mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-09-29 22:06:38 +08:00
d3777eac2d
Introduce the shared openflare service account for the agent process and OpenResty workers, normalize data_dir ownership on startup, and ensure managed paths are chowned with 0755/0644 during sync and apply. Docker entrypoint fixes volume ownership before dropping privileges; local systemd install runs the service as openflare with CAP_NET_BIND_SERVICE.
22 lines
526 B
Bash
22 lines
526 B
Bash
#!/bin/sh
|
|
set -eu
|
|
|
|
RUNTIME_USER="openflare"
|
|
AGENT_BIN="/usr/local/bin/openflare-agent"
|
|
OPENRESTY_BIN="/usr/local/openresty/nginx/sbin/nginx"
|
|
|
|
fix_runtime_ownership() {
|
|
for target in /data /etc/openflare; do
|
|
if [ -d "$target" ]; then
|
|
chown -R "${RUNTIME_USER}:${RUNTIME_USER}" "$target" 2>/dev/null || true
|
|
chmod -R u+rwX,g+rX "$target" 2>/dev/null || true
|
|
fi
|
|
done
|
|
}
|
|
|
|
if [ "$(id -u)" -eq 0 ]; then
|
|
fix_runtime_ownership
|
|
exec su-exec "${RUNTIME_USER}" "${AGENT_BIN}" "$@"
|
|
fi
|
|
|
|
exec "${AGENT_BIN}" "$@" |