diff --git a/changelog/unreleased/change-ocis-docker-volume-permissions.md b/changelog/unreleased/change-ocis-docker-volume-permissions.md index 582bd5e456..7069b14ae1 100644 --- a/changelog/unreleased/change-ocis-docker-volume-permissions.md +++ b/changelog/unreleased/change-ocis-docker-volume-permissions.md @@ -1,7 +1,7 @@ Change: Reduce permissions on docker image predeclared volumes We've lowered the permissions on the predeclared volumes of the oCIS -docker image from 777 to 700. +docker image from 777 to 750. This change doesn't affect you, unless you use the docker image with the non default uid/guid to start oCIS (default is 1000:1000). diff --git a/ocis/docker/Dockerfile.linux.amd64 b/ocis/docker/Dockerfile.linux.amd64 index be3416b926..f2ac0931e2 100644 --- a/ocis/docker/Dockerfile.linux.amd64 +++ b/ocis/docker/Dockerfile.linux.amd64 @@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \ RUN mkdir -p /var/lib/ocis && \ chown -R ocis-user:ocis-group /var/lib/ocis && \ - chmod -R 700 /var/lib/ocis && \ + chmod -R 750 /var/lib/ocis && \ mkdir -p /etc/ocis && \ chown -R ocis-user:ocis-group /etc/ocis && \ - chmod -R 700 /etc/ocis + chmod -R 750 /etc/ocis VOLUME [ "/var/lib/ocis", "/etc/ocis" ] WORKDIR /var/lib/ocis diff --git a/ocis/docker/Dockerfile.linux.arm b/ocis/docker/Dockerfile.linux.arm index 34e18bdf9f..b9b2d67862 100644 --- a/ocis/docker/Dockerfile.linux.arm +++ b/ocis/docker/Dockerfile.linux.arm @@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \ RUN mkdir -p /var/lib/ocis && \ chown -R ocis-user:ocis-group /var/lib/ocis && \ - chmod -R 700 /var/lib/ocis && \ + chmod -R 750 /var/lib/ocis && \ mkdir -p /etc/ocis && \ chown -R ocis-user:ocis-group /etc/ocis && \ - chmod -R 700 /etc/ocis + chmod -R 750 /etc/ocis VOLUME [ "/var/lib/ocis", "/etc/ocis" ] WORKDIR /var/lib/ocis diff --git a/ocis/docker/Dockerfile.linux.arm64 b/ocis/docker/Dockerfile.linux.arm64 index 324696eb4a..6c8b159546 100644 --- a/ocis/docker/Dockerfile.linux.arm64 +++ b/ocis/docker/Dockerfile.linux.arm64 @@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \ RUN mkdir -p /var/lib/ocis && \ chown -R ocis-user:ocis-group /var/lib/ocis && \ - chmod -R 700 /var/lib/ocis && \ + chmod -R 750 /var/lib/ocis && \ mkdir -p /etc/ocis && \ chown -R ocis-user:ocis-group /etc/ocis && \ - chmod -R 700 /etc/ocis + chmod -R 750 /etc/ocis VOLUME [ "/var/lib/ocis", "/etc/ocis" ] WORKDIR /var/lib/ocis