Public Access
Visitor sign in kiosk: multi-site, badge printing, WWCC expiry warnings, admin accounts with 2FA
This commit is contained in:
@@ -0,0 +1,37 @@
|
||||
#!/bin/sh
|
||||
# A bind-mounted ./data is created on the host as root, and the chown in the
|
||||
# Dockerfile only applies to the image layer that the mount then hides. So fix
|
||||
# ownership here, at runtime, before dropping to the unprivileged user.
|
||||
set -e
|
||||
|
||||
DATA_DIR="${DATA_DIR:-/data}"
|
||||
|
||||
if [ "$(id -u)" = "0" ]; then
|
||||
mkdir -p "$DATA_DIR/photos" "$DATA_DIR/certs"
|
||||
|
||||
# Only touch ownership when it is actually wrong, so a large photo archive
|
||||
# is not walked on every restart.
|
||||
if [ "$(stat -c %u "$DATA_DIR")" != "$(id -u node)" ]; then
|
||||
echo "[entrypoint] taking ownership of $DATA_DIR for the node user"
|
||||
chown -R node:node "$DATA_DIR"
|
||||
fi
|
||||
|
||||
if command -v setpriv >/dev/null 2>&1; then
|
||||
exec setpriv --reuid=node --regid=node --init-groups "$@"
|
||||
elif command -v runuser >/dev/null 2>&1; then
|
||||
exec runuser -u node -- "$@"
|
||||
else
|
||||
echo "[entrypoint] no setpriv or runuser available, staying as root" >&2
|
||||
exec "$@"
|
||||
fi
|
||||
fi
|
||||
|
||||
# Already running as a non-root user, because compose set `user:`. Nothing to fix
|
||||
# here: if the mount is not writable the app will say so plainly on start.
|
||||
if [ ! -w "$DATA_DIR" ]; then
|
||||
echo "[entrypoint] $DATA_DIR is not writable by $(id -un) (uid $(id -u))." >&2
|
||||
echo "[entrypoint] On the docker host run: sudo chown -R $(id -u):$(id -g) ./data" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
exec "$@"
|
||||
Reference in New Issue
Block a user