Skip to content

Commit cc686f5

Browse files
committed
Allow arbitrary --user values
1 parent b475211 commit cc686f5

8 files changed

+160
-48
lines changed

10.0/Dockerfile

Lines changed: 26 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,25 @@ FROM debian:jessie
44
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
55
RUN groupadd -r mysql && useradd -r -g mysql mysql
66

7-
# install "pwgen" for randomizing passwords
8-
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
7+
# add gosu for easy step-down from root
8+
ENV GOSU_VERSION 1.7
9+
RUN set -x \
10+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
11+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
12+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
13+
&& export GNUPGHOME="$(mktemp -d)" \
14+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
15+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
16+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
17+
&& chmod +x /usr/local/bin/gosu \
18+
&& gosu nobody true \
19+
&& apt-get purge -y --auto-remove ca-certificates wget
920

1021
RUN mkdir /docker-entrypoint-initdb.d
1122

23+
# install "pwgen" for randomizing passwords
24+
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
25+
1226
# Key fingerprint = 1993 69E5 404B D5FC 7D2F E43B CBCB 082A 1BB9 43DB
1327
# MariaDB Package Signing Key <[email protected]>
1428
# Key fingerprint = 430B DF5C 56E7 C94E 848E E60C 1C4C BDCD CD2E FD2A
@@ -48,8 +62,13 @@ RUN { \
4862
percona-xtrabackup \
4963
socat \
5064
&& rm -rf /var/lib/apt/lists/* \
51-
&& rm -rf /var/lib/mysql \
52-
&& mkdir /var/lib/mysql
65+
# comment out any "user" entires in the MySQL config ("docker-entrypoint.sh" or "--user" will handle user switching)
66+
&& sed -ri 's/^user\s/#&/' /etc/mysql/my.cnf /etc/mysql/conf.d/* \
67+
# purge and re-create /var/lib/mysql with appropriate ownership
68+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
69+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
70+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
71+
&& chmod 777 /var/run/mysqld
5372

5473
# comment out a few problematic configuration values
5574
# don't reverse lookup hostnames, they are usually another container
@@ -59,9 +78,9 @@ RUN sed -Ei 's/^(bind-address|log)/#&/' /etc/mysql/my.cnf \
5978

6079
VOLUME /var/lib/mysql
6180

62-
COPY docker-entrypoint.sh /
63-
64-
ENTRYPOINT ["/docker-entrypoint.sh"]
81+
COPY docker-entrypoint.sh /usr/local/bin/
82+
RUN ln -s usr/local/bin/docker-entrypoint.sh /entrypoint.sh # backwards compat
83+
ENTRYPOINT ["docker-entrypoint.sh"]
6584

6685
EXPOSE 3306
6786
CMD ["mysqld"]

10.0/docker-entrypoint.sh

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,10 +41,9 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
35-
mysql_install_db --user=mysql --datadir="$DATADIR" --rpm
46+
mysql_install_db --datadir="$DATADIR" --rpm
3647
echo 'Database initialized'
3748

3849
"$@" --skip-networking &
@@ -112,8 +123,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
112123
echo 'MySQL init process done. Ready for start up.'
113124
echo
114125
fi
115-
116-
chown -R mysql:mysql "$DATADIR"
117126
fi
118127

119128
exec "$@"

10.1/Dockerfile

Lines changed: 26 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,25 @@ FROM debian:jessie
44
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
55
RUN groupadd -r mysql && useradd -r -g mysql mysql
66

7-
# install "pwgen" for randomizing passwords
8-
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
7+
# add gosu for easy step-down from root
8+
ENV GOSU_VERSION 1.7
9+
RUN set -x \
10+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
11+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
12+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
13+
&& export GNUPGHOME="$(mktemp -d)" \
14+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
15+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
16+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
17+
&& chmod +x /usr/local/bin/gosu \
18+
&& gosu nobody true \
19+
&& apt-get purge -y --auto-remove ca-certificates wget
920

1021
RUN mkdir /docker-entrypoint-initdb.d
1122

23+
# install "pwgen" for randomizing passwords
24+
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
25+
1226
# Key fingerprint = 1993 69E5 404B D5FC 7D2F E43B CBCB 082A 1BB9 43DB
1327
# MariaDB Package Signing Key <[email protected]>
1428
# Key fingerprint = 430B DF5C 56E7 C94E 848E E60C 1C4C BDCD CD2E FD2A
@@ -48,8 +62,13 @@ RUN { \
4862
percona-xtrabackup \
4963
socat \
5064
&& rm -rf /var/lib/apt/lists/* \
51-
&& rm -rf /var/lib/mysql \
52-
&& mkdir /var/lib/mysql
65+
# comment out any "user" entires in the MySQL config ("docker-entrypoint.sh" or "--user" will handle user switching)
66+
&& sed -ri 's/^user\s/#&/' /etc/mysql/my.cnf /etc/mysql/conf.d/* \
67+
# purge and re-create /var/lib/mysql with appropriate ownership
68+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
69+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
70+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
71+
&& chmod 777 /var/run/mysqld
5372

5473
# comment out a few problematic configuration values
5574
# don't reverse lookup hostnames, they are usually another container
@@ -59,9 +78,9 @@ RUN sed -Ei 's/^(bind-address|log)/#&/' /etc/mysql/my.cnf \
5978

6079
VOLUME /var/lib/mysql
6180

62-
COPY docker-entrypoint.sh /
63-
64-
ENTRYPOINT ["/docker-entrypoint.sh"]
81+
COPY docker-entrypoint.sh /usr/local/bin/
82+
RUN ln -s usr/local/bin/docker-entrypoint.sh /entrypoint.sh # backwards compat
83+
ENTRYPOINT ["docker-entrypoint.sh"]
6584

6685
EXPOSE 3306
6786
CMD ["mysqld"]

10.1/docker-entrypoint.sh

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,10 +41,9 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
35-
mysql_install_db --user=mysql --datadir="$DATADIR" --rpm
46+
mysql_install_db --datadir="$DATADIR" --rpm
3647
echo 'Database initialized'
3748

3849
"$@" --skip-networking &
@@ -112,8 +123,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
112123
echo 'MySQL init process done. Ready for start up.'
113124
echo
114125
fi
115-
116-
chown -R mysql:mysql "$DATADIR"
117126
fi
118127

119128
exec "$@"

5.5/Dockerfile

Lines changed: 26 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,25 @@ FROM debian:wheezy
44
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
55
RUN groupadd -r mysql && useradd -r -g mysql mysql
66

7-
# install "pwgen" for randomizing passwords
8-
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
7+
# add gosu for easy step-down from root
8+
ENV GOSU_VERSION 1.7
9+
RUN set -x \
10+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
11+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
12+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
13+
&& export GNUPGHOME="$(mktemp -d)" \
14+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
15+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
16+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
17+
&& chmod +x /usr/local/bin/gosu \
18+
&& gosu nobody true \
19+
&& apt-get purge -y --auto-remove ca-certificates wget
920

1021
RUN mkdir /docker-entrypoint-initdb.d
1122

23+
# install "pwgen" for randomizing passwords
24+
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
25+
1226
# Key fingerprint = 1993 69E5 404B D5FC 7D2F E43B CBCB 082A 1BB9 43DB
1327
# MariaDB Package Signing Key <[email protected]>
1428
# Key fingerprint = 430B DF5C 56E7 C94E 848E E60C 1C4C BDCD CD2E FD2A
@@ -48,8 +62,13 @@ RUN { \
4862
percona-xtrabackup \
4963
socat \
5064
&& rm -rf /var/lib/apt/lists/* \
51-
&& rm -rf /var/lib/mysql \
52-
&& mkdir /var/lib/mysql
65+
# comment out any "user" entires in the MySQL config ("docker-entrypoint.sh" or "--user" will handle user switching)
66+
&& sed -ri 's/^user\s/#&/' /etc/mysql/my.cnf /etc/mysql/conf.d/* \
67+
# purge and re-create /var/lib/mysql with appropriate ownership
68+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
69+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
70+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
71+
&& chmod 777 /var/run/mysqld
5372

5473
# comment out a few problematic configuration values
5574
# don't reverse lookup hostnames, they are usually another container
@@ -59,9 +78,9 @@ RUN sed -Ei 's/^(bind-address|log)/#&/' /etc/mysql/my.cnf \
5978

6079
VOLUME /var/lib/mysql
6180

62-
COPY docker-entrypoint.sh /
63-
64-
ENTRYPOINT ["/docker-entrypoint.sh"]
81+
COPY docker-entrypoint.sh /usr/local/bin/
82+
RUN ln -s usr/local/bin/docker-entrypoint.sh /entrypoint.sh # backwards compat
83+
ENTRYPOINT ["docker-entrypoint.sh"]
6584

6685
EXPOSE 3306
6786
CMD ["mysqld"]

5.5/docker-entrypoint.sh

Lines changed: 14 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,21 @@ for arg; do
1717
esac
1818
done
1919

20+
_datadir() {
21+
"$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }'
22+
}
23+
24+
# allow the container to be started with `--user`
25+
if [ "$1" = 'mysqld' -a -z "$wantHelp" -a "$(id -u)" = '0' ]; then
26+
DATADIR="$(_datadir "$@")"
27+
mkdir -p "$DATADIR"
28+
chown -R mysql:mysql "$DATADIR"
29+
exec gosu mysql "$BASH_SOURCE" "$@"
30+
fi
31+
2032
if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2133
# Get config
22-
DATADIR="$("$@" --verbose --help --log-bin-index=`mktemp -u` 2>/dev/null | awk '$1 == "datadir" { print $2; exit }')"
34+
DATADIR="$(_datadir "$@")"
2335

2436
if [ ! -d "$DATADIR/mysql" ]; then
2537
if [ -z "$MYSQL_ROOT_PASSWORD" -a -z "$MYSQL_ALLOW_EMPTY_PASSWORD" -a -z "$MYSQL_RANDOM_ROOT_PASSWORD" ]; then
@@ -29,10 +41,9 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
2941
fi
3042

3143
mkdir -p "$DATADIR"
32-
chown -R mysql:mysql "$DATADIR"
3344

3445
echo 'Initializing database'
35-
mysql_install_db --user=mysql --datadir="$DATADIR" --rpm
46+
mysql_install_db --datadir="$DATADIR" --rpm
3647
echo 'Database initialized'
3748

3849
"$@" --skip-networking &
@@ -112,8 +123,6 @@ if [ "$1" = 'mysqld' -a -z "$wantHelp" ]; then
112123
echo 'MySQL init process done. Ready for start up.'
113124
echo
114125
fi
115-
116-
chown -R mysql:mysql "$DATADIR"
117126
fi
118127

119128
exec "$@"

Dockerfile.template

Lines changed: 26 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4,11 +4,25 @@ FROM debian:%%SUITE%%
44
# add our user and group first to make sure their IDs get assigned consistently, regardless of whatever dependencies get added
55
RUN groupadd -r mysql && useradd -r -g mysql mysql
66

7-
# install "pwgen" for randomizing passwords
8-
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
7+
# add gosu for easy step-down from root
8+
ENV GOSU_VERSION 1.7
9+
RUN set -x \
10+
&& apt-get update && apt-get install -y --no-install-recommends ca-certificates wget && rm -rf /var/lib/apt/lists/* \
11+
&& wget -O /usr/local/bin/gosu "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture)" \
12+
&& wget -O /usr/local/bin/gosu.asc "https://github.com/tianon/gosu/releases/download/$GOSU_VERSION/gosu-$(dpkg --print-architecture).asc" \
13+
&& export GNUPGHOME="$(mktemp -d)" \
14+
&& gpg --keyserver ha.pool.sks-keyservers.net --recv-keys B42F6819007F00F88E364FD4036A9C25BF357DD4 \
15+
&& gpg --batch --verify /usr/local/bin/gosu.asc /usr/local/bin/gosu \
16+
&& rm -r "$GNUPGHOME" /usr/local/bin/gosu.asc \
17+
&& chmod +x /usr/local/bin/gosu \
18+
&& gosu nobody true \
19+
&& apt-get purge -y --auto-remove ca-certificates wget
920

1021
RUN mkdir /docker-entrypoint-initdb.d
1122

23+
# install "pwgen" for randomizing passwords
24+
RUN apt-get update && apt-get install -y pwgen && rm -rf /var/lib/apt/lists/*
25+
1226
# Key fingerprint = 1993 69E5 404B D5FC 7D2F E43B CBCB 082A 1BB9 43DB
1327
# MariaDB Package Signing Key <[email protected]>
1428
# Key fingerprint = 430B DF5C 56E7 C94E 848E E60C 1C4C BDCD CD2E FD2A
@@ -48,8 +62,13 @@ RUN { \
4862
percona-xtrabackup \
4963
socat \
5064
&& rm -rf /var/lib/apt/lists/* \
51-
&& rm -rf /var/lib/mysql \
52-
&& mkdir /var/lib/mysql
65+
# comment out any "user" entires in the MySQL config ("docker-entrypoint.sh" or "--user" will handle user switching)
66+
&& sed -ri 's/^user\s/#&/' /etc/mysql/my.cnf /etc/mysql/conf.d/* \
67+
# purge and re-create /var/lib/mysql with appropriate ownership
68+
&& rm -rf /var/lib/mysql && mkdir -p /var/lib/mysql /var/run/mysqld \
69+
&& chown -R mysql:mysql /var/lib/mysql /var/run/mysqld \
70+
# ensure that /var/run/mysqld (used for socket and lock files) is writable regardless of the UID our mysqld instance ends up having at runtime
71+
&& chmod 777 /var/run/mysqld
5372

5473
# comment out a few problematic configuration values
5574
# don't reverse lookup hostnames, they are usually another container
@@ -59,9 +78,9 @@ RUN sed -Ei 's/^(bind-address|log)/#&/' /etc/mysql/my.cnf \
5978

6079
VOLUME /var/lib/mysql
6180

62-
COPY docker-entrypoint.sh /
63-
64-
ENTRYPOINT ["/docker-entrypoint.sh"]
81+
COPY docker-entrypoint.sh /usr/local/bin/
82+
RUN ln -s usr/local/bin/docker-entrypoint.sh /entrypoint.sh # backwards compat
83+
ENTRYPOINT ["docker-entrypoint.sh"]
6584

6685
EXPOSE 3306
6786
CMD ["mysqld"]

0 commit comments

Comments
 (0)