Entrypoint checks DATA_DIR in full before acting on it as root (closes #80)
check / check (push) Failing after 12m54s
check / check (push) Failing after 12m54s
`bin/entrypoint.sh` now checks `DATA_DIR` before it creates anything or changes an owner or mode: it must be `/data` or a path below it with no `.`, `..` or empty part, and no part of it that exists, `/data` included, may be a symbolic link. Anything else stops the start with one message naming `DATA_DIR`. Only then does it create `DATA_DIR`, give `/data` and everything in it to `netwatch` (`chown -R -h`, so a link in it is not followed) and set mode 750 on `/data` and `DATA_DIR`. The README section "Running under upaas" says which values are accepted. Model: opus-5-5
This commit is contained in:
@@ -216,8 +216,10 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for netwatch needs:
|
||||
- `CORS_ALLOWED_ORIGINS`, default empty: other origins whose pages may call
|
||||
the API
|
||||
- `DEBUG`, default `false`: debug logging
|
||||
- `DATA_DIR`, default `/data/reports`: leave unset; reports kept outside
|
||||
`/data` do not survive a redeploy
|
||||
- `DATA_DIR`, default `/data/reports`: the directory the reports are kept
|
||||
in: `/data` or a path below it, with no `.` or `..` part and no extra `/`.
|
||||
The container also stops if a part of the path that exists, `/data`
|
||||
included, is a symbolic link
|
||||
- `TRUSTED_PROXIES`, default empty: set it to the address the reverse proxy
|
||||
in front of the container connects from, as an IP address or CIDR; several
|
||||
are separated by commas. nginx takes the client address from
|
||||
|
||||
Reference in New Issue
Block a user