nodered: inline-write start.sh to avoid COPY+chmod permission issue
The NR base image's /data has restrictive ACLs that block chmod on COPY'd files even as root. Writing start.sh inline with printf + chmod sidesteps this.
This commit is contained in:
@@ -12,6 +12,9 @@ FROM nodered/node-red:5.0.0
|
|||||||
|
|
||||||
# Install Dashboard 2.0 (and any future deps) at image-build time.
|
# Install Dashboard 2.0 (and any future deps) at image-build time.
|
||||||
# Versions are pinned in infra/nodered/package.json for reproducibility.
|
# Versions are pinned in infra/nodered/package.json for reproducibility.
|
||||||
|
# The NR base image defaults USER to node-red (uid 1000), so switch to root
|
||||||
|
# for the install (writes to /data/node_modules need root then chown).
|
||||||
|
USER root
|
||||||
COPY package.json /data/package.json
|
COPY package.json /data/package.json
|
||||||
WORKDIR /data
|
WORKDIR /data
|
||||||
RUN npm install --omit=dev --no-audit --no-fund \
|
RUN npm install --omit=dev --no-audit --no-fund \
|
||||||
@@ -19,9 +22,23 @@ RUN npm install --omit=dev --no-audit --no-fund \
|
|||||||
&& echo "[Dockerfile] installed @flowfuse/node-red-dashboard"
|
&& echo "[Dockerfile] installed @flowfuse/node-red-dashboard"
|
||||||
|
|
||||||
# start.sh handles the SPA base-href patch (idempotent: grep guard).
|
# start.sh handles the SPA base-href patch (idempotent: grep guard).
|
||||||
# Chmod so the compose `user: 1000:1000` can run it.
|
# Inline-write + chmod so we don't hit the COPY-then-chmod permission issue
|
||||||
COPY start.sh /data/start.sh
|
# (the base image's /data ACLs block chmod on COPY'd files even as root).
|
||||||
RUN chmod +x /data/start.sh
|
RUN printf "%s\n" \
|
||||||
|
"#!/bin/sh" \
|
||||||
|
"INDEX=/data/node_modules/@flowfuse/node-red-dashboard/dist/index.html" \
|
||||||
|
"BASE_HREF=\"\${DASHBOARD_BASE_HREF:-/dashboard/}\"" \
|
||||||
|
"if [ -f \"\$INDEX\" ] && ! grep -q \"<base href\" \"\$INDEX\"; then" \
|
||||||
|
" sed -i \"s|<meta name=\\\"description\\\"|<base href=\\\"\$BASE_HREF\\\">" \
|
||||||
|
" <meta name=\\\"description\\\"|\" \"\$INDEX\"" \
|
||||||
|
" echo \"[start.sh] PATCHED base href=\$BASE_HREF\"" \
|
||||||
|
"fi" \
|
||||||
|
"cd /usr/src/node-red" \
|
||||||
|
"exec node \$NODE_OPTIONS node_modules/node-red/red.js \$FLOWS" \
|
||||||
|
> /data/start.sh \
|
||||||
|
&& chmod +x /data/start.sh \
|
||||||
|
&& chown 1000:1000 /data/start.sh
|
||||||
|
|
||||||
# Reset to NR's working dir; userDir is /data via the compose volume mount.
|
# Drop back to NR's default user; userDir is /data via the compose volume mount.
|
||||||
|
USER node-red
|
||||||
WORKDIR /usr/src/node-red
|
WORKDIR /usr/src/node-red
|
||||||
|
|||||||
Reference in New Issue
Block a user