diff --git a/deploy/Dockerfile.web b/deploy/Dockerfile.web index 616b502..bb1b425 100644 --- a/deploy/Dockerfile.web +++ b/deploy/Dockerfile.web @@ -18,5 +18,10 @@ ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https:// COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template COPY dtf-site.html /usr/share/nginx/html/index.html COPY local/static/ /usr/share/nginx/html/ +# The official entrypoint renders the server configuration at startup and Nginx +# writes its PID/cache files. Keep the service non-root while granting it +# ownership of only those runtime locations. This works in Docker Swarm, +# where the previous read-only/tmpfs combination was not mounted as expected. +RUN chown -R 101:101 /etc/nginx/conf.d /var/cache/nginx /run USER 101:101 EXPOSE 8080 diff --git a/docker-compose.yml b/docker-compose.yml index 591fa2e..06f74b4 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -124,12 +124,6 @@ services: published: ${SITE_PORT:-18080} protocol: tcp mode: ingress - read_only: true - tmpfs: - - /tmp:uid=101,gid=101,mode=0750 - - /var/cache/nginx:uid=101,gid=101,mode=0750 - - /var/run:uid=101,gid=101,mode=0750 - - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 healthcheck: test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] interval: 15s @@ -152,12 +146,6 @@ services: published: ${KANBAN_PORT:-18081} protocol: tcp mode: ingress - read_only: true - tmpfs: - - /tmp:uid=101,gid=101,mode=0750 - - /var/cache/nginx:uid=101,gid=101,mode=0750 - - /var/run:uid=101,gid=101,mode=0750 - - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 healthcheck: test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] interval: 15s