Files
litellm/Dockerfile
T
inference-bot fd34e33508 Sync packaging to live v1.84.0 deployment (CVE-2026-35029/59822 fix line)
- Dockerfile: pin ghcr.io/berriai/litellm:v1.84.0 (was floating
  main-v1.74.0-stable, which silently moved to a newer digest).
  v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on
  /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session
  auth bypass, fixed 1.84.0, CISA KEV).
- Drop the v1.74.0-era sed CORS patch: upstream v1.84.0 moved the
  file and now reads LITELLM_CORS_ORIGINS natively.
- start.sh: export LITELLM_CORS_ORIGINS (the native v1.84.0 var)
  instead of LITELLM_CORS_ALLOWED_ORIGINS (the old sed-patch var
  that v1.84.0 ignores) — keeps CORS locked to chat.inference.coop.
- CloudronManifest: upstreamVersion 1.74.0 -> 1.84.0.

Live gateway already runs v1.84.0 (image digest
sha256:dc532d896ba8..., built 2026-10-02 04:50 UTC); this commit
makes the repo mirror the deployed packaging per the no-drift rule.
LITELLM_CORS_ORIGINS also set as a Cloudron env var on the app so
the running container honours it without a rebuild.
2026-10-01 23:32:43 -06:00

31 lines
1.3 KiB
Docker

FROM ghcr.io/berriai/litellm:v1.84.0
# v1.84.0 is the fix line for CVE-2026-35029 (auth bypass on
# /config/update, fixed 1.83.0) and CVE-2026-59822 (MCP session auth
# bypass, fixed 1.84.0, CISA KEV catalog). Pin the exact tag — do NOT
# use a floating tag like main-v1.74.0-stable, which silently moved.
# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
# container, so we keep root to match the base image and avoid /app/data
# volume-ownership issues.
# Create the data directory (Cloudron mounts the localstorage volume here)
RUN mkdir -p /app/data /app/code
# Create a startup script that configures LiteLLM with Cloudron addons
COPY start.sh /app/code/start.sh
RUN chmod +x /app/code/start.sh
# Default config — will be overridden by Cloudron env vars at runtime
COPY config.yaml /app/data/config.yaml
# Override the base image's ENTRYPOINT (which is `litellm`) so our
# startup script runs instead of being passed as an argument to litellm.
ENTRYPOINT ["/app/code/start.sh"]
# No CORS patch needed since v1.84.0: upstream replaced the hardcoded
# `origins = ["*"]` with a native LITELLM_CORS_ORIGINS env var (start.sh
# exports it). The old sed patch targeted a v1.74.0 file layout that no
# longer exists — the v1.84.0 rebuild self-skipped it correctly.