Conversation
|
@rgaudin This is an attempt to make our Docker a bit more secure. But this has for direct consequence that the mounted volumed should be writeable by the new user |
|
This pull request has been automatically marked as stale because it has not had recent activity. It will be now be reviewed manually. Thank you for your contributions. |
Codecov Report
@@ Coverage Diff @@
## master #1321 +/- ##
=======================================
Coverage 69.42% 69.42%
=======================================
Files 26 26
Lines 2401 2401
Branches 469 469
=======================================
Hits 1667 1667
Misses 569 569
Partials 165 165 Continue to review full report at Codecov.
|
rgaudin
left a comment
There was a problem hiding this comment.
- most rootless images defaults to user
1001as this is what a regular distro would create so it has more chances to work out of the box. - rootless implies choosing a user so uid and gid might be anything
/datais gonna be mounted and there's no guarantee you'll be able to write on it. You may want to check that in entrypoint to provide a quick and clear feedback should permissions not be adequate. I don't know how quick and clear mwoffliner is gonna fail in this case.- README may need to be updated to inform about write requirements on mounted volume source.
|
This pull request has been automatically marked as stale because it has not had recent activity. It will be now be reviewed manually. Thank you for your contributions. |
Fixes #995