Container sets its data directory's owner and mode itself (#353)
check / check (push) Waiting to run
check / check (push) Waiting to run
Closes #340. The image no longer sets `USER`. Its new `ENTRYPOINT`, `deploy/docker-entrypoint.sh`, starts as root, creates `DATA_DIR` if missing, gives the directory and anything in it owned by another user to `webhooker` (UID 1000), sets the directory to `0750`, and runs the command as `webhooker` through `su-exec`. An empty root-owned bind mount, or data left by another UID, now works as mounted; the app never runs as root and is still PID 1. `CMD` is still `/app/webhooker`, so the `resetpw` commands are unchanged. Started with `--user`, the script only runs the command. It is in `/usr/local/bin`, not `/app`, which belongs to `webhooker`. README: the UID 1000 ownership block, the upaas pre-deploy commands and the restore ownership step are gone; the upaas volume bullet names only the path. - Judgement call: `su-exec` over `setpriv`: Alpine's small tool for this, needing only musl; busybox's `setpriv` cannot change user, and util-linux's adds `libcap-ng`. - Deviation: `su-exec` is pinned by version (`0.2-r3`), not by hash; `ca-certificates` beside it is unpinned. - Judgement call: each start reads every entry's owner but changes only entries owned by someone else. - `docker exec` and the health check now run as root, since the image sets no `USER`. - No automated test covers the script: the suite runs inside `docker build`, which cannot start a container. - A missing host directory under upaas is sneak/upaas#235. Model: opus-5-5 Reviewed-on: #353 Co-authored-by: clawbot <35+clawbot@noreply.example.org>
This commit was merged in pull request #353.
This commit is contained in:
Executable
+22
@@ -0,0 +1,22 @@
|
||||
#!/bin/sh
|
||||
# deploy/docker-entrypoint.sh: the image's ENTRYPOINT. A bind-mounted
|
||||
# data directory keeps its owner from the host, often root, and the app
|
||||
# could not write to it. Started as root, this creates DATA_DIR if
|
||||
# needed, gives it and everything in it to webhooker, sets its mode, and
|
||||
# runs the command as webhooker, so the app never runs as root. Started
|
||||
# as another user, it only runs the command.
|
||||
set -eu
|
||||
|
||||
main() {
|
||||
if [ "$(id -u)" != 0 ]; then
|
||||
exec "$@"
|
||||
fi
|
||||
|
||||
dir="${DATA_DIR:-/var/lib/webhooker}"
|
||||
mkdir -p "$dir"
|
||||
find "$dir" ! -user webhooker -exec chown -h webhooker:webhooker {} +
|
||||
chmod 750 "$dir"
|
||||
exec su-exec webhooker "$@"
|
||||
}
|
||||
|
||||
main "$@"
|
||||
Reference in New Issue
Block a user