Skip to content

Commit 5296199

Browse files
committed
Merge pull request #161 from infosiftr/any-user
Allow arbitrary --user values
2 parents 11a7c3a + a6f4c23 commit 5296199

File tree

6 files changed

+100
-21
lines changed

6 files changed

+100
-21
lines changed

5.5/Dockerfile

Lines changed: 23 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,20 @@ FROM debian:jessie
33
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
44
RUN groupadd -r mysql && useradd -r -g mysql mysql
55

6+
# add gosu for easy step-down from root
7+
ENV GOSU_VERSION 1.7
8+
RUN set -x \
9+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
10+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
11+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
12+
&& export GNUPGHOME="$(mktemp -d)" \
13+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
14+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
15+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
16+
&& chmod +x /usr/local/bin/gosu \
17+
&& gosu nobody true \
18+
&& apt-get purge -y --auto-remove ca-certificates wget
19+
620
RUN mkdir /docker-entrypoint-initdb.d
721

822
# FATAL ERROR: please install the following Perl modules before executing /usr/local/mysql/scripts/mysql_install_db:
@@ -19,10 +33,10 @@ ENV MYSQL_MAJOR 5.5
1933
ENV MYSQL_VERSION 5.5.49
2034

2135
# note: we're pulling the *.asc file from mysql.he.net instead of dev.mysql.com because the official mirror 404s that file for whatever reason - maybe it's at a different path?
22-
RUN apt-get update && apt-get install -y curl --no-install-recommends && rm -rf /var/lib/apt/lists/* \
23-
&& curl -SL "http://dev.mysql.com/get/Downloads/MySQL-$MYSQL_MAJOR/mysql-$MYSQL_VERSION-linux2.6-x86_64.tar.gz" -o mysql.tar.gz \
24-
&& curl -SL "http://mysql.he.net/Downloads/MySQL-$MYSQL_MAJOR/mysql-$MYSQL_VERSION-linux2.6-x86_64.tar.gz.asc" -o mysql.tar.gz.asc \
25-
&& apt-get purge -y --auto-remove curl \
36+
RUN apt-get update && apt-get install -y wget --no-install-recommends && rm -rf /var/lib/apt/lists/* \
37+
&& wget "http://dev.mysql.com/get/Downloads/MySQL-$MYSQL_MAJOR/mysql-$MYSQL_VERSION-linux2.6-x86_64.tar.gz" -O mysql.tar.gz \
38+
&& wget "http://mysql.he.net/Downloads/MySQL-$MYSQL_MAJOR/mysql-$MYSQL_VERSION-linux2.6-x86_64.tar.gz.asc" -O mysql.tar.gz.asc \
39+
&& apt-get purge -y --auto-remove wget \
2640
&& export GNUPGHOME="$(mktemp -d)" \
2741
# gpg: key 5072E1F5: public key "MySQL Release Engineering <[email protected]>" imported
2842
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys A4A9406876FCBD3C456770C88C718D3B5072E1F5 \
@@ -46,11 +60,15 @@ RUN mkdir -p /etc/mysql/conf.d \
4660
echo '[mysqld]'; \
4761
echo 'skip-host-cache'; \
4862
echo 'skip-name-resolve'; \
49-
echo 'user = mysql'; \
5063
echo 'datadir = /var/lib/mysql'; \
5164
echo '!includedir /etc/mysql/conf.d/'; \
5265
} > /etc/mysql/my.cnf
5366

67+
RUN mkdir -p /var/lib/mysql /var/run/mysqld \
68+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
69+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
70+
&& chmod 777 /var/run/mysqld
71+
5472
VOLUME /var/lib/mysql
5573

5674
COPY docker-entrypoint.sh /usr/local/bin/

5.5/docker-entrypoint.sh

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,10 +41,9 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
35-
mysql_install_db --user=mysql --datadir="$DATADIR" --rpm --basedir=/usr/local/mysql
46+
mysql_install_db --datadir="$DATADIR" --rpm --basedir=/usr/local/mysql
3647
echo 'Database initialized'
3748

3849
"$@" --skip-networking --basedir=/usr/local/mysql &
@@ -117,8 +128,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
117128
echo 'MySQL init process done. Ready for start up.'
118129
echo
119130
fi
120-
121-
chown -R mysql:mysql "$DATADIR"
122131
fi
123132

124133
exec "$@"

5.6/Dockerfile

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,20 @@ FROM debian:jessie
33
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
44
RUN groupadd -r mysql && useradd -r -g mysql mysql
55

6+
# add gosu for easy step-down from root
7+
ENV GOSU_VERSION 1.7
8+
RUN set -x \
9+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
10+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
11+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
12+
&& export GNUPGHOME="$(mktemp -d)" \
13+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
14+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
15+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
16+
&& chmod +x /usr/local/bin/gosu \
17+
&& gosu nobody true \
18+
&& apt-get purge -y --auto-remove ca-certificates wget
19+
620
RUN mkdir /docker-entrypoint-initdb.d
721

822
# FATAL ERROR: please install the following Perl modules before executing /usr/local/mysql/scripts/mysql_install_db:
@@ -29,7 +43,10 @@ RUN { \
2943
echo mysql-community-server mysql-community-server/remove-test-db select false; \
3044
} | debconf-set-selections \
3145
&& apt-get update && apt-get install -y mysql-server="${MYSQL_VERSION}" && rm -rf /var/lib/apt/lists/* \
32-
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql
46+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
47+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
48+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
49+
&& chmod 777 /var/run/mysqld
3350

3451
# comment out a few problematic configuration values
3552
# don't reverse lookup hostnames, they are usually another container

5.6/docker-entrypoint.sh

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,10 +41,9 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
35-
mysql_install_db --user=mysql --datadir="$DATADIR" --rpm --keep-my-cnf
46+
mysql_install_db --datadir="$DATADIR" --rpm --keep-my-cnf
3647
echo 'Database initialized'
3748

3849
"$@" --skip-networking &
@@ -117,8 +128,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
117128
echo 'MySQL init process done. Ready for start up.'
118129
echo
119130
fi
120-
121-
chown -R mysql:mysql "$DATADIR"
122131
fi
123132

124133
exec "$@"

5.7/Dockerfile

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,20 @@ FROM debian:jessie
33
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
44
RUN groupadd -r mysql && useradd -r -g mysql mysql
55

6+
# add gosu for easy step-down from root
7+
ENV GOSU_VERSION 1.7
8+
RUN set -x \
9+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
10+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
11+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
12+
&& export GNUPGHOME="$(mktemp -d)" \
13+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
14+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
15+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
16+
&& chmod +x /usr/local/bin/gosu \
17+
&& gosu nobody true \
18+
&& apt-get purge -y --auto-remove ca-certificates wget
19+
620
RUN mkdir /docker-entrypoint-initdb.d
721

822
# FATAL ERROR: please install the following Perl modules before executing /usr/local/mysql/scripts/mysql_install_db:
@@ -29,7 +43,10 @@ RUN { \
2943
echo mysql-community-server mysql-community-server/remove-test-db select false; \
3044
} | debconf-set-selections \
3145
&& apt-get update && apt-get install -y mysql-server="${MYSQL_VERSION}" && rm -rf /var/lib/apt/lists/* \
32-
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql
46+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
47+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
48+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
49+
&& chmod 777 /var/run/mysqld
3350

3451
# comment out a few problematic configuration values
3552
# don't reverse lookup hostnames, they are usually another container

5.7/docker-entrypoint.sh

Lines changed: 13 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,7 +41,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
3546
"$@" --initialize-insecure
@@ -117,8 +128,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
117128
echo 'MySQL init process done. Ready for start up.'
118129
echo
119130
fi
120-
121-
chown -R mysql:mysql "$DATADIR"
122131
fi
123132

124133
exec "$@"

0 commit comments

Comments
 (0)