Start on a fresh upaas volume and document running under upaas (closes #129)
check / check (push) Successful in 11s
check / check (push) Successful in 11s
upaas bind-mounts an existing host directory and sets no container user, so a directory made with mkdir as root left pixad unable to write /var/lib/pixa, and the container exited at startup. The image now starts as root: deploy/docker-entrypoint.sh gives /var/lib/pixa to pixad when pixad does not own it, then runs the server as pixad through su-exec (alpine's package), so the server never runs as root. README.md gains a "Running under upaas" section: port, volume, environment variables, health check, first-run step. Model: opus-5-5
This commit was merged in pull request #135.
This commit is contained in:
+6
-3
@@ -61,17 +61,20 @@ RUN apk add --no-cache \
|
||||
vips \
|
||||
libheif \
|
||||
ca-certificates \
|
||||
tzdata
|
||||
tzdata \
|
||||
su-exec
|
||||
|
||||
# Copy binary from builder
|
||||
COPY --from=builder /pixad /usr/local/bin/pixad
|
||||
COPY deploy/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
||||
|
||||
# Create non-root user, config directory, and data directory
|
||||
RUN adduser -D -H -s /sbin/nologin pixad && \
|
||||
mkdir -p /var/lib/pixa /etc/pixa && \
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
|
||||
USER pixad
|
||||
# No USER: the entrypoint must start as root to give a bind-mounted
|
||||
# /var/lib/pixa to pixad; it then runs the server as pixad.
|
||||
WORKDIR /var/lib/pixa
|
||||
|
||||
EXPOSE 8080
|
||||
@@ -84,4 +87,4 @@ HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
|
||||
# Settings come from PORT and the PIXA_ environment variables; only
|
||||
# PIXA_SIGNING_KEY is required. A config file mounted at
|
||||
# /etc/pixa/config.yml is optional and is read when present.
|
||||
ENTRYPOINT ["/usr/local/bin/pixad"]
|
||||
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]
|
||||
|
||||
Reference in New Issue
Block a user