fix: switch from PUID/PGID env vars to Docker --user for permissions

This commit is contained in:
rustmailer
2026-01-28 13:15:06 +08:00
parent 1fde24b3db
commit 01dba4f71b
3 changed files with 37 additions and 68 deletions
+37 -9
View File
@@ -122,36 +122,64 @@ docker pull rustmailer/bichon:latest
# Create data directory
mkdir -p ./bichon-data
# Optional: Set PUID and PGID to match your host user for proper file permissions
# Find your user ID with: id $USER
# This prevents permission issues when using NFS mounts or shared volumes
# Run container
docker run -d \
--name bichon \
-p 15630:15630 \
-v $(pwd)/bichon-data:/data \
-e PUID=1000 \
-e PGID=1000 \
--user 1000:1000 \
-e BICHON_LOG_LEVEL=info \
-e BICHON_ROOT_DIR=/data \
rustmailer/bichon:latest
```
# Optional: For custom storage configuration with separate volumes
### Optional: Custom storage layout
```bash
docker run -d \
--name bichon \
-p 15630:15630 \
-v $(pwd)/bichon-data:/data \
-v $(pwd)/envelope:/envelope \
-v $(pwd)/eml:/eml \
-e PUID=1000 \
-e PGID=1000 \
--user 1000:1000 \
-e BICHON_ROOT_DIR=/data \
-e BICHON_INDEX_DIR=/envelope \
-e BICHON_DATA_DIR=/eml \
rustmailer/bichon:latest
```
### Recommended docker-compose example
```bash
services:
bichon:
image: rustmailer/bichon:latest
container_name: bichon
ports:
- "15630:15630"
volumes:
- ./bichon-data:/data
user: "1000:1000"
environment:
BICHON_ROOT_DIR: /data
BICHON_LOG_LEVEL: info
```
### User and permissions
`PUID` and `PGID` are no longer used to create users or groups inside the container.
Please use Dockers native `--user` option (or `user:` in docker-compose) to specify the UID and GID:
```bash
docker run --user 1000:1000 ...
```
This ensures container file permissions match the ownership of host-mounted directories.
## CORS Configuration (Important for Browser Access)
Starting from **v0.1.4**, Bichon changes how `BICHON_CORS_ORIGINS` works:
-5
View File
@@ -25,9 +25,6 @@ RUN chmod +x /opt/bichon/bichon
RUN chmod +x /usr/local/bin/bichonctl
RUN chmod +x /usr/local/bin/bichon-admin
# Copy and setup entrypoint script for PUID/PGID support
COPY entrypoint.sh /usr/local/bin/entrypoint.sh
RUN chmod +x /usr/local/bin/entrypoint.sh
# Install ca-certificates to ensure HTTPS certificate verification works correctly
RUN apt update && apt install -y ca-certificates curl && rm -rf /var/lib/apt/lists/*
@@ -43,6 +40,4 @@ WORKDIR /data
HEALTHCHECK --interval=30s --timeout=5s --start-period=5s --retries=3 \
CMD curl -fs http://localhost:15630/api/status || exit 1
# Entrypoint with PUID/PGID support
ENTRYPOINT ["/usr/local/bin/entrypoint.sh"]
CMD ["/opt/bichon/bichon"]
-54
View File
@@ -1,54 +0,0 @@
#!/bin/bash
# Entrypoint script for Bichon Docker container
# Handles PUID/PGID environment variables for proper user permissions
set -e
# If not running as root, do nothing
if [ "$(id -u)" != "0" ]; then
echo "Running as non-root user ($(id -u)), skipping PUID/PGID handling"
exec "$@"
fi
# Function to create user and switch to it
switch_user() {
local puid="$1"
local pgid="$2"
local USER_NAME
local GROUP_NAME
# group
if getent group "$pgid" >/dev/null 2>&1; then
GROUP_NAME=$(getent group "$pgid" | cut -d: -f1)
else
groupadd -g "$pgid" bichon
GROUP_NAME=bichon
fi
# user
if getent passwd "$puid" >/dev/null 2>&1; then
USER_NAME=$(getent passwd "$puid" | cut -d: -f1)
else
useradd -u "$puid" -g "$GROUP_NAME" -s /bin/bash -d /data bichon
USER_NAME=bichon
fi
chown -R "$puid:$pgid" /data
chown -R "$puid:$pgid" /opt/bichon
[ -d /envelope ] && chown -R "$puid:$pgid" /envelope
[ -d /eml ] && chown -R "$puid:$pgid" /eml
exec runuser -u "$USER_NAME" -- "$@"
}
# Check if PUID and PGID are set
if [ -n "$PUID" ] && [ -n "$PGID" ]; then
echo "Switching to user with PUID=$PUID, PGID=$PGID"
switch_user "$PUID" "$PGID" "$@"
else
echo "No PUID/PGID specified, running as root"
exec "$@"
fi