Start on a fresh upaas volume and document running under upaas (closes #129)
check / check (push) Successful in 3m16s
check / check (push) Successful in 3m16s
upaas bind-mounts an existing host directory and sets no container user, so a directory made with mkdir as root left pixad unable to write /var/lib/pixa, and the container exited at startup. The image now starts as root: deploy/docker-entrypoint.sh gives /var/lib/pixa to pixad when pixad does not own it, then runs the server as pixad through su-exec (alpine's package), so the server never runs as root. README.md gains a "Running under upaas" section: port, volume, environment variables, health check, first-run step. Model: opus-5-5
This commit is contained in:
Executable
+15
@@ -0,0 +1,15 @@
|
||||
#!/bin/sh
|
||||
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
|
||||
# root only to give /var/lib/pixa to pixad: a host directory
|
||||
# bind-mounted there keeps its host owner, often root, and pixad could
|
||||
# not write to it. The server itself always runs as pixad.
|
||||
set -eu
|
||||
|
||||
main() {
|
||||
if [ "$(stat -c %U /var/lib/pixa)" != pixad ]; then
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
fi
|
||||
exec su-exec pixad /usr/local/bin/pixad "$@"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user