Merge pull request #6500 from dokku/3454-chown-add
Add support for custom user namespaces when creating persistent storage directories
This commit is contained in:
@@ -76,6 +76,8 @@ By default, permissions are set for usage with Herokuish buildpacks. These permi
|
||||
- This is used for apps deployed with Cloud Native Buildpacks using the `heroku/builder` builder.
|
||||
- `--chown packeto`: Use `2000:2000` as the folder permissions.
|
||||
- This is used for apps deployed with Cloud Native Buildpacks using the `cloudfoundry/cnb` or `packeto` builders.
|
||||
- `--chown root`: Use `0:0` as the folder permissions.
|
||||
- This is used for containers that run their processes as root, as is typical for most Dockerfile or Docker image deploys.
|
||||
- `--chown false`: Skips the `chown` call.
|
||||
|
||||
Users deploying via Dockerfile will want to specify `--chown false` and manually `chown` the created directory if the user and/or group id of the runnning process in the deployed container do not correspond to any of the above options.
|
||||
|
||||
@@ -44,12 +44,19 @@ cmd-storage-ensure-directory() {
|
||||
CHOWN_FLAG="1000"
|
||||
elif [[ "$CHOWN_FLAG" == "packeto" ]]; then
|
||||
CHOWN_FLAG="2000"
|
||||
elif [[ "$CHOWN_FLAG" == "root" ]]; then
|
||||
CHOWN_FLAG="0"
|
||||
elif [[ "$CHOWN_FLAG" == "false" ]]; then
|
||||
CHOWN_FLAG="false"
|
||||
else
|
||||
dokku_log_fail "Unsupported chown permissions"
|
||||
fi
|
||||
|
||||
userns_enabled="$(docker info -f '{{range .SecurityOptions}}{{if eq . "name=userns"}}true{{end}}{{end}}')"
|
||||
if [[ "$userns_enabled" == "true" ]] && [[ "$CHOWN_FLAG" != "false" ]]; then
|
||||
CHOWN_FLAG=$((CHOWN_FLAG + 165536))
|
||||
fi
|
||||
|
||||
local storage_directory="${DOKKU_LIB_ROOT}/data/storage/$DIRECTORY"
|
||||
dokku_log_info1 "Ensuring ${storage_directory} exists"
|
||||
mkdir -p "${storage_directory}"
|
||||
|
||||
Reference in New Issue
Block a user