From 7605ca9918cda334bf1a5a2d555e8f3a19d8af42 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cau=C3=AA=20Faleiros?= Date: Fri, 18 Sep 2026 12:02:31 -0300 Subject: [PATCH] fix: start web services in Portainer Swarm --- deploy/Dockerfile.web | 5 +++++ docker-compose.yml | 12 ------------ 2 files changed, 5 insertions(+), 12 deletions(-) diff --git a/deploy/Dockerfile.web b/deploy/Dockerfile.web index 616b502..bb1b425 100644 --- a/deploy/Dockerfile.web +++ b/deploy/Dockerfile.web @@ -18,5 +18,10 @@ ENV WEB_INDEX=index.html PUBLIC_HOST=invalid.example S3_PUBLIC_ENDPOINT=https:// COPY --from=policy /build/default.conf.template /etc/nginx/templates/default.conf.template COPY dtf-site.html /usr/share/nginx/html/index.html COPY local/static/ /usr/share/nginx/html/ +# The official entrypoint renders the server configuration at startup and Nginx +# writes its PID/cache files. Keep the service non-root while granting it +# ownership of only those runtime locations. This works in Docker Swarm, +# where the previous read-only/tmpfs combination was not mounted as expected. +RUN chown -R 101:101 /etc/nginx/conf.d /var/cache/nginx /run USER 101:101 EXPOSE 8080 diff --git a/docker-compose.yml b/docker-compose.yml index 591fa2e..06f74b4 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -124,12 +124,6 @@ services: published: ${SITE_PORT:-18080} protocol: tcp mode: ingress - read_only: true - tmpfs: - - /tmp:uid=101,gid=101,mode=0750 - - /var/cache/nginx:uid=101,gid=101,mode=0750 - - /var/run:uid=101,gid=101,mode=0750 - - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 healthcheck: test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] interval: 15s @@ -152,12 +146,6 @@ services: published: ${KANBAN_PORT:-18081} protocol: tcp mode: ingress - read_only: true - tmpfs: - - /tmp:uid=101,gid=101,mode=0750 - - /var/cache/nginx:uid=101,gid=101,mode=0750 - - /var/run:uid=101,gid=101,mode=0750 - - /etc/nginx/conf.d:uid=101,gid=101,mode=0750 healthcheck: test: [CMD-SHELL, 'wget -q --header="Host: $$PUBLIC_HOST" -O /dev/null http://127.0.0.1:8080/health'] interval: 15s