fix: container sets up its own data directory (closes #75)
check / check (push) Successful in 49s

bin/entrypoint.sh, still running as root, now creates DATA_DIR if
missing and gives it and /data to the netwatch user with mode 750
before starting the backend as that user. An empty host directory
owned by root, or one holding files from another uid, works with no
step on the host, so the README no longer tells the operator to create
or chown it. The image no longer sets that ownership at build time.

Model: opus-5-5
This commit is contained in:
2026-09-29 09:16:58 +00:00
parent c226ceee01
commit 7d31f514e3
5 changed files with 24 additions and 14 deletions
+10
View File
@@ -61,6 +61,16 @@ for proxy in $(printf '%s' "$TRUSTED_PROXIES" | tr ',' ' '); do
echo "set_real_ip_from $cidr;"
done > /etc/nginx/trusted-proxies.conf
# netwatch-server keeps its report files in DATA_DIR, on the /data
# volume, which may be a host directory owned by root or by another
# uid. Both are given to the netwatch user here, with the mode the
# server gives a directory it creates, so the host directory needs no
# preparing.
export DATA_DIR="${DATA_DIR:-/data/reports}"
mkdir -p "$DATA_DIR" || exit 1
chown -R netwatch:netwatch /data "$DATA_DIR" || exit 1
chmod 750 /data "$DATA_DIR" || exit 1
# A stop signal is only noted here; the loop below acts on it.
stop_requested=""
trap 'stop_requested=yes' TERM INT