fix(agent): unify agent and openresty runtime user as openflare

Introduce the shared openflare service account for the agent process and
OpenResty workers, normalize data_dir ownership on startup, and ensure
managed paths are chowned with 0755/0644 during sync and apply. Docker
entrypoint fixes volume ownership before dropping privileges; local systemd
install runs the service as openflare with CAP_NET_BIND_SERVICE.
This commit is contained in:
ryan
2026-06-21 14:25:20 +08:00
parent ee047cb351
commit d3777eac2d
17 changed files with 505 additions and 55 deletions
+10 -4
View File
@@ -25,16 +25,22 @@ RUN --mount=type=cache,target=/go/pkg/mod \
FROM openresty/openresty:alpine
RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb \
RUN apk add --no-cache ca-certificates tzdata perl libmaxminddb su-exec libcap \
&& ln -sf /usr/lib/libmaxminddb.so.0 /usr/lib/libmaxminddb.so \
&& opm get anjia0532/lua-resty-maxminddb \
&& mkdir -p /etc/openflare /data
&& addgroup -S openflare \
&& adduser -S -G openflare -H -h /data -s /sbin/nologin openflare \
&& mkdir -p /etc/openflare /data \
&& chown -R openflare:openflare /etc/openflare /data \
&& setcap 'cap_net_bind_service=+ep' /usr/local/openresty/nginx/sbin/nginx
ENV OPENFLARE_OPENRESTY_PATH=openresty \
OPENFLARE_DATA_DIR=/data
COPY --from=builder /build/bin/openflare-agent /usr/local/bin/openflare-agent
COPY docker/agent-entrypoint.sh /usr/local/bin/openflare-agent-entrypoint.sh
RUN chmod +x /usr/local/bin/openflare-agent-entrypoint.sh
EXPOSE 80 443 18081
ENTRYPOINT ["/usr/local/bin/openflare-agent"]
CMD ["-config", "/etc/openflare/agent.json"]
ENTRYPOINT ["/usr/local/bin/openflare-agent-entrypoint.sh"]
CMD ["-config", "/etc/openflare/agent.json"]
+22
View File
@@ -0,0 +1,22 @@
#!/bin/sh
set -eu
RUNTIME_USER="openflare"
AGENT_BIN="/usr/local/bin/openflare-agent"
OPENRESTY_BIN="/usr/local/openresty/nginx/sbin/nginx"
fix_runtime_ownership() {
for target in /data /etc/openflare; do
if [ -d "$target" ]; then
chown -R "${RUNTIME_USER}:${RUNTIME_USER}" "$target" 2>/dev/null || true
chmod -R u+rwX,g+rX "$target" 2>/dev/null || true
fi
done
}
if [ "$(id -u)" -eq 0 ]; then
fix_runtime_ownership
exec su-exec "${RUNTIME_USER}" "${AGENT_BIN}" "$@"
fi
exec "${AGENT_BIN}" "$@"