Fix projects/ volume ownership on container start
The named Docker volume mounted at /app/projects is created by Docker as root before the container starts, so the image's build-time chown never applies to it. A root-owned volume made the app (running as the non-root forge user) unable to write new game folders in production. Add an entrypoint that chowns /app/projects to forge at each startup, then drops privileges before exec'ing gunicorn.
This commit is contained in:
+7
-1
@@ -8,8 +8,14 @@ RUN pip install --no-cache-dir -r requirements-prod.txt
|
|||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN useradd --create-home forge && chown -R forge:forge /app
|
RUN useradd --create-home forge && chown -R forge:forge /app
|
||||||
USER forge
|
|
||||||
|
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
||||||
|
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
||||||
|
|
||||||
EXPOSE 5050
|
EXPOSE 5050
|
||||||
|
|
||||||
|
# Démarre en root (nécessaire pour corriger la propriété du volume monté sur
|
||||||
|
# /app/projects, voir docker-entrypoint.sh) — le script abandonne ensuite les
|
||||||
|
# privilèges root avant de lancer gunicorn.
|
||||||
|
ENTRYPOINT ["docker-entrypoint.sh"]
|
||||||
CMD ["gunicorn", "--bind", "0.0.0.0:5050", "--workers", "2", "app:app"]
|
CMD ["gunicorn", "--bind", "0.0.0.0:5050", "--workers", "2", "app:app"]
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/sh
|
||||||
|
# Un volume Docker nommé (ex: forge_projects, voir docker-compose.prod.yml)
|
||||||
|
# est créé par Docker lui-même, propriété de root, AVANT que le conteneur ne
|
||||||
|
# démarre — le "chown" fait au build de l'image (voir Dockerfile) n'a donc
|
||||||
|
# aucun effet dessus une fois monté par-dessus /app/projects. On corrige ici,
|
||||||
|
# à chaque démarrage (idempotent, sans risque à répéter), puis on abandonne
|
||||||
|
# les privilèges root pour lancer le vrai serveur en tant qu'utilisateur
|
||||||
|
# "forge" — ce script tourne donc brièvement en root, uniquement pour ça.
|
||||||
|
set -e
|
||||||
|
|
||||||
|
mkdir -p /app/projects
|
||||||
|
chown -R forge:forge /app/projects
|
||||||
|
|
||||||
|
exec su forge -s /bin/sh -c 'exec "$@"' -- "$@"
|
||||||
Reference in New Issue
Block a user