sneak ruled on 2026-09-29 that an app's operator never pre-creates or chowns a host directory for the app's data, and no README tells him to (filed for pixa as sneak/pixa#159). The container sets its data directory's permissions itself.
That covers ownership, but not existence. upaas mounts an app volume as a bind mount through Docker's mount API (buildMounts in internal/docker/client.go, mount.TypeBind), and Docker refuses a bind mount whose host path does not exist. upaas does not create the path first, so a new app's first deploy fails unless someone runs mkdir on the host, which the ruling rules out.
Definition of done
Before creating an app's container, upaas creates each of the app's volume host paths that does not exist yet (os.MkdirAll, mode 0755, owned by root; the container fixes ownership itself). An existing path is left alone.
A test covers a missing path being created and an existing one being left untouched.
README: the volume section says upaas creates a missing host directory, and nothing tells the operator to create one.
Model: opus-5-5
sneak ruled on 2026-09-29 that an app's operator never pre-creates or chowns a host directory for the app's data, and no README tells him to (filed for pixa as https://git.eeqj.de/sneak/pixa/issues/159). The container sets its data directory's permissions itself.
That covers ownership, but not existence. upaas mounts an app volume as a bind mount through Docker's mount API (`buildMounts` in `internal/docker/client.go`, `mount.TypeBind`), and Docker refuses a bind mount whose host path does not exist. upaas does not create the path first, so a new app's first deploy fails unless someone runs `mkdir` on the host, which the ruling rules out.
## Definition of done
- Before creating an app's container, upaas creates each of the app's volume host paths that does not exist yet (`os.MkdirAll`, mode 0755, owned by root; the container fixes ownership itself). An existing path is left alone.
- A test covers a missing path being created and an existing one being left untouched.
- README: the volume section says upaas creates a missing host directory, and nothing tells the operator to create one.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
sneak ruled on 2026-09-29 that an app's operator never pre-creates or chowns a host directory for the app's data, and no README tells him to (filed for pixa as sneak/pixa#159). The container sets its data directory's permissions itself.
That covers ownership, but not existence. upaas mounts an app volume as a bind mount through Docker's mount API (
buildMountsininternal/docker/client.go,mount.TypeBind), and Docker refuses a bind mount whose host path does not exist. upaas does not create the path first, so a new app's first deploy fails unless someone runsmkdiron the host, which the ruling rules out.Definition of done
os.MkdirAll, mode 0755, owned by root; the container fixes ownership itself). An existing path is left alone.Model: opus-5-5