fix: container sets up its own data directory (closes #75)
check / check (push) Successful in 49s

bin/entrypoint.sh, still running as root, now creates DATA_DIR if
missing and gives it and /data to the netwatch user with mode 750
before starting the backend as that user. An empty host directory
owned by root, or one holding files from another uid, works with no
step on the host, so the README no longer tells the operator to create
or chown it. The image no longer sets that ownership at build time.

Model: opus-5-5
This commit is contained in:
2026-09-29 09:16:58 +00:00
parent c226ceee01
commit 7d31f514e3
5 changed files with 24 additions and 14 deletions
+2 -1
View File
@@ -104,7 +104,8 @@ this server. The image's entrypoint, `bin/entrypoint.sh`, starts the server as
user `netwatch` (uid 1000) with `BIND_ADDRESS=127.0.0.1` and `PORT=8081`, so
only nginx reaches it, and with `TRUSTED_PROXIES=127.0.0.1/32`, so it takes the
client address nginx passes on and no other. `DATA_DIR` is `/data/reports`, on
the `/data` volume, which `netwatch` owns. nginx replaces the security headers
the `/data` volume; the entrypoint creates it and gives it and `/data` to
`netwatch` before starting the server. nginx replaces the security headers
this server sets with those in the root `security-headers.conf`, so those are
what clients of the image see.