Start on a fresh upaas volume and document running under upaas (closes #129)
check / check (push) Successful in 11s

upaas bind-mounts an existing host directory and sets no container
user, so a directory made with mkdir as root left pixad unable to
write /var/lib/pixa, and the container exited at startup.

The image now starts as root: deploy/docker-entrypoint.sh gives
/var/lib/pixa to pixad when pixad does not own it, then runs the
server as pixad through su-exec (alpine's package), so the server
never runs as root. README.md gains a "Running under upaas" section:
port, volume, environment variables, health check, first-run step.

Model: opus-5-5
This commit was merged in pull request #135.
This commit is contained in:
2026-09-28 15:12:48 +02:00
parent 2f7365cc9b
commit 50123b2a6d
4 changed files with 54 additions and 3 deletions
+6 -3
View File
@@ -61,17 +61,20 @@ RUN apk add --no-cache \
vips \
libheif \
ca-certificates \
tzdata
tzdata \
su-exec
# Copy binary from builder
COPY --from=builder /pixad /usr/local/bin/pixad
COPY deploy/docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
# Create non-root user, config directory, and data directory
RUN adduser -D -H -s /sbin/nologin pixad && \
mkdir -p /var/lib/pixa /etc/pixa && \
chown pixad:pixad /var/lib/pixa
USER pixad
# No USER: the entrypoint must start as root to give a bind-mounted
# /var/lib/pixa to pixad; it then runs the server as pixad.
WORKDIR /var/lib/pixa
EXPOSE 8080
@@ -84,4 +87,4 @@ HEALTHCHECK --interval=30s --timeout=5s --start-period=10s --retries=3 \
# Settings come from PORT and the PIXA_ environment variables; only
# PIXA_SIGNING_KEY is required. A config file mounted at
# /etc/pixa/config.yml is optional and is read when present.
ENTRYPOINT ["/usr/local/bin/pixad"]
ENTRYPOINT ["/usr/local/bin/docker-entrypoint.sh"]