docker: set up the data directory in an entrypoint (closes #166)
check / check (push) Successful in 1m9s
check / check (push) Successful in 1m9s
The runtime image no longer sets USER. Its new entrypoint, deploy/docker-entrypoint.sh, runs as root: it creates the data directory if needed, gives it and everything in it to the dnswatcher user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with su-exec. An empty root-owned host directory, or one holding a state file left by another uid, now works with no step on the host, so the README's instruction to create and chown it is gone. The startup check that the data directory is writable stays. Model: opus-5-5
This commit is contained in:
@@ -533,17 +533,7 @@ repository's `Dockerfile` and runs it. The app needs:
|
||||
- **Branch:** `prod`. `prod` is cut from `main`, and merging a `main` to
|
||||
`prod` pull request is a deploy.
|
||||
- **Volume:** one host directory mounted at `/var/lib/dnswatcher`, where
|
||||
the state file lives. upaas bind-mounts the host path it is given and
|
||||
does not create it. The container runs as uid 10001 and does not start
|
||||
unless it can write there. Create the directory before the first
|
||||
deploy:
|
||||
|
||||
```sh
|
||||
mkdir -p /path/to/data
|
||||
chown 10001:10001 /path/to/data
|
||||
chmod 700 /path/to/data
|
||||
```
|
||||
|
||||
the state file lives.
|
||||
- **Network and port:** the dashboard is unauthenticated and shows every
|
||||
watched name and recent alert, and upaas publishes every mapped port on
|
||||
all interfaces of the host
|
||||
|
||||
Reference in New Issue
Block a user