adduser -D gave pixad the first free uid, 1000. Since #129 the container gives a bind-mounted /var/lib/pixa to pixad, so on the host a person's login account (usually uid 1000) ended up owning pixa's database and cache.
The Dockerfile runtime stage now creates the pixad group with gid 65532 and the pixad user with uid 65532 in it. The first-run step of "Running under upaas" in README.md names that uid and gid, so an operator can create the host directory with that owner or leave it to root.
Choice: 65532, the non-root user of the distroless images; above the host login range (1000 to 60000), clear of system accounts (below 1000) and of nobody (65534).
Not changed: deploy/docker-entrypoint.sh names the user only as pixad, so it follows the new uid without edits.
Checked once by hand: on a fresh root-owned host directory (made by a root container) bind-mounted at /var/lib/pixa, the container went healthy, the directory ended up owned by 65532:65532, the server ran as uid and gid 65532, a second container on the same directory answered the first run's image from its cache, and make docker-smoke passed under the lock.
Model: opus-5-5
Closes https://git.eeqj.de/sneak/pixa/issues/151.
`adduser -D` gave `pixad` the first free uid, 1000. Since https://git.eeqj.de/sneak/pixa/issues/129 the container gives a bind-mounted `/var/lib/pixa` to `pixad`, so on the host a person's login account (usually uid 1000) ended up owning pixa's database and cache.
The `Dockerfile` runtime stage now creates the `pixad` group with gid 65532 and the `pixad` user with uid 65532 in it. The first-run step of "Running under upaas" in `README.md` names that uid and gid, so an operator can create the host directory with that owner or leave it to root.
Choice: 65532, the non-root user of the distroless images; above the host login range (1000 to 60000), clear of system accounts (below 1000) and of `nobody` (65534).
Not changed: `deploy/docker-entrypoint.sh` names the user only as `pixad`, so it follows the new uid without edits.
Checked once by hand: on a fresh root-owned host directory (made by a root container) bind-mounted at `/var/lib/pixa`, the container went healthy, the directory ended up owned by 65532:65532, the server ran as uid and gid 65532, a second container on the same directory answered the first run's image from its cache, and `make docker-smoke` passed under the lock.
Model: opus-5-5
adduser took the first free uid, 1000, and the entrypoint gives a
bind-mounted /var/lib/pixa to pixad, so on the host a person's login
account ended up owning pixa's database and cache. The image now creates
the pixad group with gid 65532 and the pixad user with uid 65532, which
host login and system accounts do not use. The first-run step of
"Running under upaas" in README.md names the uid and gid.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Closes #151.
adduser -Dgavepixadthe first free uid, 1000. Since #129 the container gives a bind-mounted/var/lib/pixatopixad, so on the host a person's login account (usually uid 1000) ended up owning pixa's database and cache.The
Dockerfileruntime stage now creates thepixadgroup with gid 65532 and thepixaduser with uid 65532 in it. The first-run step of "Running under upaas" inREADME.mdnames that uid and gid, so an operator can create the host directory with that owner or leave it to root.Choice: 65532, the non-root user of the distroless images; above the host login range (1000 to 60000), clear of system accounts (below 1000) and of
nobody(65534).Not changed:
deploy/docker-entrypoint.shnames the user only aspixad, so it follows the new uid without edits.Checked once by hand: on a fresh root-owned host directory (made by a root container) bind-mounted at
/var/lib/pixa, the container went healthy, the directory ended up owned by 65532:65532, the server ran as uid and gid 65532, a second container on the same directory answered the first run's image from its cache, andmake docker-smokepassed under the lock.Model: opus-5-5
PASS:
pixadhas uid and gid 65532 in the image, and the first-run step of "Running under upaas" is true of it.Model: opus-5-5