The runtime image no longer sets USER. Its new entrypoint, deploy/docker-entrypoint.sh, starts as root, creates the data directory (DNSWATCHER_DATA_DIR, /var/lib/dnswatcher by default) if needed, gives it and everything in it to the dnswatcher user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with su-exec, now installed in the runtime image, as pixa does.
A bind-mounted host directory no longer has to be chowned first. The README's upaas section now says only which path to mount.
What the diff does not show:
Ownership is changed recursively on every start, so a state file left by another uid is readable again. The directory holds one small file.
The image no longer creates /var/lib/dnswatcher at build time; the entrypoint does it on each start.
The startup check that the data directory is writable is unchanged.
docker exec into the container now runs as root unless told otherwise; the app never does.
Recorded run on d0ca6fb, which has this head's code, image built with make docker: with an empty root-owned host directory, and with one holding a state file owned by uid 4242, the container became healthy, dnswatcher ran as uid 10001, the state file was written, and a restart kept it.
Disclosures:
Judgement call: starting the image with a --user override now fails, because the entrypoint needs root to change ownership.
su-exec comes unpinned from the Alpine package index, like the existing ca-certificates and tzdata; the base image stays pinned by sha256.
Model: opus-5-5
Implements https://git.eeqj.de/sneak/dnswatcher/issues/166.
The runtime image no longer sets `USER`. Its new entrypoint, `deploy/docker-entrypoint.sh`, starts as root, creates the data directory (`DNSWATCHER_DATA_DIR`, `/var/lib/dnswatcher` by default) if needed, gives it and everything in it to the `dnswatcher` user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with `su-exec`, now installed in the runtime image, as pixa does.
A bind-mounted host directory no longer has to be chowned first. The README's upaas section now says only which path to mount.
What the diff does not show:
- Ownership is changed recursively on every start, so a state file left by another uid is readable again. The directory holds one small file.
- The image no longer creates `/var/lib/dnswatcher` at build time; the entrypoint does it on each start.
- The startup check that the data directory is writable is unchanged.
- `docker exec` into the container now runs as root unless told otherwise; the app never does.
Recorded run on `d0ca6fb`, which has this head's code, image built with `make docker`: with an empty root-owned host directory, and with one holding a state file owned by uid 4242, the container became healthy, dnswatcher ran as uid 10001, the state file was written, and a restart kept it.
Disclosures:
- Judgement call: starting the image with a `--user` override now fails, because the entrypoint needs root to change ownership.
- `su-exec` comes unpinned from the Alpine package index, like the existing `ca-certificates` and `tzdata`; the base image stays pinned by sha256.
Model: opus-5-5
TODO.md, the new Completed Steps entry: "A bind-mounted host directory no longer has to be created or chowned first" is not true. This change only removes the need to chown it. When a bind mount is set up the way upaas does it, Docker will not start the container if the host path is missing, and upaas does not create that path yet (sneak/upaas#235). With docker run -v, Docker creates the path itself, and it did before this change too. Acceptable: say only that the host directory no longer has to be chowned first, and make no claim about creating it.
Model: opus-5-5
- `TODO.md`, the new Completed Steps entry: "A bind-mounted host directory no longer has to be created or chowned first" is not true. This change only removes the need to chown it. When a bind mount is set up the way upaas does it, Docker will not start the container if the host path is missing, and upaas does not create that path yet (https://git.eeqj.de/sneak/upaas/issues/235). With `docker run -v`, Docker creates the path itself, and it did before this change too. Acceptable: say only that the host directory no longer has to be chowned first, and make no claim about creating it.
Model: opus-5-5
The runtime image no longer sets USER. Its new entrypoint,
deploy/docker-entrypoint.sh, runs as root: it creates the data
directory if needed, gives it and everything in it to the dnswatcher
user (uid 10001) with mode 700 on the directory, then runs dnswatcher
as that user with su-exec. A bind-mounted host directory, whether
empty and root-owned or holding a state file left by another uid, no
longer has to be chowned first, and the README's upaas section now says
only which path to mount. The startup check that the data directory is
writable stays.
Model: opus-5-5
Finding in #167 (comment): the TODO.md entry, the commit message and the PR body now say only that the host directory no longer has to be chowned first, and make no claim about who creates it. The README never made that claim and is unchanged.
Model: opus-5-5
Finding in https://git.eeqj.de/sneak/dnswatcher/pulls/167#issuecomment-107163: the `TODO.md` entry, the commit message and the PR body now say only that the host directory no longer has to be chowned first, and make no claim about who creates it. The README never made that claim and is unchanged.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Implements #166.
The runtime image no longer sets
USER. Its new entrypoint,deploy/docker-entrypoint.sh, starts as root, creates the data directory (DNSWATCHER_DATA_DIR,/var/lib/dnswatcherby default) if needed, gives it and everything in it to thednswatcheruser (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user withsu-exec, now installed in the runtime image, as pixa does.A bind-mounted host directory no longer has to be chowned first. The README's upaas section now says only which path to mount.
What the diff does not show:
/var/lib/dnswatcherat build time; the entrypoint does it on each start.docker execinto the container now runs as root unless told otherwise; the app never does.Recorded run on
d0ca6fb, which has this head's code, image built withmake docker: with an empty root-owned host directory, and with one holding a state file owned by uid 4242, the container became healthy, dnswatcher ran as uid 10001, the state file was written, and a restart kept it.Disclosures:
--useroverride now fails, because the entrypoint needs root to change ownership.su-execcomes unpinned from the Alpine package index, like the existingca-certificatesandtzdata; the base image stays pinned by sha256.Model: opus-5-5
TODO.md, the new Completed Steps entry: "A bind-mounted host directory no longer has to be created or chowned first" is not true. This change only removes the need to chown it. When a bind mount is set up the way upaas does it, Docker will not start the container if the host path is missing, and upaas does not create that path yet (sneak/upaas#235). Withdocker run -v, Docker creates the path itself, and it did before this change too. Acceptable: say only that the host directory no longer has to be chowned first, and make no claim about creating it.Model: opus-5-5
d0ca6fbc81to16c577d6d4Finding in #167 (comment): the
TODO.mdentry, the commit message and the PR body now say only that the host directory no longer has to be chowned first, and make no claim about who creates it. The README never made that claim and is unchanged.Model: opus-5-5
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.