adduser took the first free uid, 1000, and the entrypoint gives a bind-mounted /var/lib/pixa to pixad, so on the host a person's login account ended up owning pixa's database and cache. The image now creates the pixad group with gid 65532 and the pixad user with uid 65532, which host login and system accounts do not use. The first-run step of "Running under upaas" in README.md names the uid and gid. Model: opus-5-5
This commit is contained in:
+6
-2
@@ -68,8 +68,12 @@ RUN apk add --no-cache \
|
||||
COPY --from=builder /pixad /usr/local/bin/pixad
|
||||
COPY deploy/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
||||
|
||||
# Create non-root user, config directory, and data directory
|
||||
RUN adduser -D -H -s /sbin/nologin pixad && \
|
||||
# Create non-root user, config directory, and data directory. pixad
|
||||
# gets uid and gid 65532, which host login and system accounts do not
|
||||
# use: a bind-mounted /var/lib/pixa is given to pixad, and on the host
|
||||
# it must not belong to a person's account.
|
||||
RUN addgroup -g 65532 pixad && \
|
||||
adduser -D -H -s /sbin/nologin -u 65532 -G pixad pixad && \
|
||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
|
||||
|
||||
Reference in New Issue
Block a user