Merge pull request #443 from AtalayaLabs/claude/jolly-johnson-yso7z7

Optimize volume permission handling and reduce Docker build context
This commit is contained in:
Dionisio Pozo
2026-06-10 10:48:45 +02:00
committed by GitHub
3 changed files with 35 additions and 11 deletions
+9 -1
View File
@@ -21,11 +21,19 @@ rootless-compose.yml
storage/ storage/
# Documentation # Documentation
doc/ docs/
*.md *.md
LICENSE LICENSE
CODEOWNERS CODEOWNERS
# Project assets and tooling not needed by the build
# (the Dockerfile only COPYs src, static, migrations, templates, build.rs,
# Cargo.*, and entrypoint.sh; everything else is dead weight in the context)
images/
charts/
tools/
tests/
# Miscellaneous # Miscellaneous
.github/ .github/
.env .env
+7 -3
View File
@@ -1,7 +1,10 @@
# ─── Stage 1: Shared build base (avoids duplicate apk install) ──────────────── # ─── Stage 1: Shared build base (avoids duplicate apk install) ────────────────
FROM rust:1.94.1-alpine3.23 AS base FROM rust:1.94.1-alpine3.23 AS base
# sqlx's postgres driver speaks the wire protocol in pure Rust (no pq-sys in
# Cargo.lock) and TLS goes through rustls, so libpq headers are never needed at
# build time. perl/make/gcc/musl-dev remain for the C builds of aws-lc-sys.
RUN apk --no-cache upgrade && \ RUN apk --no-cache upgrade && \
apk add --no-cache musl-dev pkgconfig postgresql-dev gcc perl make apk add --no-cache musl-dev pkgconfig gcc perl make
# ─── Stage 2: Cache dependencies ───────────────────────────────────────────── # ─── Stage 2: Cache dependencies ─────────────────────────────────────────────
FROM base AS cacher FROM base AS cacher
@@ -49,9 +52,10 @@ LABEL org.opencontainers.image.title="OxiCloud" \
org.opencontainers.image.licenses="MIT" org.opencontainers.image.licenses="MIT"
# Install only necessary runtime dependencies and update packages # Install only necessary runtime dependencies and update packages
# su-exec is needed by the entrypoint to drop privileges after fixing volume permissions # su-exec is needed by the entrypoint to drop privileges after fixing volume permissions.
# No libpq: the pure-Rust sqlx postgres driver never links it.
RUN apk --no-cache upgrade && \ RUN apk --no-cache upgrade && \
apk add --no-cache libgcc ca-certificates libpq tzdata su-exec && \ apk add --no-cache libgcc ca-certificates tzdata su-exec && \
addgroup -g 1001 -S oxicloud && \ addgroup -g 1001 -S oxicloud && \
adduser -u 1001 -S oxicloud -G oxicloud adduser -u 1001 -S oxicloud -G oxicloud
+19 -7
View File
@@ -9,14 +9,26 @@ set -e
STORAGE_DIR="/app/storage" STORAGE_DIR="/app/storage"
STATIC_DIR="/app/static" STATIC_DIR="/app/static"
# Ensure the storage directory exists and is writable by oxicloud # Recursively chown DIR to the oxicloud user, but only when its top-level
if [ -d "$STORAGE_DIR" ] && [ "$(id -u)" -eq 0 ]; then # entry is not already owned by that user. The storage volume is a
chown -R oxicloud:oxicloud "$STORAGE_DIR" # content-addressable blob store that can hold millions of objects; a blind
fi # "chown -R" on every boot would re-stat and rewrite the inode of every blob,
# turning startup into minutes of disk I/O. Checking the root entry is the
# cheap idempotent guard: the first boot fixes a freshly mounted (root-owned)
# volume, and every later boot is a no-op.
ensure_owned() {
dir="$1"
if [ -d "$dir" ] && [ "$(stat -c %u "$dir")" != "$OXI_UID" ]; then
chown -R oxicloud:oxicloud "$dir"
fi
}
# Ensure static directory is readable # Only root can chown; when started unprivileged the volume permissions are
if [ -d "$STATIC_DIR" ] && [ "$(id -u)" -eq 0 ]; then # assumed to be correct already.
chown -R oxicloud:oxicloud "$STATIC_DIR" if [ "$(id -u)" -eq 0 ]; then
OXI_UID="$(id -u oxicloud)"
ensure_owned "$STORAGE_DIR"
ensure_owned "$STATIC_DIR"
fi fi
# Drop privileges and exec the main binary (or whatever was passed as CMD) # Drop privileges and exec the main binary (or whatever was passed as CMD)