fix: container sets up its own data directory (closes #75)
check / check (push) Successful in 49s
check / check (push) Successful in 49s
bin/entrypoint.sh, still running as root, now creates DATA_DIR if missing and gives it and /data to the netwatch user with mode 750 before starting the backend as that user. An empty host directory owned by root, or one holding files from another uid, works with no step on the host, so the README no longer tells the operator to create or chown it. The image no longer sets that ownership at build time. Model: opus-5-5
This commit is contained in:
@@ -61,6 +61,16 @@ for proxy in $(printf '%s' "$TRUSTED_PROXIES" | tr ',' ' '); do
|
||||
echo "set_real_ip_from $cidr;"
|
||||
done > /etc/nginx/trusted-proxies.conf
|
||||
|
||||
# netwatch-server keeps its report files in DATA_DIR, on the /data
|
||||
# volume, which may be a host directory owned by root or by another
|
||||
# uid. Both are given to the netwatch user here, with the mode the
|
||||
# server gives a directory it creates, so the host directory needs no
|
||||
# preparing.
|
||||
export DATA_DIR="${DATA_DIR:-/data/reports}"
|
||||
mkdir -p "$DATA_DIR" || exit 1
|
||||
chown -R netwatch:netwatch /data "$DATA_DIR" || exit 1
|
||||
chmod 750 /data "$DATA_DIR" || exit 1
|
||||
|
||||
# A stop signal is only noted here; the loop below acts on it.
|
||||
stop_requested=""
|
||||
trap 'stop_requested=yes' TERM INT
|
||||
|
||||
Reference in New Issue
Block a user