mirror of
https://github.com/rustmailer/bichon.git
synced 2026-08-03 07:48:34 +02:00
fix: switch from PUID/PGID env vars to Docker --user for permissions
This commit is contained in:
@@ -122,36 +122,64 @@ docker pull rustmailer/bichon:latest
|
|||||||
# Create data directory
|
# Create data directory
|
||||||
mkdir -p ./bichon-data
|
mkdir -p ./bichon-data
|
||||||
|
|
||||||
# Optional: Set PUID and PGID to match your host user for proper file permissions
|
|
||||||
# Find your user ID with: id $USER
|
|
||||||
# This prevents permission issues when using NFS mounts or shared volumes
|
|
||||||
|
|
||||||
# Run container
|
# Run container
|
||||||
docker run -d \
|
docker run -d \
|
||||||
--name bichon \
|
--name bichon \
|
||||||
-p 15630:15630 \
|
-p 15630:15630 \
|
||||||
-v $(pwd)/bichon-data:/data \
|
-v $(pwd)/bichon-data:/data \
|
||||||
-e PUID=1000 \
|
--user 1000:1000 \
|
||||||
-e PGID=1000 \
|
|
||||||
-e BICHON_LOG_LEVEL=info \
|
-e BICHON_LOG_LEVEL=info \
|
||||||
-e BICHON_ROOT_DIR=/data \
|
-e BICHON_ROOT_DIR=/data \
|
||||||
rustmailer/bichon:latest
|
rustmailer/bichon:latest
|
||||||
|
```
|
||||||
|
|
||||||
# Optional: For custom storage configuration with separate volumes
|
### Optional: Custom storage layout
|
||||||
|
|
||||||
|
```bash
|
||||||
docker run -d \
|
docker run -d \
|
||||||
--name bichon \
|
--name bichon \
|
||||||
-p 15630:15630 \
|
-p 15630:15630 \
|
||||||
-v $(pwd)/bichon-data:/data \
|
-v $(pwd)/bichon-data:/data \
|
||||||
-v $(pwd)/envelope:/envelope \
|
-v $(pwd)/envelope:/envelope \
|
||||||
-v $(pwd)/eml:/eml \
|
-v $(pwd)/eml:/eml \
|
||||||
-e PUID=1000 \
|
--user 1000:1000 \
|
||||||
-e PGID=1000 \
|
|
||||||
-e BICHON_ROOT_DIR=/data \
|
-e BICHON_ROOT_DIR=/data \
|
||||||
-e BICHON_INDEX_DIR=/envelope \
|
-e BICHON_INDEX_DIR=/envelope \
|
||||||
-e BICHON_DATA_DIR=/eml \
|
-e BICHON_DATA_DIR=/eml \
|
||||||
rustmailer/bichon:latest
|
rustmailer/bichon:latest
|
||||||
```
|
```
|
||||||
|
|
||||||
|
### Recommended docker-compose example
|
||||||
|
|
||||||
|
```bash
|
||||||
|
services:
|
||||||
|
bichon:
|
||||||
|
image: rustmailer/bichon:latest
|
||||||
|
container_name: bichon
|
||||||
|
ports:
|
||||||
|
- "15630:15630"
|
||||||
|
volumes:
|
||||||
|
- ./bichon-data:/data
|
||||||
|
user: "1000:1000"
|
||||||
|
environment:
|
||||||
|
BICHON_ROOT_DIR: /data
|
||||||
|
BICHON_LOG_LEVEL: info
|
||||||
|
|
||||||
|
```
|
||||||
|
|
||||||
|
### User and permissions
|
||||||
|
|
||||||
|
`PUID` and `PGID` are no longer used to create users or groups inside the container.
|
||||||
|
|
||||||
|
Please use Docker’s native `--user` option (or `user:` in docker-compose) to specify the UID and GID:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
docker run --user 1000:1000 ...
|
||||||
|
```
|
||||||
|
|
||||||
|
This ensures container file permissions match the ownership of host-mounted directories.
|
||||||
|
|
||||||
|
|
||||||
## CORS Configuration (Important for Browser Access)
|
## CORS Configuration (Important for Browser Access)
|
||||||
|
|
||||||
Starting from **v0.1.4**, Bichon changes how `BICHON_CORS_ORIGINS` works:
|
Starting from **v0.1.4**, Bichon changes how `BICHON_CORS_ORIGINS` works:
|
||||||
|
|||||||
@@ -25,9 +25,6 @@ RUN chmod +x /opt/bichon/bichon
|
|||||||
RUN chmod +x /usr/local/bin/bichonctl
|
RUN chmod +x /usr/local/bin/bichonctl
|
||||||
RUN chmod +x /usr/local/bin/bichon-admin
|
RUN chmod +x /usr/local/bin/bichon-admin
|
||||||
|
|
||||||
# Copy and setup entrypoint script for PUID/PGID support
|
|
||||||
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
|
|
||||||
RUN chmod +x /usr/local/bin/entrypoint.sh
|
|
||||||
|
|
||||||
# Install ca-certificates to ensure HTTPS certificate verification works correctly
|
# Install ca-certificates to ensure HTTPS certificate verification works correctly
|
||||||
RUN apt update && apt install -y ca-certificates curl && rm -rf /var/lib/apt/lists/*
|
RUN apt update && apt install -y ca-certificates curl && rm -rf /var/lib/apt/lists/*
|
||||||
@@ -43,6 +40,4 @@ WORKDIR /data
|
|||||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=5s --retries=3 \
|
HEALTHCHECK --interval=30s --timeout=5s --start-period=5s --retries=3 \
|
||||||
CMD curl -fs http://localhost:15630/api/status || exit 1
|
CMD curl -fs http://localhost:15630/api/status || exit 1
|
||||||
|
|
||||||
# Entrypoint with PUID/PGID support
|
|
||||||
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
|
|
||||||
CMD ["/opt/bichon/bichon"]
|
CMD ["/opt/bichon/bichon"]
|
||||||
|
|||||||
@@ -1,54 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# Entrypoint script for Bichon Docker container
|
|
||||||
# Handles PUID/PGID environment variables for proper user permissions
|
|
||||||
|
|
||||||
set -e
|
|
||||||
|
|
||||||
# If not running as root, do nothing
|
|
||||||
if [ "$(id -u)" != "0" ]; then
|
|
||||||
echo "Running as non-root user ($(id -u)), skipping PUID/PGID handling"
|
|
||||||
exec "$@"
|
|
||||||
fi
|
|
||||||
|
|
||||||
|
|
||||||
# Function to create user and switch to it
|
|
||||||
switch_user() {
|
|
||||||
local puid="$1"
|
|
||||||
local pgid="$2"
|
|
||||||
local USER_NAME
|
|
||||||
local GROUP_NAME
|
|
||||||
|
|
||||||
# group
|
|
||||||
if getent group "$pgid" >/dev/null 2>&1; then
|
|
||||||
GROUP_NAME=$(getent group "$pgid" | cut -d: -f1)
|
|
||||||
else
|
|
||||||
groupadd -g "$pgid" bichon
|
|
||||||
GROUP_NAME=bichon
|
|
||||||
fi
|
|
||||||
|
|
||||||
# user
|
|
||||||
if getent passwd "$puid" >/dev/null 2>&1; then
|
|
||||||
USER_NAME=$(getent passwd "$puid" | cut -d: -f1)
|
|
||||||
else
|
|
||||||
useradd -u "$puid" -g "$GROUP_NAME" -s /bin/bash -d /data bichon
|
|
||||||
USER_NAME=bichon
|
|
||||||
fi
|
|
||||||
|
|
||||||
chown -R "$puid:$pgid" /data
|
|
||||||
chown -R "$puid:$pgid" /opt/bichon
|
|
||||||
[ -d /envelope ] && chown -R "$puid:$pgid" /envelope
|
|
||||||
[ -d /eml ] && chown -R "$puid:$pgid" /eml
|
|
||||||
|
|
||||||
exec runuser -u "$USER_NAME" -- "$@"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
# Check if PUID and PGID are set
|
|
||||||
if [ -n "$PUID" ] && [ -n "$PGID" ]; then
|
|
||||||
echo "Switching to user with PUID=$PUID, PGID=$PGID"
|
|
||||||
switch_user "$PUID" "$PGID" "$@"
|
|
||||||
else
|
|
||||||
echo "No PUID/PGID specified, running as root"
|
|
||||||
exec "$@"
|
|
||||||
fi
|
|
||||||
Reference in New Issue
Block a user