fix: container sets up its own data directory (closes #75)
check / check (push) Successful in 49s
check / check (push) Successful in 49s
bin/entrypoint.sh, still running as root, now creates DATA_DIR if missing and gives it and /data to the netwatch user with mode 750 before starting the backend as that user. An empty host directory owned by root, or one holding files from another uid, works with no step on the host, so the README no longer tells the operator to create or chown it. The image no longer sets that ownership at build time. Model: opus-5-5
This commit is contained in:
@@ -191,8 +191,9 @@ only inside the container, on `127.0.0.1:8081`. The image:
|
||||
- Sends the security headers `REPO_POLICIES.md` requires on every response, as
|
||||
`security-headers.conf` sets them, in place of the backend's own
|
||||
- Stores reports in `DATA_DIR`, `/data/reports` by default, on the `/data`
|
||||
volume. The backend runs as user `netwatch` (uid 1000), so a directory
|
||||
bind-mounted at `/data` must be writable by uid 1000
|
||||
volume. Before the backend starts, the image creates `DATA_DIR` and gives it
|
||||
and `/data` to user `netwatch` (uid 1000), which the backend runs as, so a
|
||||
host directory bind-mounted at `/data` ends up owned by uid 1000
|
||||
- Writes buffered reports to disk on `docker stop`, and exits non-zero if nginx
|
||||
or the backend exits on its own, so the platform restarts it
|
||||
|
||||
@@ -202,16 +203,6 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for netwatch needs:
|
||||
|
||||
- **Port:** container port `8080`.
|
||||
- **Volume:** container path `/data`; the reports are kept in `/data/reports`.
|
||||
- **First run:** upaas bind-mounts the host directory it is given and does not
|
||||
create it, and the backend, which runs as uid 1000, does not start unless it
|
||||
can write there. Create the directory, owned by uid 1000, before the first
|
||||
deploy:
|
||||
|
||||
```bash
|
||||
mkdir -p /path/to/data
|
||||
chown 1000:1000 /path/to/data
|
||||
```
|
||||
|
||||
- **Environment variables:** none is required. An empty one counts as unset, and
|
||||
one set to a value netwatch cannot use stops the container at start, with the
|
||||
reason in its log.
|
||||
|
||||
Reference in New Issue
Block a user