Merge pull request #6500 from dokku/3454-chown-add

Add support for custom user namespaces when creating persistent storage directories
This commit is contained in:
Jose Diaz-Gonzalez
2024-01-23 02:50:39 -05:00
committed by GitHub
2 changed files with 9 additions and 0 deletions

View File

@@ -76,6 +76,8 @@ By default, permissions are set for usage with Herokuish buildpacks. These permi
- This is used for apps deployed with Cloud Native Buildpacks using the `heroku/builder` builder.
- `--chown packeto`: Use `2000:2000` as the folder permissions.
- This is used for apps deployed with Cloud Native Buildpacks using the `cloudfoundry/cnb` or `packeto` builders.
- `--chown root`: Use `0:0` as the folder permissions.
- This is used for containers that run their processes as root, as is typical for most Dockerfile or Docker image deploys.
- `--chown false`: Skips the `chown` call.
Users deploying via Dockerfile will want to specify `--chown false` and manually `chown` the created directory if the user and/or group id of the runnning process in the deployed container do not correspond to any of the above options.

View File

@@ -44,12 +44,19 @@ cmd-storage-ensure-directory() {
CHOWN_FLAG="1000"
elif [[ "$CHOWN_FLAG" == "packeto" ]]; then
CHOWN_FLAG="2000"
elif [[ "$CHOWN_FLAG" == "root" ]]; then
CHOWN_FLAG="0"
elif [[ "$CHOWN_FLAG" == "false" ]]; then
CHOWN_FLAG="false"
else
dokku_log_fail "Unsupported chown permissions"
fi
userns_enabled="$(docker info -f '{{range .SecurityOptions}}{{if eq . "name=userns"}}true{{end}}{{end}}')"
if [[ "$userns_enabled" == "true" ]] && [[ "$CHOWN_FLAG" != "false" ]]; then
CHOWN_FLAG=$((CHOWN_FLAG + 165536))
fi
local storage_directory="${DOKKU_LIB_ROOT}/data/storage/$DIRECTORY"
dokku_log_info1 "Ensuring ${storage_directory} exists"
mkdir -p "${storage_directory}"