diff --git a/Dockerfile b/Dockerfile index 09f832c..2c90177 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,9 +9,11 @@ RUN pip install --no-cache-dir -r requirements.txt # Copy app COPY app/ ./app/ -# Cloudron runs as UID 1000 -RUN mkdir -p /app/data && chown -R 1000:1000 /app/data /app/code -USER 1000 +# Run as root (the base image default). Cloudron's sandboxing (read-only +# rootfs, AppArmor, dropped capabilities) still applies to root inside the +# container, and /app/data is mounted as a root-owned volume, so running as +# root is required for the app to write its SQLite store there. +RUN mkdir -p /app/data EXPOSE 8000