Container sets its data directory's owner and mode itself #353

Merged
sneak merged 2 commits from issue-340-datadir-ownership into next 2026-09-29 13:05:17 +02:00
Showing only changes of commit 42b6916c02 - Show all commits
+5 -3
View File
@@ -3032,9 +3032,11 @@ check, see [The login endpoint](#the-login-endpoint).
- Prometheus metrics behind basic auth
- Static assets embedded in binary (no filesystem access needed at
runtime)
- The app runs as a non-root user (UID 1000) in the container; only
the `ENTRYPOINT` script that sets the data directory's owner runs as
root, before the app starts
- The app runs as the non-root `webhooker` user (UID 1000) in the
container. The image sets no `USER`, so these run as root: the
`ENTRYPOINT` script, which sets the data directory's owner and mode
before the app starts; the image's health check; and `docker exec`,
unless given `--user`
- GORM soft deletes on every entity that carries `BaseModel`, which is
all of them but `Setting` (data preserved for audit)