From 41068a62643fa9ad202a672e1420b29bf28c3ee0 Mon Sep 17 00:00:00 2001 From: inference-bot Date: Fri, 4 Sep 2026 10:29:15 -0600 Subject: [PATCH] Fix Dockerfile for Cloudron: run as root (base image default), override ENTRYPOINT, fix .dockerignore --- .dockerignore | 3 +-- Dockerfile | 25 ++++++++++--------------- 2 files changed, 11 insertions(+), 17 deletions(-) diff --git a/.dockerignore b/.dockerignore index 43620d2..940daaf 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,5 +1,4 @@ node_modules .git *.md -Dockerfile -.dockerignore \ No newline at end of file +.dockerignore diff --git a/Dockerfile b/Dockerfile index fd4389b..c1a3265 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,25 +1,20 @@ FROM ghcr.io/berriai/litellm:main-v1.74.0-stable -# Cloudron runs apps as the 'cloudron' user (uid 1000) by default. -# LiteLLM's official image runs as root; we switch to cloudron for security. -# However, LiteLLM needs to write to /app/data for its database/config. +# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only +# rootfs, AppArmor, dropped capabilities) still applies to root inside the +# container, so we keep root to match the base image and avoid /app/data +# volume-ownership issues. -USER root - -# Install supervisor to manage processes (LiteLLM + optional cron) -RUN pip install --no-cache-dir supervisor - -# Create the data directory and set ownership -RUN mkdir -p /app/data && chown -R cloudron:cloudron /app/data +# Create the data directory (Cloudron mounts the localstorage volume here) +RUN mkdir -p /app/data # Create a startup script that configures LiteLLM with Cloudron addons COPY start.sh /app/code/start.sh -RUN chmod +x /app/code/start.sh && chown cloudron:cloudron /app/code/start.sh +RUN chmod +x /app/code/start.sh # Default config — will be overridden by Cloudron env vars at runtime COPY config.yaml /app/data/config.yaml -RUN chown cloudron:cloudron /app/data/config.yaml -USER cloudron - -CMD ["/app/code/start.sh"] \ No newline at end of file +# Override the base image's ENTRYPOINT (which is `litellm`) so our +# startup script runs instead of being passed as an argument to litellm. +ENTRYPOINT ["/app/code/start.sh"]