Merge pull request #3641 from wkloucek/docker_narrow_volume_permissions

reduce docker image volume permissions and update alpine
This commit is contained in:
Willy Kloucek
2022-05-03 18:09:36 +02:00
committed by GitHub
4 changed files with 18 additions and 9 deletions

View File

@@ -0,0 +1,9 @@
Change: Reduce permissions on docker image predeclared volumes
We've lowered the permissions on the predeclared volumes of the oCIS
docker image from 777 to 750.
This change doesn't affect you, unless you use the docker image with
the non default uid/guid to start oCIS (default is 1000:1000).
https://github.com/owncloud/ocis/pull/3641

View File

@@ -1,4 +1,4 @@
FROM amd64/alpine:3.14
FROM amd64/alpine:3.15
ARG VERSION=""
ARG REVISION=""
@@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \
RUN mkdir -p /var/lib/ocis && \
chown -R ocis-user:ocis-group /var/lib/ocis && \
chmod -R 777 /var/lib/ocis && \
chmod -R 750 /var/lib/ocis && \
mkdir -p /etc/ocis && \
chown -R ocis-user:ocis-group /etc/ocis && \
chmod -R 777 /etc/ocis
chmod -R 750 /etc/ocis
VOLUME [ "/var/lib/ocis", "/etc/ocis" ]
WORKDIR /var/lib/ocis

View File

@@ -1,4 +1,4 @@
FROM arm32v6/alpine:3.14
FROM arm32v6/alpine:3.15
ARG VERSION=""
ARG REVISION=""
@@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \
RUN mkdir -p /var/lib/ocis && \
chown -R ocis-user:ocis-group /var/lib/ocis && \
chmod -R 777 /var/lib/ocis && \
chmod -R 750 /var/lib/ocis && \
mkdir -p /etc/ocis && \
chown -R ocis-user:ocis-group /etc/ocis && \
chmod -R 777 /etc/ocis
chmod -R 750 /etc/ocis
VOLUME [ "/var/lib/ocis", "/etc/ocis" ]
WORKDIR /var/lib/ocis

View File

@@ -1,4 +1,4 @@
FROM arm64v8/alpine:3.14
FROM arm64v8/alpine:3.15
ARG VERSION=""
ARG REVISION=""
@@ -26,10 +26,10 @@ RUN addgroup -g 1000 -S ocis-group && \
RUN mkdir -p /var/lib/ocis && \
chown -R ocis-user:ocis-group /var/lib/ocis && \
chmod -R 777 /var/lib/ocis && \
chmod -R 750 /var/lib/ocis && \
mkdir -p /etc/ocis && \
chown -R ocis-user:ocis-group /etc/ocis && \
chmod -R 777 /etc/ocis
chmod -R 750 /etc/ocis
VOLUME [ "/var/lib/ocis", "/etc/ocis" ]
WORKDIR /var/lib/ocis