Container makes its data directory usable itself (closes #42)
check / check (push) Successful in 3m18s
check / check (push) Successful in 3m18s
The entrypoint now creates the data directory if it is missing and stops the start when any step fails, so a failed cd can no longer change the ownership of some other directory. It already took ownership of the directory and dropped to the routewatch user; that is unchanged. The README's upaas section now says only which path to mount. Model: opus-5-5
This commit is contained in:
@@ -1,4 +1,5 @@
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
|
||||
# glibc silently ignores a malformed MALLOC_ARENA_MAX, so refuse it here.
|
||||
if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; then
|
||||
@@ -6,6 +7,9 @@ if [[ -n "${MALLOC_ARENA_MAX:-}" && ! "$MALLOC_ARENA_MAX" =~ ^[1-9][0-9]*$ ]]; t
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Give the data directory to the routewatch user before the daemon starts,
|
||||
# whether it is missing, an empty root-owned mount, or holds another uid's files.
|
||||
mkdir -p /var/lib/berlin.sneak.app.routewatch
|
||||
cd /var/lib/berlin.sneak.app.routewatch
|
||||
chown -R routewatch:routewatch .
|
||||
chmod 700 .
|
||||
|
||||
Reference in New Issue
Block a user