Skip to content

Run the Docker image as the hstore user - #20

Merged
venkat1701 merged 2 commits into
mainfrom
fix/docker-non-root-user
Oct 4, 2026
Merged

venkat1701 merged 2 commits into
mainfrom
fix/docker-non-root-user

Conversation

@venkat1701

Copy link
Copy Markdown
Collaborator

Closes #6

The image now ends with USER hstore, so both the server and docker exec run as uid 999.

The root path in the entrypoint is still there for people who start the container with --user root, usually to fix a root-owned bind mount: it chowns the data directory and drops to hstore with setpriv like before. If the data directory isn't writable by hstore, the entrypoint now stops right away and says how to fix it, instead of failing somewhere inside hstore init.

Checked by hand with Docker:

  • Default named volume: the container is healthy, docker exec id -un prints hstore, and every file in the data directory is owned by hstore.
  • A root-owned, non-empty volume: the container exits with code 1 and the new message.
  • The same volume started with --user root: the ownership gets fixed, the server process runs as uid 999, and the container is healthy.

One gotcha I hit while testing: an empty root-owned named volume doesn't reproduce the problem, because Docker copies the image directory's ownership onto empty volumes on first mount. Docker Desktop on macOS also ignores ownership on bind mounts, so the failure case only shows on Linux hosts or with a non-empty volume.

docker exec used to land as root, so running hstore inside the container
could leave root-owned files in the data directory. The image now sets
USER hstore. Starting with --user root still fixes ownership and drops
privileges, and an unwritable data directory fails with a clear message.
@venkat1701
venkat1701 merged commit c5f9aa9 into main Oct 4, 2026
@venkat1701
venkat1701 deleted the fix/docker-non-root-user branch October 4, 2026 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

docker exec runs as root

1 participant