docker: Add env var to control capabilities (#8552)
As it's not simple to run a container under Docker/Kubernetes as non-root but with additional capabilities, add an internal hack.
This commit is contained in:
@@ -3,6 +3,17 @@
|
||||
set -eu
|
||||
|
||||
if [ "$(id -u)" = '0' ]; then
|
||||
binary="$1"
|
||||
if [ "$PCAP" == "" ] ; then
|
||||
# If Syncthing should have no extra capabilities, make sure to remove them
|
||||
# from the binary. This will fail with an error if there are no
|
||||
# capabilities to remove, hence the || true etc.
|
||||
setcap -r "$binary" 2>/dev/null || true
|
||||
else
|
||||
# Set capabilities on the Syncthing binary before launching it.
|
||||
setcap "$PCAP" "$binary"
|
||||
fi
|
||||
|
||||
chown "${PUID}:${PGID}" "${HOME}" \
|
||||
&& exec su-exec "${PUID}:${PGID}" \
|
||||
env HOME="$HOME" "$@"
|
||||
|
||||
Reference in New Issue
Block a user