Container sets its data directory's owner and mode itself (closes #340)
check / check (push) Successful in 4m12s
check / check (push) Successful in 4m12s
The image now starts as root through deploy/docker-entrypoint.sh, which creates DATA_DIR if it is missing, gives the directory and anything in it owned by another user to webhooker, sets the directory to 0750, and runs the command as webhooker with su-exec. An empty root-owned bind mount, or data left by another uid, now works with no step on the host. Started with --user, the script only runs the command. The README drops every instruction to create or chown the host directory; the upaas volume bullet names only the path. Model: opus-5-5
This commit is contained in:
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/bin/sh
|
||||
# deploy/docker-entrypoint.sh: the image's ENTRYPOINT. A bind-mounted
|
||||
# data directory keeps its owner from the host, often root, and the app
|
||||
# could not write to it. Started as root, this creates DATA_DIR if
|
||||
# needed, gives it and everything in it to webhooker, sets its mode, and
|
||||
# runs the command as webhooker, so the app never runs as root. Started
|
||||
# as another user, it only runs the command.
|
||||
set -eu
|
||||
|
||||
main() {
|
||||
if [ "$(id -u)" != 0 ]; then
|
||||
exec "$@"
|
||||
fi
|
||||
|
||||
dir="${DATA_DIR:-/var/lib/webhooker}"
|
||||
mkdir -p "$dir"
|
||||
find "$dir" ! -user webhooker -exec chown -h webhooker:webhooker {} +
|
||||
chmod 750 "$dir"
|
||||
exec su-exec webhooker "$@"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user