Fix bind-mount data dir permissions via entrypoint

Docker creates ./data root-owned on the host, but the app runs as the unprivileged node user, causing SQLITE_CANTOPEN on first deploy. New entrypoint starts as root, chowns DATA_DIR, then drops privileges with setpriv. Compose keeps the SQLite database in ./data next to the compose file. Also trims scripts/ and playwright artifacts from the image.
This commit is contained in:
2026-07-18 23:54:50 +07:00
parent fe89bb2b1c
commit 1d86c68665
5 changed files with 32 additions and 4 deletions
+5 -1
View File
@@ -20,7 +20,11 @@ COPY public/ ./public/
# Owned by the unprivileged `node` user that ships with the base image.
RUN mkdir -p /app/data && chown -R node:node /app
USER node
# The entrypoint starts as root only to chown a bind-mounted DATA_DIR
# (Docker creates host dirs root-owned), then drops to `node` via setpriv.
COPY docker-entrypoint.sh /usr/local/bin/docker-entrypoint.sh
RUN chmod +x /usr/local/bin/docker-entrypoint.sh
ENTRYPOINT ["docker-entrypoint.sh"]
EXPOSE 3000