fix: container sets up its own data directory (closes #75)
check / check (push) Successful in 1m51s

bin/entrypoint.sh, still running as root, now creates DATA_DIR if
missing and gives it and /data to the netwatch user with mode 750
before starting the backend as that user. It stops the start instead
when a symbolic link is on the path to /data or DATA_DIR, since chown
and chmod would change what the link points to. An empty host
directory owned by root, or one holding files from another uid, works
with no step on the host, so the README no longer tells the operator
to create or chown it. The image no longer sets that ownership at
build time.

Model: opus-5-5
This commit is contained in:
2026-09-29 09:59:40 +00:00
parent f423768975
commit 3a335bbabe
5 changed files with 39 additions and 14 deletions
+2 -1
View File
@@ -104,7 +104,8 @@ this server. The image's entrypoint, `bin/entrypoint.sh`, starts the server as
user `netwatch` (uid 1000) with `BIND_ADDRESS=127.0.0.1` and `PORT=8081`, so
only nginx reaches it, and with `TRUSTED_PROXIES=127.0.0.1/32`, so it takes the
client address nginx passes on and no other. `DATA_DIR` is `/data/reports`, on
the `/data` volume, which `netwatch` owns. nginx replaces the security headers
the `/data` volume; the entrypoint creates it and gives it and `/data` to
`netwatch` before starting the server. nginx replaces the security headers
this server sets with those in the root `security-headers.conf`, so those are
what clients of the image see.