check / check (push) Waiting to run
The runtime image no longer sets USER. Its new entrypoint, deploy/docker-entrypoint.sh, runs as root: it creates the data directory if needed, gives it and everything in it to the dnswatcher user (uid 10001) with mode 700 on the directory, then runs dnswatcher as that user with su-exec. A bind-mounted host directory, whether empty and root-owned or holding a state file left by another uid, no longer has to be chowned first, and the README's upaas section now says only which path to mount. The startup check that the data directory is writable stays. Model: opus-5-5
18 lines
599 B
Bash
Executable File
18 lines
599 B
Bash
Executable File
#!/bin/sh
|
|
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
|
|
# root only to give the data directory to the dnswatcher user: a host
|
|
# directory bind-mounted there keeps its host owner, often root, and may
|
|
# hold a state file left by another uid, which dnswatcher could neither
|
|
# read nor replace. dnswatcher itself always runs as the dnswatcher user.
|
|
set -eu
|
|
|
|
main() {
|
|
dir="${DNSWATCHER_DATA_DIR:-/var/lib/dnswatcher}"
|
|
mkdir -p "$dir"
|
|
chown -R dnswatcher:dnswatcher "$dir"
|
|
chmod 700 "$dir"
|
|
exec su-exec dnswatcher /usr/local/bin/dnswatcher "$@"
|
|
}
|
|
|
|
main "$@"
|