Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix tmp folder permissions on helm #18014

Draft
wants to merge 1 commit into
base: release/15.3
Choose a base branch
from
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 9 additions & 0 deletions docker/prod/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,15 @@ RUN cp Gemfile.lock.bak Gemfile.lock && rm Gemfile.lock.bak && \
# -------------------------------------
FROM base AS slim

# install sudo so we can run the following single command as root on start-up
# (see entrypoint-slim.sh)
RUN apt-get update -qq && \
apt-get install -yq --no-install-recommends sudo && \
apt-get clean && \
rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* && \
truncate -s 0 /var/log/*log
RUN echo "$APP_USER ALL=(ALL) NOPASSWD:$APP_PATH/docker/prod/fix-tmp-permissions" > /etc/sudoers

USER $APP_USER
EXPOSE 8080
CMD ["./docker/prod/web"]
Expand Down
4 changes: 4 additions & 0 deletions docker/prod/entrypoint-slim.sh
Original file line number Diff line number Diff line change
Expand Up @@ -8,4 +8,8 @@ if [ "$USE_JEMALLOC" = "true" ]; then
export LD_PRELOAD=libjemalloc.so.2
fi

# make sure tmp folders have the correct owners and permissions
# so that Ruby can create temporary files
sudo docker/prod/fix-tmp-permissions

exec "$@"
10 changes: 10 additions & 0 deletions docker/prod/fix-tmp-permissions
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
#!/bin/bash -e
# needs to be executed as root

APP_TMP_DIR=/app/tmp
TMP_DIR=/tmp

chmod 775 $APP_TMP_DIR
chown app:app $APP_TMP_DIR

chmod 1777 $TMP_DIR
Loading