Skip to content

Allow arbitrary "--user" values (skip "gosu" unless we're running as root) #70

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Nov 29, 2016

Conversation

tianon
Copy link
Member

@tianon tianon commented Nov 28, 2016

@tianon
Copy link
Member Author

tianon commented Nov 28, 2016

To run as another user, one currently has to use --entrypoint since our use of gosu is unconditional, but this change allows for --user to be used arbitrarily.

@tianon
Copy link
Member Author

tianon commented Nov 28, 2016

Hmm, turns out /var/lib/logstash makes this slightly more complicated.

@tianon
Copy link
Member Author

tianon commented Nov 28, 2016

Sending Logstash's logs to /var/log/logstash which is now configured via log4j2.properties 22:52:37.077 [LogStash::Runner] FATAL logstash.runner - An unexpected error occurred! {:error=>#<ArgumentError: Path "/var/lib/logstash" is not a directory or not writable.>, :backtrace=>["/usr/share/logstash/logstash-core/lib/logstash/settings.rb:396:in initialize'", "org/jruby/RubyProc.java:281:in call'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:191:in validate'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:182:in validate_value'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:100:in validate_all'", "org/jruby/RubyHash.java:1342:in each'", "/usr/share/logstash/logstash-core/lib/logstash/settings.rb:99:in validate_all'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:224:in execute'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:67:in run'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:175:in run'", "/usr/share/logstash/vendor/bundle/jruby/1.9/gems/clamp-0.6.5/lib/clamp/command.rb:132:in run'", "/usr/share/logstash/lib/bootstrap/environment.rb:68:in (root)'"]}

@tianon
Copy link
Member Author

tianon commented Nov 28, 2016

It does work if I specify --tmpfs /var/lib/logstash as well, so I'm going to chalk that one up to a documentation issue (if you want to use arbitrary --user values, you need to also handle permissions on /var/lib/logstash). Sound fair?

@yosifkit
Copy link
Member

Sounds fair to me; just like the MongoDB image.

@yosifkit yosifkit merged commit f1c6980 into docker-library:master Nov 29, 2016
@yosifkit yosifkit deleted the any-user branch November 29, 2016 00:07
tianon added a commit to infosiftr/stackbrew that referenced this pull request Nov 30, 2016
- `elasticsearch`: 5.0.2 (docker-library/elasticsearch#145)
- `kibana`: 5.0.2
- `logstash`: 5.0.2, 5.1.0, allow arbitrary `--user` values (docker-library/logstash#70)
- `mongo`: 3.4.0 GA (remove 3.3 development series)
- `percona`: 5.6.34-79.1-1.jessie, 5.7.16-10-1.jessie
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants