docker: set up the data directory in an entrypoint (closes #166) #167

Open
clawbot wants to merge 1 commits from issue-166-entrypoint-data-dir into next
Collaborator

Implements #166.

The runtime image no longer sets USER. Its new entrypoint, deploy/docker-entrypoint.sh, starts as root, creates the data directory (DNSWATCHER_DATA_DIR, /var/lib/dnswatcher by default) if needed, gives it and everything in it to the dnswatcher user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with su-exec, now installed in the runtime image, as pixa does.

A bind-mounted host directory no longer has to be chowned first. The README's upaas section now says only which path to mount.

What the diff does not show:

  • Ownership is changed recursively on every start, so a state file left by another uid is readable again. The directory holds one small file.
  • The image no longer creates /var/lib/dnswatcher at build time; the entrypoint does it on each start.
  • The startup check that the data directory is writable is unchanged.
  • docker exec into the container now runs as root unless told otherwise; the app never does.

Recorded run on d0ca6fb, which has this head's code, image built with make docker: with an empty root-owned host directory, and with one holding a state file owned by uid 4242, the container became healthy, dnswatcher ran as uid 10001, the state file was written, and a restart kept it.

Disclosures:

  • Judgement call: starting the image with a --user override now fails, because the entrypoint needs root to change ownership.
  • su-exec comes unpinned from the Alpine package index, like the existing ca-certificates and tzdata; the base image stays pinned by sha256.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/dnswatcher/issues/166. The runtime image no longer sets `USER`. Its new entrypoint, `deploy/docker-entrypoint.sh`, starts as root, creates the data directory (`DNSWATCHER_DATA_DIR`, `/var/lib/dnswatcher` by default) if needed, gives it and everything in it to the `dnswatcher` user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with `su-exec`, now installed in the runtime image, as pixa does. A bind-mounted host directory no longer has to be chowned first. The README's upaas section now says only which path to mount. What the diff does not show: - Ownership is changed recursively on every start, so a state file left by another uid is readable again. The directory holds one small file. - The image no longer creates `/var/lib/dnswatcher` at build time; the entrypoint does it on each start. - The startup check that the data directory is writable is unchanged. - `docker exec` into the container now runs as root unless told otherwise; the app never does. Recorded run on `d0ca6fb`, which has this head's code, image built with `make docker`: with an empty root-owned host directory, and with one holding a state file owned by uid 4242, the container became healthy, dnswatcher ran as uid 10001, the state file was written, and a restart kept it. Disclosures: - Judgement call: starting the image with a `--user` override now fails, because the entrypoint needs root to change ownership. - `su-exec` comes unpinned from the Alpine package index, like the existing `ca-certificates` and `tzdata`; the base image stays pinned by sha256. Model: opus-5-5
clawbot added the needs-review label 2026-09-29 12:12:47 +02:00
clawbot self-assigned this 2026-09-29 12:12:47 +02:00
Author
Collaborator
  • TODO.md, the new Completed Steps entry: "A bind-mounted host directory no longer has to be created or chowned first" is not true. This change only removes the need to chown it. When a bind mount is set up the way upaas does it, Docker will not start the container if the host path is missing, and upaas does not create that path yet (sneak/upaas#235). With docker run -v, Docker creates the path itself, and it did before this change too. Acceptable: say only that the host directory no longer has to be chowned first, and make no claim about creating it.

Model: opus-5-5

- `TODO.md`, the new Completed Steps entry: "A bind-mounted host directory no longer has to be created or chowned first" is not true. This change only removes the need to chown it. When a bind mount is set up the way upaas does it, Docker will not start the container if the host path is missing, and upaas does not create that path yet (https://git.eeqj.de/sneak/upaas/issues/235). With `docker run -v`, Docker creates the path itself, and it did before this change too. Acceptable: say only that the host directory no longer has to be chowned first, and make no claim about creating it. Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-29 12:54:29 +02:00
clawbot added 1 commit 2026-09-29 13:00:18 +02:00
The runtime image no longer sets USER. Its new entrypoint,
deploy/docker-entrypoint.sh, runs as root: it creates the data
directory if needed, gives it and everything in it to the dnswatcher
user (uid 10001) with mode 700 on the directory, then runs dnswatcher
as that user with su-exec. A bind-mounted host directory, whether
empty and root-owned or holding a state file left by another uid, no
longer has to be chowned first, and the README's upaas section now says
only which path to mount. The startup check that the data directory is
writable stays.

Model: opus-5-5
clawbot force-pushed issue-166-entrypoint-data-dir from d0ca6fbc81 to 16c577d6d4 2026-09-29 13:00:18 +02:00 Compare
Author
Collaborator

Finding in #167 (comment): the TODO.md entry, the commit message and the PR body now say only that the host directory no longer has to be chowned first, and make no claim about who creates it. The README never made that claim and is unchanged.

Model: opus-5-5

Finding in https://git.eeqj.de/sneak/dnswatcher/pulls/167#issuecomment-107163: the `TODO.md` entry, the commit message and the PR body now say only that the host directory no longer has to be chowned first, and make no claim about who creates it. The README never made that claim and is unchanged. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-09-29 13:00:29 +02:00
Some checks are pending
check / check (push) Waiting to run
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin issue-166-entrypoint-data-dir:issue-166-entrypoint-data-dir
git checkout issue-166-entrypoint-data-dir
Sign in to join this conversation.