diff --git a/cron/Dockerfile b/cron/Dockerfile index 26c46a6f68f..0f023e539ab 100644 --- a/cron/Dockerfile +++ b/cron/Dockerfile @@ -5,7 +5,7 @@ RUN if [ -n "${HTTP_PROXY}" ]; then echo "Acquire::http::proxy \"${HTTP_PROXY}\" RUN if [ -n "${HTTPS_PROXY}" ]; then echo "Acquire::https::proxy \"${HTTPS_PROXY}\";" >> /etc/apt/apt.conf; fi RUN if [ -n "${http_proxy}" ]; then echo "Acquire::http::proxy \"${http_proxy}\";" >> /etc/apt/apt.conf; fi RUN if [ -n "${https_proxy}" ]; then echo "Acquire::https::proxy \"${https_proxy}\";" >> /etc/apt/apt.conf; fi -RUN apt-get update && apt-get install -y --no-install-recommends cron && \ +RUN apt-get update && apt-get install -y --no-install-recommends cron gosu && \ rm -r /var/lib/apt/lists/* COPY entrypoint.sh /entrypoint.sh ENTRYPOINT ["/entrypoint.sh"] diff --git a/install.sh b/install.sh index 9bbe33f10b0..c0ead4943b6 100755 --- a/install.sh +++ b/install.sh @@ -37,6 +37,7 @@ source install/check-memcached-backend.sh source install/ensure-relay-credentials.sh source install/generate-secret-key.sh source install/build-docker-images.sh +source install/ensure-sentry-data-ownership.sh source install/migrate-seaweedfs-kek.sh source install/upgrade-postgres.sh source install/bootstrap-s3-nodestore.sh diff --git a/install/ensure-sentry-data-ownership.sh b/install/ensure-sentry-data-ownership.sh new file mode 100644 index 00000000000..7c7c6a45bf1 --- /dev/null +++ b/install/ensure-sentry-data-ownership.sh @@ -0,0 +1,25 @@ +echo "${_group}Ensuring sentry-data volume ownership ..." + +# Sentry containers run as the non-root `sentry` user (uid 999). Older sentry +# images fixed /data ownership at every container start while running as root; +# do it once here instead. This uses python3 rather than shell tools so it keeps +# working on images without a shell. +$dcr --no-deps --user 0 --entrypoint python3 web -c ' +import os + +SENTRY_UID = 999 + + +def fail(error): + raise error + + +os.makedirs("/data/files", exist_ok=True) +if any(os.stat(p).st_uid != SENTRY_UID for p in ("/data", "/data/files")): + for root, dirs, files in os.walk("/data", topdown=False, onerror=fail): + for path in (*(os.path.join(root, name) for name in dirs + files), root): + if os.lstat(path).st_uid != SENTRY_UID: + os.lchown(path, SENTRY_UID, -1) +' + +echo "${_endgroup}" diff --git a/sentry/Dockerfile b/sentry/Dockerfile index 62a490e4de4..f4b56b19200 100644 --- a/sentry/Dockerfile +++ b/sentry/Dockerfile @@ -1,6 +1,10 @@ ARG SENTRY_IMAGE FROM ${SENTRY_IMAGE} +# Customizations below need root. Newer sentry images default to the non-root +# `sentry` user, so switch explicitly and switch back at the end. +USER 0 + RUN pip install https://github.com/getsentry/sentry-nodestore-s3/archive/main.zip COPY . /usr/src/sentry @@ -13,3 +17,10 @@ RUN if [ -s /usr/src/sentry/requirements.txt ]; then \ echo "sentry/requirements.txt is deprecated, use sentry/enhance-image.sh - see https://develop.sentry.dev/self-hosted/#enhance-sentry-image"; \ pip install -r /usr/src/sentry/requirements.txt; \ fi + +# Let the non-root sentry user run update-ca-certificates (sentry/entrypoint.sh) +# for custom CAs mounted from ./certificates. It only needs to create symlinks +# and replace the bundle in this directory. +RUN chown sentry:sentry /etc/ssl/certs + +USER sentry