mirror of
https://github.com/bitwarden/server.git
synced 2025-12-10 00:42:07 -06:00
* testing-wolfi * testing alpine * fix gosu download * fix Admin dockerfile * update dockerfiles * alpine-compatible-entrypoint-script-for-api-test * make-entrypoint-scripts-alpine-compatible * testing nginx with alpine * cleaning up comments from dockerfile from testing * restore accidentally deleted icon * remove unused file * pin alpine, update apk add no cache * remove comments from testing * test shadow implementtaion for entrypoints * add shadow package, revert entrypoints, change from bash to shell for entry * add icu to setup container, update helpers to use shell * update migrator utility * add missing krb5 libraries
48 lines
1.1 KiB
Bash
48 lines
1.1 KiB
Bash
#!/bin/sh
|
|
|
|
# Setup
|
|
|
|
GROUPNAME="bitwarden"
|
|
USERNAME="bitwarden"
|
|
|
|
LUID=${LOCAL_UID:-0}
|
|
LGID=${LOCAL_GID:-0}
|
|
|
|
# Step down from host root to well-known nobody/nogroup user
|
|
|
|
if [ $LUID -eq 0 ]
|
|
then
|
|
LUID=65534
|
|
fi
|
|
if [ $LGID -eq 0 ]
|
|
then
|
|
LGID=65534
|
|
fi
|
|
|
|
# Create user and group
|
|
|
|
groupadd -o -g $LGID $GROUPNAME >/dev/null 2>&1 ||
|
|
groupmod -o -g $LGID $GROUPNAME >/dev/null 2>&1
|
|
useradd -o -u $LUID -g $GROUPNAME -s /bin/false $USERNAME >/dev/null 2>&1 ||
|
|
usermod -o -u $LUID -g $GROUPNAME -s /bin/false $USERNAME >/dev/null 2>&1
|
|
mkhomedir_helper $USERNAME
|
|
|
|
# The rest...
|
|
|
|
chown -R $USERNAME:$GROUPNAME /etc/bitwarden
|
|
cp /etc/bitwarden/nginx/*.conf /etc/nginx/conf.d/
|
|
mkdir -p /etc/letsencrypt
|
|
chown -R $USERNAME:$GROUPNAME /etc/letsencrypt
|
|
mkdir -p /etc/ssl
|
|
chown -R $USERNAME:$GROUPNAME /etc/ssl
|
|
mkdir -p /var/run/nginx
|
|
touch /var/run/nginx/nginx.pid
|
|
chown -R $USERNAME:$GROUPNAME /var/run/nginx
|
|
chown -R $USERNAME:$GROUPNAME /var/cache/nginx
|
|
chown -R $USERNAME:$GROUPNAME /var/log/nginx
|
|
|
|
# Launch a loop to rotate nginx logs on a daily basis
|
|
gosu $USERNAME:$GROUPNAME /bin/sh -c "/logrotate.sh loop >/dev/null 2>&1 &"
|
|
|
|
exec gosu $USERNAME:$GROUPNAME nginx -g 'daemon off;'
|