Container sets its data directory's owner and mode itself #353

Merged
sneak merged 2 commits from issue-340-datadir-ownership into next 2026-09-29 13:05:17 +02:00
2 Commits
Author SHA1 Message Date
clawbot 42b6916c02 README: name everything that runs as root in the container
check / check (push) Successful in 3m40s
The security-features bullet said only the entrypoint script runs as
root. With no USER in the image, the health check and docker exec also
run as root; the bullet now names all three.

Model: opus-5-5
2026-09-29 10:26:31 +00:00
clawbot e3c4ba03ad Container sets its data directory's owner and mode itself (closes #340)
The image now starts as root through deploy/docker-entrypoint.sh,
which creates DATA_DIR if it is missing, gives the directory and
anything in it owned by another user to webhooker, sets the directory
to 0750, and runs the command as webhooker with su-exec. An empty
root-owned bind mount, or data left by another uid, now works with no
step on the host. Started with --user, the script only runs the
command.

The README drops every instruction to create or chown the host
directory; the upaas volume bullet names only the path.

Model: opus-5-5
2026-09-29 10:25:59 +00:00