diff --git a/self-hosted/Dockerfile b/self-hosted/Dockerfile index b4f52f40d5d6..abac1f6319fa 100644 --- a/self-hosted/Dockerfile +++ b/self-hosted/Dockerfile @@ -29,7 +29,6 @@ RUN groupadd -r sentry --gid 999 && useradd -r -m -g sentry --uid 999 sentry RUN : \ && apt-get update \ && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ - gosu \ libexpat1 \ tini \ && apt-get clean \ @@ -91,6 +90,12 @@ RUN : double-check some built files are available \ && test -f /usr/src/sentry/src/sentry/static/sentry/dist/entrypoints/app.js \ && sentry help +# Pre-create /data owned by sentry so fresh named volumes are initialized +# with the right ownership. This must happen before the VOLUME instruction. +RUN mkdir -p /data/files && chown -R sentry:sentry /data + +USER sentry + EXPOSE 9000 VOLUME /data diff --git a/self-hosted/docker-entrypoint.sh b/self-hosted/docker-entrypoint.sh index 2f0eb6c7d819..e3610fb68ca3 100755 --- a/self-hosted/docker-entrypoint.sh +++ b/self-hosted/docker-entrypoint.sh @@ -14,14 +14,6 @@ fi if [ "$1" = 'sentry' ]; then set -- tini -- "$@" - if [ "$(id -u)" = '0' ]; then - mkdir -p /data/files - sentry_uid=$(id -u sentry) - if [ "$(stat -c %u /data)" != "$sentry_uid" ] || [ "$(stat -c %u /data/files)" != "$sentry_uid" ]; then - find /data ! -user sentry -exec chown sentry {} \; - fi - set -- gosu sentry "$@" - fi fi exec "$@"