Container makes /var/lib/pixa usable before starting pixad (closes #159)
check / check (push) Successful in 3m44s
check / check (push) Successful in 3m44s
The entrypoint now creates /var/lib/pixa if it is missing. When the directory or one of its top-level entries belongs to another user or group, it gives the whole tree to pixad (uid and gid 65532); it then sets the directory's mode to 750 and runs the server as pixad as before. Data left by a run under another uid is taken over this way. Only the top level is checked, so a normal start does not walk the cache; the tree is changed deepest first, so an interrupted start is finished by the next one. "Running under upaas" in README.md no longer tells the operator to create or chown the host directory. Model: opus-5-5
This commit is contained in:
@@ -40,9 +40,8 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
||||
|
||||
- **Port:** pixa listens on container port `8080`.
|
||||
- **Volume:** container path `/var/lib/pixa`, where pixa keeps its
|
||||
database and cache. upaas bind-mounts the host path it is given and
|
||||
does not create it, so the host directory must exist before the first
|
||||
deploy.
|
||||
database and cache. Creating the host directory when it is missing is
|
||||
upaas's job, tracked in https://git.eeqj.de/sneak/upaas/issues/235.
|
||||
- **Environment variables:**
|
||||
- `PIXA_SIGNING_KEY` (required): secret for signed and encrypted URLs
|
||||
and login, 32+ characters, for example from
|
||||
@@ -58,10 +57,6 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
||||
`healthy`. The probe uses the port from `PORT` (default `8080`), so a
|
||||
port changed only in a mounted config file is not seen by it: change
|
||||
the port with `PORT`.
|
||||
- **First run:** create the host directory, owned by root or by uid
|
||||
`65532` and gid `65532`. The server runs as the container's `pixad`
|
||||
user, which has that uid and gid, and the container gives the
|
||||
directory to `pixad` when it starts.
|
||||
|
||||
## Rationale
|
||||
|
||||
|
||||
Reference in New Issue
Block a user