their values be documented better? (Our build tooling won't ever use them, so they're mostly just noise here.)

Explicitly using Builder: buildkit isn't really necessary (the TARGETPLATFORM value it seems to be used to get isn't something we recommend relying on, preferring instead to see userspace/runtime detection based off things like apk --print-arch).

Building mbedtls from source is a little eyebrow-raising -- Alpine contains the same version 3.6.5, is there a reason it isn't used? (https://pkgs.alpinelinux.org/package/v3.23/main/x86_64/mbedtls-dev)

Having such long single-line RUN lines is really hard to read/review -- those should be split up with \ and newlines.

Using FROM alpine with no specific version is going to have a large tendency to break when the "square wheel" rolls, so we highly recommend pinning to an explicit release of Alpine like FROM alpine:3.23 so that you can more directly control/manage the rolling of that wheel (and the breakage that may or may not come from it).

Using LABEL is not recommended, as the inheritance behavior of it is really poor; see #3540, especially #3540 (comment) (our build system automatically adds appropriate similar annotations).

Using HEALTHCHECK is also not something I'd personally recommend setting on the image (https://github.com/docker-library/faq#healthcheck) -- perhaps this command should be included in the documentation instead, so that users who want its behavior can get it easily? (in either a healthcheck in Docker or an appropriate probe in Kubernetes, for example, which won't read HEALTHCHECK metadata anyways)

Ideally the download of the source code would have some kind of verification, but that's a little hard with the source code tarball being generated by GitHub directly. 😔

@github-actions

Copy link
Copy Markdown
Diff for 2596b6e:
diff --git a/_bashbrew-arches b/_bashbrew-arches
index 8b13789..e85a97f 100644
--- a/_bashbrew-arches
+++ b/_bashbrew-arches
@@ -1 +1,2 @@
-
+amd64
+arm64v8
diff --git a/_bashbrew-cat b/_bashbrew-cat
index bdfae4a..02b2505 100644
--- a/_bashbrew-cat
+++ b/_bashbrew-cat
@@ -1 +1,9 @@
-Maintainers: New Image! :D (@docker-library-bot)
+Maintainers: Jaron Viëtor <jaron.vietor@ddvtech.com> (@Thulinma), Marco van Dijk <marco.van.dijk@ddvtech.com> (@stronk-dev), Carina van der Meer <carina.van.der.meer@ddvtech.com> (@thoronwen), Balder Viëtor <balder.vietor@ddvtech.com> (@Rokamun), Ramkoemar Bhoera <ramkoemar.bhoera@ddvtech.com> (@ramkoemar), Juno Jense <unit-stamp-sled@duck.com> (@junojense)
+GitRepo: https://github.com/DDVTECH/mistserver-docker-builder.git
+GitFetch: refs/heads/main
+GitCommit: 6ad8faed85bf59bc95173fd9832f1867df55a278
+
+Tags: latest, 3.11.1
+Architectures: amd64, arm64v8
+Directory: 3.11.1
+File: Dockerfile.mistserver
diff --git a/_bashbrew-list b/_bashbrew-list
index e69de29..41da094 100644
--- a/_bashbrew-list
+++ b/_bashbrew-list
@@ -0,0 +1,2 @@
+mistserver:3.11.1
+mistserver:latest
diff --git a/_bashbrew-list-build-order b/_bashbrew-list-build-order
index e69de29..b74bea6 100644
--- a/_bashbrew-list-build-order
+++ b/_bashbrew-list-build-order
@@ -0,0 +1 @@
+mistserver:3.11.1
diff --git a/mistserver_3.11.1/Dockerfile.mistserver b/mistserver_3.11.1/Dockerfile.mistserver
new file mode 100644
index 0000000..268b6ef
--- /dev/null
+++ b/mistserver_3.11.1/Dockerfile.mistserver
@@ -0,0 +1,69 @@
+FROM alpine:3.24
+
+ARG MIST_OPTS=""
+ARG MIST_DEBUG=3
+ENV MIST_VERSION=3.11.1
+ENV MIST_SHA256=8a76b9cc06fcaf544a4d80763234a1b0001d34ea96e414c148e90fbb37d091d6
+
+ENV MBEDTLS_VERSION=3.6.6
+ENV MBEDTLS_SHA256=8fb65fae8dcae5840f793c0a334860a411f884cc537ea290ce1c52bb64ca007a
+
+RUN set -eux; \
+  apk add --no-cache --virtual .build-deps \
+    git \
+    patch \
+    meson \
+    ninja \
+    gcc \
+    g++ \
+    linux-headers \
+    pigz \
+    curl \
+    cjson-dev \
+    pkgconfig \
+    pax-utils; \
+  \
+  curl -fsSL -o /tmp/src.tar.gz "https://r.mistserver.org/dl/mistserver_sourceV${MIST_VERSION}.tar.gz"; \
+  echo "${MIST_SHA256} */tmp/src.tar.gz" | sha256sum -c -; \
+  mkdir /src; \
+  tar -xzf /tmp/src.tar.gz -C /src; \
+  rm -f /tmp/src.tar.gz; \
+  \
+# Explicitly build mbedtls because official builds lack DTLS support
+  mkdir -p /deps/build/mbedtls; \
+  curl -fsSL -o /tmp/mbedtls-${MBEDTLS_VERSION}.tar.bz2 "https://github.com/Mbed-TLS/mbedtls/releases/download/mbedtls-${MBEDTLS_VERSION}/mbedtls-${MBEDTLS_VERSION}.tar.bz2"; \
+  echo "${MBEDTLS_SHA256} */tmp/mbedtls-${MBEDTLS_VERSION}.tar.bz2" | sha256sum -c -; \
+  tar -xjf /tmp/mbedtls-${MBEDTLS_VERSION}.tar.bz2 -C /deps; \
+  rm -f /tmp/mbedtls-${MBEDTLS_VERSION}.tar.bz2; \
+  \
+  cp /src/subprojects/packagefiles/mbedtls/meson.build /deps/mbedtls-${MBEDTLS_VERSION}/; \
+  cp /src/subprojects/packagefiles/mbedtls/include/mbedtls/mbedtls_config.h /deps/mbedtls-${MBEDTLS_VERSION}/include/mbedtls/; \
+  \
+  cd /deps/build/mbedtls; \
+  meson setup /deps/mbedtls-${MBEDTLS_VERSION} -Dstrip=true; \
+  meson install; \
+  \
+  mkdir /build; \
+  cd /build; \
+  meson setup /src \
+    -DDOCKERRUN=true \
+    -DNOUPDATE=true \
+    -DDEBUG=${MIST_DEBUG} \
+    -DVERSION=${MIST_VERSION} \
+    -DRELEASE="Docker_$(apk --print-arch)" \
+    -Dstrip=true \
+    ${MIST_OPTS:-}; \
+  ninja install; \
+  \
+  runDeps="$( \
+    scanelf --needed --nobanner --format '%n' --recursive /usr/local \
+      | tr ',' '\n' \
+      | sort -u \
+      | awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' \
+  )"; \
+  apk add --no-cache --virtual .mist-rundeps $runDeps; \
+  apk del .build-deps
+
+EXPOSE 4242 8080 1935 5554 8889/udp 18203/udp
+
+ENTRYPOINT ["MistController"]

@junojense

Copy link
Copy Markdown
Author

Thanks for the feedback @tianon, all points have been addressed in the updated Dockerfile.

  • Got rid of the multi-stage build, we now use scanelf to find run-time deps
  • Significantly reduced ARG usage, the remaining arguments are...
    • MIST_DEBUG sets the MistServer logging level to production instead of development
    • MIST_OPTS space separated compile options as specified here
  • Removed Builder: buildkit in favour of apk --print-arch
  • Removed HEALTHCHECK, LABEL, improved the formatting of RUN, and pinned the alpine version

To elaborate on building mbedtls from source; we require DTLS support which is not present in mbedtls official builds / releases. Though, the retrieved source code is now at least verified with its SHA-256 checksum.

As for verification of MistServer itself, our newest release (3.11.1) includes downloads for the source code with matching SHA-256 checksum that we check against in the new Dockerfile.

As everything mentioned has been addressed, the PR should be ready for further review.

@junojense junojense changed the title Add MistServer 3.9 Add MistServer 3.11 Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants