Use regular user for executing service
Praise modular copy-pasteable designs
This commit is contained in:
parent
3194998503
commit
fe6d3a7f7c
19
Dockerfile
19
Dockerfile
|
@ -1,11 +1,22 @@
|
||||||
FROM golang:1.22-alpine
|
FROM golang:1.22-alpine
|
||||||
|
|
||||||
RUN mkdir /app
|
ENV USER=tiamat
|
||||||
|
ENV GROUPNAME=$USER
|
||||||
|
ENV UID=1000
|
||||||
|
ENV GID=1000
|
||||||
|
ENV APP_HOME="/home/tiamat/app"
|
||||||
|
|
||||||
ADD . /app
|
RUN addgroup --gid "$GID" "$GROUPNAME"
|
||||||
|
RUN adduser --gecos "" --disabled-password --ingroup "$GROUPNAME" --uid "$UID" "$USER"
|
||||||
|
|
||||||
WORKDIR /app
|
USER "$USER"
|
||||||
|
|
||||||
|
RUN mkdir "$APP_HOME"
|
||||||
|
|
||||||
|
ADD . "$APP_HOME"
|
||||||
|
|
||||||
|
WORKDIR "$APP_HOME"
|
||||||
|
|
||||||
RUN go build -o main .
|
RUN go build -o main .
|
||||||
|
|
||||||
CMD ["/app/main", "server"]
|
CMD ["./main", "server"]
|
||||||
|
|
|
@ -5,9 +5,8 @@ networks:
|
||||||
driver: bridge
|
driver: bridge
|
||||||
|
|
||||||
services:
|
services:
|
||||||
tiamat:
|
default:
|
||||||
container_name: "tiamat"
|
container_name: "tiamat"
|
||||||
#image: "tiamat"
|
|
||||||
build:
|
build:
|
||||||
context: .
|
context: .
|
||||||
dockerfile: "Dockerfile"
|
dockerfile: "Dockerfile"
|
||||||
|
@ -17,4 +16,4 @@ services:
|
||||||
networks:
|
networks:
|
||||||
- tiamat
|
- tiamat
|
||||||
volumes:
|
volumes:
|
||||||
- ./sample-config/:/root/.config/tiamat/
|
- ./sample-config/:/home/tiamat/.config/tiamat/
|
||||||
|
|
Loading…
Reference in New Issue