From 5a2c87630c1b107cf0174f772f2e75d3411687f8 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Mon, 28 Aug 2017 20:02:55 +0200 Subject: [PATCH] adapt dir permissions for openshift and add dumb-init This commit updates directory permissions to be compatible with OpenShift which starts the container with an arbitrary uid which is member of the root group. For more information please consult https://docs.openshift.org/latest/creating_images/guidelines.html. dumb-init is added to have a proper PID 1. bash should not run as PID 1 as this could lead to improper container shutdown. --- Dockerfile | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index dab432ca..4cc5c04c 100644 --- a/Dockerfile +++ b/Dockerfile @@ -16,6 +16,12 @@ RUN cd /usr/bin && \ tar -xf dockerize.tar.gz && \ rm dockerize.tar.gz +# dumb-init for a proper PID 1 +RUN cd /tmp && \ + wget https://github.com/Yelp/dumb-init/releases/download/v1.2.0/dumb-init_1.2.0_amd64.deb && \ + dpkg -i dumb-init_1.2.0_amd64.deb && \ + rm dumb-init_1.2.0_amd64.deb + # explicitly add Gemfile and install dependencies using bundler to make use of # Docker's caching WORKDIR /osem/ @@ -25,12 +31,13 @@ RUN bundle install --without test development # add OSEM files and prepare them for use inside a Docker container COPY . /osem/ -RUN chown osem.osem /osem/ -R && \ +RUN chown -R osem.root /osem/ && \ + chmod -R g=u /osem/ && \ mv /osem/config/database.yml.docker /osem/config/database.yml # data directory is used to cache the secret key in a file ENV DATA_DIR /data -RUN install -d -m 0700 -o osem $DATA_DIR +RUN install -d -m 0770 -o osem -g root $DATA_DIR VOLUME ["$DATA_DIR"] USER osem @@ -42,4 +49,7 @@ COPY docker/init.sh /init.sh # from a webserver ENV RAILS_SERVE_STATIC_FILES 1 +# Runs "/usr/bin/dumb-init -- /my/script --with --args" +ENTRYPOINT ["/usr/bin/dumb-init", "--"] + CMD ["bash", "/init.sh"]