docker: set up the data directory in an entrypoint (closes #166)
check / check (push) Successful in 1m9s
check / check (push) Successful in 1m9s
The runtime image no longer sets USER. Its new entrypoint, deploy/docker-entrypoint.sh, runs as root: it creates the data directory if needed, gives it and everything in it to the dnswatcher user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with su-exec. An empty root-owned host directory, or one holding a state file left by another uid, now works with no step on the host, so the README's instruction to create and chown it is gone. The startup check that the data directory is writable stays. Model: opus-5-5
This commit is contained in:
@@ -19,6 +19,12 @@ Rationale, Design, TODO, License, Author) if any are still missing.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29: the image sets up its own data directory. Its entrypoint,
|
||||
`deploy/docker-entrypoint.sh`, starts as root, creates the data directory if
|
||||
needed, gives it and everything in it to the `dnswatcher` user with mode 700
|
||||
on the directory, then runs dnswatcher as that user with `su-exec`. A
|
||||
bind-mounted host directory no longer has to be created or chowned first,
|
||||
and the README no longer asks for it (closes #166).
|
||||
- 2026-09-29: `.golangci.yml` re-fetched unchanged from `sneak/prompts`. It
|
||||
replaces the deprecated `gomodguard` with `gomodguard_v2`, so `make lint` no
|
||||
longer warns about it, and turns on `depguard` with the org `test-support`
|
||||
|
||||
Reference in New Issue
Block a user