#!/bin/sh # deploy/docker-entrypoint.sh: the image's ENTRYPOINT. A bind-mounted # data directory keeps its owner from the host, often root, and the app # could not write to it. Started as root, this creates DATA_DIR if # needed, gives it and everything in it to webhooker, sets its mode, and # runs the command as webhooker, so the app never runs as root. Started # as another user, it only runs the command. set -eu main() { if [ "$(id -u)" != 0 ]; then exec "$@" fi dir="${DATA_DIR:-/var/lib/webhooker}" mkdir -p "$dir" find "$dir" ! -user webhooker -exec chown -h webhooker:webhooker {} + chmod 750 "$dir" exec su-exec webhooker "$@" } main "$@"