Keep the database in ./data and bind-mount it
SQLite writes three files — the database plus its -wal and -shm companions. Putting them in one directory means a deployment mounts a single path and a backup copies a single directory. - FOODSTER_DB defaults to ./data/foodster.db, and openDB creates the parent directory on startup rather than failing on a fresh checkout - compose bind-mounts ./data instead of using a named volume, so the file can be listed, copied and opened with any sqlite client without going through the container engine - the image runs as UID 65534, which cannot write to a host directory owned by someone else, so compose now sets user: from FOODSTER_UID/FOODSTER_GID - `make up` creates ./data first: left to the engine it appears root-owned and the app silently cannot write to it
This commit is contained in:
@@ -105,7 +105,8 @@ Everything is environment variables. `.env` is gitignored; start from
|
||||
| Variable | Default | Purpose |
|
||||
|---|---|---|
|
||||
| `FOODSTER_PASSWORD` | *required* | Shared password. The app will not start without it. |
|
||||
| `FOODSTER_DB` | `/data/foodster.db` | SQLite file path. |
|
||||
| `FOODSTER_DB` | `./data/foodster.db` | SQLite file path; the directory is created if missing. |
|
||||
| `FOODSTER_UID` / `FOODSTER_GID` | `1000` | Host owner of `./data`, for the bind mount. |
|
||||
| `TZ` | `Europe/Helsinki` | Used for every calendar-day calculation. |
|
||||
| `FOODSTER_REPO` | *required to build* | Image repository, no tag. |
|
||||
| `FOODSTER_TAG` | `latest` | Tag to run under compose. |
|
||||
@@ -129,8 +130,13 @@ Versions are CalVer — `vYYYYMMDD-N`, where `N` is the Nth build that day. The
|
||||
running version is served at `GET /healthz`, which is the one route outside
|
||||
authentication.
|
||||
|
||||
There is no database container. SQLite lives on a named volume, so a backup
|
||||
is a file copy.
|
||||
There is no database container. SQLite lives in `./data`, bind-mounted into
|
||||
the container, so a backup is `cp -r data` and you can inspect the file with
|
||||
any sqlite client without going through the engine.
|
||||
|
||||
That directory must exist and be owned by the user compose runs as — `make up`
|
||||
creates it, and `FOODSTER_UID`/`FOODSTER_GID` in `.env` tell the container who
|
||||
that is. Get them from `id -u` and `id -g`.
|
||||
|
||||
## Security
|
||||
|
||||
|
||||
Reference in New Issue
Block a user