Merge pull request #443 from AtalayaLabs/claude/jolly-johnson-yso7z7
Optimize volume permission handling and reduce Docker build context
This commit is contained in:
+9
-1
@@ -21,11 +21,19 @@ rootless-compose.yml
|
|||||||
storage/
|
storage/
|
||||||
|
|
||||||
# Documentation
|
# Documentation
|
||||||
doc/
|
docs/
|
||||||
*.md
|
*.md
|
||||||
LICENSE
|
LICENSE
|
||||||
CODEOWNERS
|
CODEOWNERS
|
||||||
|
|
||||||
|
# Project assets and tooling not needed by the build
|
||||||
|
# (the Dockerfile only COPYs src, static, migrations, templates, build.rs,
|
||||||
|
# Cargo.*, and entrypoint.sh; everything else is dead weight in the context)
|
||||||
|
images/
|
||||||
|
charts/
|
||||||
|
tools/
|
||||||
|
tests/
|
||||||
|
|
||||||
# Miscellaneous
|
# Miscellaneous
|
||||||
.github/
|
.github/
|
||||||
.env
|
.env
|
||||||
|
|||||||
+7
-3
@@ -1,7 +1,10 @@
|
|||||||
# ─── Stage 1: Shared build base (avoids duplicate apk install) ────────────────
|
# ─── Stage 1: Shared build base (avoids duplicate apk install) ────────────────
|
||||||
FROM rust:1.94.1-alpine3.23 AS base
|
FROM rust:1.94.1-alpine3.23 AS base
|
||||||
|
# sqlx's postgres driver speaks the wire protocol in pure Rust (no pq-sys in
|
||||||
|
# Cargo.lock) and TLS goes through rustls, so libpq headers are never needed at
|
||||||
|
# build time. perl/make/gcc/musl-dev remain for the C builds of aws-lc-sys.
|
||||||
RUN apk --no-cache upgrade && \
|
RUN apk --no-cache upgrade && \
|
||||||
apk add --no-cache musl-dev pkgconfig postgresql-dev gcc perl make
|
apk add --no-cache musl-dev pkgconfig gcc perl make
|
||||||
|
|
||||||
# ─── Stage 2: Cache dependencies ─────────────────────────────────────────────
|
# ─── Stage 2: Cache dependencies ─────────────────────────────────────────────
|
||||||
FROM base AS cacher
|
FROM base AS cacher
|
||||||
@@ -49,9 +52,10 @@ LABEL org.opencontainers.image.title="OxiCloud" \
|
|||||||
org.opencontainers.image.licenses="MIT"
|
org.opencontainers.image.licenses="MIT"
|
||||||
|
|
||||||
# Install only necessary runtime dependencies and update packages
|
# Install only necessary runtime dependencies and update packages
|
||||||
# su-exec is needed by the entrypoint to drop privileges after fixing volume permissions
|
# su-exec is needed by the entrypoint to drop privileges after fixing volume permissions.
|
||||||
|
# No libpq: the pure-Rust sqlx postgres driver never links it.
|
||||||
RUN apk --no-cache upgrade && \
|
RUN apk --no-cache upgrade && \
|
||||||
apk add --no-cache libgcc ca-certificates libpq tzdata su-exec && \
|
apk add --no-cache libgcc ca-certificates tzdata su-exec && \
|
||||||
addgroup -g 1001 -S oxicloud && \
|
addgroup -g 1001 -S oxicloud && \
|
||||||
adduser -u 1001 -S oxicloud -G oxicloud
|
adduser -u 1001 -S oxicloud -G oxicloud
|
||||||
|
|
||||||
|
|||||||
+19
-7
@@ -9,14 +9,26 @@ set -e
|
|||||||
STORAGE_DIR="/app/storage"
|
STORAGE_DIR="/app/storage"
|
||||||
STATIC_DIR="/app/static"
|
STATIC_DIR="/app/static"
|
||||||
|
|
||||||
# Ensure the storage directory exists and is writable by oxicloud
|
# Recursively chown DIR to the oxicloud user, but only when its top-level
|
||||||
if [ -d "$STORAGE_DIR" ] && [ "$(id -u)" -eq 0 ]; then
|
# entry is not already owned by that user. The storage volume is a
|
||||||
chown -R oxicloud:oxicloud "$STORAGE_DIR"
|
# content-addressable blob store that can hold millions of objects; a blind
|
||||||
fi
|
# "chown -R" on every boot would re-stat and rewrite the inode of every blob,
|
||||||
|
# turning startup into minutes of disk I/O. Checking the root entry is the
|
||||||
|
# cheap idempotent guard: the first boot fixes a freshly mounted (root-owned)
|
||||||
|
# volume, and every later boot is a no-op.
|
||||||
|
ensure_owned() {
|
||||||
|
dir="$1"
|
||||||
|
if [ -d "$dir" ] && [ "$(stat -c %u "$dir")" != "$OXI_UID" ]; then
|
||||||
|
chown -R oxicloud:oxicloud "$dir"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
# Ensure static directory is readable
|
# Only root can chown; when started unprivileged the volume permissions are
|
||||||
if [ -d "$STATIC_DIR" ] && [ "$(id -u)" -eq 0 ]; then
|
# assumed to be correct already.
|
||||||
chown -R oxicloud:oxicloud "$STATIC_DIR"
|
if [ "$(id -u)" -eq 0 ]; then
|
||||||
|
OXI_UID="$(id -u oxicloud)"
|
||||||
|
ensure_owned "$STORAGE_DIR"
|
||||||
|
ensure_owned "$STATIC_DIR"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Drop privileges and exec the main binary (or whatever was passed as CMD)
|
# Drop privileges and exec the main binary (or whatever was passed as CMD)
|
||||||
|
|||||||
Reference in New Issue
Block a user