Repository navigation
Run the Docker image as the hstore user - #20
Merged
Merged
Conversation
docker exec used to land as root, so running hstore inside the container could leave root-owned files in the data directory. The image now sets USER hstore. Starting with --user root still fixes ownership and drops privileges, and an unwritable data directory fails with a clear message.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #6
The image now ends with
USER hstore, so both the server anddocker execrun as uid 999.The root path in the entrypoint is still there for people who start the container with
--user root, usually to fix a root-owned bind mount: it chowns the data directory and drops tohstorewithsetprivlike before. If the data directory isn't writable byhstore, the entrypoint now stops right away and says how to fix it, instead of failing somewhere insidehstore init.Checked by hand with Docker:
docker exec id -unprintshstore, and every file in the data directory is owned byhstore.--user root: the ownership gets fixed, the server process runs as uid 999, and the container is healthy.One gotcha I hit while testing: an empty root-owned named volume doesn't reproduce the problem, because Docker copies the image directory's ownership onto empty volumes on first mount. Docker Desktop on macOS also ignores ownership on bind mounts, so the failure case only shows on Linux hosts or with a non-empty volume.