Container makes /var/lib/pixa usable before starting pixad #161
@@ -40,9 +40,8 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
||||
|
||||
- **Port:** pixa listens on container port `8080`.
|
||||
- **Volume:** container path `/var/lib/pixa`, where pixa keeps its
|
||||
database and cache. upaas bind-mounts the host path it is given and
|
||||
does not create it, so the host directory must exist before the first
|
||||
deploy.
|
||||
database and cache. Creating the host directory when it is missing is
|
||||
upaas's job, tracked in https://git.eeqj.de/sneak/upaas/issues/235.
|
||||
- **Environment variables:**
|
||||
- `PIXA_SIGNING_KEY` (required): secret for signed and encrypted URLs
|
||||
and login, 32+ characters, for example from
|
||||
@@ -58,10 +57,6 @@ What the [upaas](https://git.eeqj.de/sneak/upaas) app for pixa needs:
|
||||
`healthy`. The probe uses the port from `PORT` (default `8080`), so a
|
||||
port changed only in a mounted config file is not seen by it: change
|
||||
the port with `PORT`.
|
||||
- **First run:** create the host directory, owned by root or by uid
|
||||
`65532` and gid `65532`. The server runs as the container's `pixad`
|
||||
user, which has that uid and gid, and the container gives the
|
||||
directory to `pixad` when it starts.
|
||||
|
||||
## Rationale
|
||||
|
||||
|
||||
@@ -29,6 +29,13 @@ P2: security: referer blacklist
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-29 the container makes `/var/lib/pixa` usable by itself (closes
|
||||
#159): `deploy/docker-entrypoint.sh` creates the directory if it is missing,
|
||||
gives the directory and everything in it to `pixad` when the directory or one
|
||||
of its top-level entries belongs to another user or group, sets its mode to
|
||||
`750`, then runs the server as `pixad`; data left by an earlier run under
|
||||
another uid is taken over this way; "Running under upaas" in `README.md` no
|
||||
longer tells the operator to create or chown the host directory.
|
||||
- 2026-09-29 variant content types kept in memory (closes #70):
|
||||
`Cache.metaCache` holds the content types of up to 10,000 variants in an LRU
|
||||
(`github.com/hashicorp/golang-lru/v2`), filled by `StoreVariant` and by
|
||||
|
||||
@@ -1,14 +1,22 @@
|
||||
#!/bin/sh
|
||||
# deploy/docker-entrypoint.sh: the Docker image's ENTRYPOINT. It runs as
|
||||
# root only to give /var/lib/pixa to pixad: a host directory
|
||||
# bind-mounted there keeps its host owner, often root, and pixad could
|
||||
# not write to it. The server itself always runs as pixad.
|
||||
# root only to make /var/lib/pixa usable by pixad: a host directory
|
||||
# bind-mounted there keeps its host owner, often root, and data from an
|
||||
# earlier run may belong to another uid. The server itself always runs
|
||||
# as pixad.
|
||||
set -eu
|
||||
|
||||
main() {
|
||||
if [ "$(stat -c %U /var/lib/pixa)" != pixad ]; then
|
||||
chown pixad:pixad /var/lib/pixa
|
||||
mkdir -p /var/lib/pixa
|
||||
# Only the directory and its top-level entries are checked, so a
|
||||
# normal start does not walk the cache. -depth gives each directory
|
||||
# to pixad after its contents, so a start stopped part way leaves
|
||||
# something at the top for the next start to find; -h changes a
|
||||
# symlink itself, never the file it points to.
|
||||
if [ -n "$(find /var/lib/pixa -maxdepth 1 \( ! -user pixad -o ! -group pixad \))" ]; then
|
||||
find /var/lib/pixa -depth -exec chown -h pixad:pixad {} +
|
||||
fi
|
||||
chmod 750 /var/lib/pixa
|
||||
exec su-exec pixad /usr/local/bin/pixad "$@"
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user