#!/bin/sh # deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as # root only to give the data directory to the dnswatcher user: a host # directory bind-mounted there keeps its host owner, often root, and may # hold a state file left by another uid, which dnswatcher could neither # read nor replace. dnswatcher itself always runs as the dnswatcher user. set -eu main() { dir="${DNSWATCHER_DATA_DIR:-/var/lib/dnswatcher}" mkdir -p "$dir" chown -R dnswatcher:dnswatcher "$dir" chmod 700 "$dir" exec su-exec dnswatcher /usr/local/bin/dnswatcher "$@" } main "$@"