The named Docker volume mounted at /app/projects is created by Docker as root before the container starts, so the image's build-time chown never applies to it. A root-owned volume made the app (running as the non-root forge user) unable to write new game folders in production. Add an entrypoint that chowns /app/projects to forge at each startup, then drops privileges before exec'ing gunicorn.
22 lines
653 B
Docker
22 lines
653 B
Docker
FROM python:3.13-slim
|
|
|
|
WORKDIR /app
|
|
|
|
COPY requirements.txt requirements-prod.txt ./
|
|
RUN pip install --no-cache-dir -r requirements-prod.txt
|
|
|
|
COPY . .
|
|
|
|
RUN useradd --create-home forge && chown -R forge:forge /app
|
|
|
|
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
|
|
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
|
|
|
|
EXPOSE 5050
|
|
|
|
# Démarre en root (nécessaire pour corriger la propriété du volume monté sur
|
|
# /app/projects, voir docker-entrypoint.sh) — le script abandonne ensuite les
|
|
# privilèges root avant de lancer gunicorn.
|
|
ENTRYPOINT ["docker-entrypoint.sh"]
|
|
CMD ["gunicorn", "--bind", "0.0.0.0:5050", "--workers", "2", "app:app"]
|