Fix Dockerfile for Cloudron: run as root (base image default), override ENTRYPOINT, fix .dockerignore
This commit is contained in:
1 parent
b9b4620e52
commit
41068a6264
2 files changed
+11
-17
No files matched your search
+1
-2
@@ -1,5 +1,4 @@
|
|||||||
node_modules
|
node_modules
|
||||||
.git
|
.git
|
||||||
*.md
|
*.md
|
||||||
Dockerfile
|
.dockerignore
|
||||||
.dockerignore
|
|
||||||
+10
-15
@@ -1,25 +1,20 @@
|
|||||||
FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
|
FROM ghcr.io/berriai/litellm:main-v1.74.0-stable
|
||||||
|
|
||||||
# Cloudron runs apps as the 'cloudron' user (uid 1000) by default.
|
# LiteLLM's official image runs as root. Cloudron's sandboxing (read-only
|
||||||
# LiteLLM's official image runs as root; we switch to cloudron for security.
|
# rootfs, AppArmor, dropped capabilities) still applies to root inside the
|
||||||
# However, LiteLLM needs to write to /app/data for its database/config.
|
# container, so we keep root to match the base image and avoid /app/data
|
||||||
|
# volume-ownership issues.
|
||||||
|
|
||||||
USER root
|
# Create the data directory (Cloudron mounts the localstorage volume here)
|
||||||
|
RUN mkdir -p /app/data
|
||||||
# Install supervisor to manage processes (LiteLLM + optional cron)
|
|
||||||
RUN pip install --no-cache-dir supervisor
|
|
||||||
|
|
||||||
# Create the data directory and set ownership
|
|
||||||
RUN mkdir -p /app/data && chown -R cloudron:cloudron /app/data
|
|
||||||
|
|
||||||
# Create a startup script that configures LiteLLM with Cloudron addons
|
# Create a startup script that configures LiteLLM with Cloudron addons
|
||||||
COPY start.sh /app/code/start.sh
|
COPY start.sh /app/code/start.sh
|
||||||
RUN chmod +x /app/code/start.sh && chown cloudron:cloudron /app/code/start.sh
|
RUN chmod +x /app/code/start.sh
|
||||||
|
|
||||||
# Default config — will be overridden by Cloudron env vars at runtime
|
# Default config — will be overridden by Cloudron env vars at runtime
|
||||||
COPY config.yaml /app/data/config.yaml
|
COPY config.yaml /app/data/config.yaml
|
||||||
RUN chown cloudron:cloudron /app/data/config.yaml
|
|
||||||
|
|
||||||
USER cloudron
|
# Override the base image's ENTRYPOINT (which is `litellm`) so our
|
||||||
|
# startup script runs instead of being passed as an argument to litellm.
|
||||||
CMD ["/app/code/start.sh"]
|
ENTRYPOINT ["/app/code/start.sh"]
|
||||||
Reference in new issue
Block a user