Skip to content

Commit

Permalink
Merge pull request #6040 from ipfs/revert-5048-docker-non-root
Browse files Browse the repository at this point in the history
Revert "Really run as non-root user in docker container"
  • Loading branch information
Stebalien authored Mar 4, 2019
2 parents 71d7cf7 + 9f74e12 commit e767ec4
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 9 deletions.
5 changes: 1 addition & 4 deletions Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -60,15 +60,12 @@ EXPOSE 8080
# Swarm Websockets; must be exposed publicly when the node is listening using the websocket transport (/ipX/.../tcp/8081/ws).
EXPOSE 8081

# Create the fs-repo directory
# Create the fs-repo directory and switch to a non-privileged user.
ENV IPFS_PATH /data/ipfs
RUN mkdir -p $IPFS_PATH \
&& adduser -D -h $IPFS_PATH -u 1000 -G users ipfs \
&& chown ipfs:users $IPFS_PATH

# Switch to a non-privileged user
USER ipfs

# Expose the fs-repo as a volume.
# start_ipfs initializes an fs-repo if none is mounted.
# Important this happens after the USER directive so permission are correct.
Expand Down
6 changes: 1 addition & 5 deletions Dockerfile.fast
Original file line number Diff line number Diff line change
Expand Up @@ -53,18 +53,14 @@ EXPOSE 5001
EXPOSE 8080
EXPOSE 8081

# Create the fs-repo directory
# Create the fs-repo directory and switch to a non-privileged user.
ENV IPFS_PATH /data/ipfs
RUN mkdir -p $IPFS_PATH \
&& useradd -s /usr/sbin/nologin -d $IPFS_PATH -u 1000 -G users ipfs \
&& chown ipfs:users $IPFS_PATH

# Switch to a non-privileged user
USER ipfs

# Expose the fs-repo as a volume.
# start_ipfs initializes an fs-repo if none is mounted.
# Important this happens after the USER directive so permission are correct.
VOLUME $IPFS_PATH

# The default logging level
Expand Down

0 comments on commit e767ec4

Please sign in to comment.