Run the container as root so a bind-mounted /data works

The compose file mounts ./data over /data. A host directory created by
compose is not writable for a separate user in the image, so the
server could not open its database on the first start.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
AuthorKonata <konata@posteo.jp>
Date
Commit3b132ab96fe28e27441421353295cd27e0c81f1c
Parentbf96932
1 file changed, 1 insertion(+), 2 deletions(-)
▾MContainerfile
@@ -21,11 +21,10 @@ FROM ${BIN_STAGE} AS bin
FROM docker.io/library/debian:trixie-slim
# webauthn-rs links OpenSSL.
RUN apt-get update && apt-get install -y --no-install-recommends libssl3t64 && rm -rf /var/lib/apt/lists/* \
&& useradd --system --uid 10001 ot && mkdir /data && chown ot /data
&& mkdir /data
COPY --from=bin /src/target/release/otserver /usr/local/bin/
COPY --from=bin /src/web/dist /srv/web
ENV OT_ADDR=0.0.0.0:8080 OT_DB=/data/ot.db OT_WEB_DIR=/srv/web
USER ot
VOLUME /data
EXPOSE 8080
ENTRYPOINT ["otserver"]