docker: set up the data directory in an entrypoint (closes #166)
check / check (push) Successful in 1m9s

The runtime image no longer sets USER. Its new entrypoint,
deploy/docker-entrypoint.sh, runs as root: it creates the data
directory if needed, gives it and everything in it to the dnswatcher
user (uid 10001) with mode 700 on the directory, then runs dnswatcher
as that user with su-exec. An empty root-owned host directory, or one
holding a state file left by another uid, now works with no step on
the host, so the README's instruction to create and chown it is gone.
The startup check that the data directory is writable stays.

Model: opus-5-5
This commit is contained in:
2026-09-29 10:02:39 +00:00
parent 93c1fe15e3
commit d0ca6fbc81
4 changed files with 32 additions and 21 deletions
+17
View File
@@ -0,0 +1,17 @@
#!/bin/sh
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
# root only to give the data directory to the dnswatcher user: a host
# directory bind-mounted there keeps its host owner, often root, and may
# hold a state file left by another uid, which dnswatcher could neither
# read nor replace. dnswatcher itself always runs as the dnswatcher user.
set -eu
main() {
dir="${DNSWATCHER_DATA_DIR:-/var/lib/dnswatcher}"
mkdir -p "$dir"
chown -R dnswatcher:dnswatcher "$dir"
chmod 700 "$dir"
exec su-exec dnswatcher /usr/local/bin/dnswatcher "$@"
}
main "$@"