fix(docker): keep uv Python out of tmpfs-mounted /tmp

HOME=/tmp put the uv-managed Python at /tmp/.local/share/uv, so a
tmpfs mount on /tmp (e.g. compose tmpfs: /tmp) wiped the interpreter at
container start, leaving the /app/.venv/bin/python symlink dangling and
startup failing with 'exec /app/.venv/bin/python failed: No such file
or directory' (#389).

Move HOME to /home/byparr and apply the OpenShift permission pattern
(owner uid 1000, group 0, group=user) so both the default user and
arbitrary-UID runtimes (docker run --user, OpenShift) can write to it.
Apply the same pattern to /cache, where invisible_playwright keeps
runtime browser/profile data and which arbitrary UIDs previously could
not write.

Fixes #389
This commit is contained in:
ThePhaseless
2026-08-10 23:40:16 +02:00
parent aa7bfee7bb
commit c38a6f4e85
+4 -4
View File
@@ -12,7 +12,7 @@ ENV GITHUB_BUILD=${GITHUB_BUILD}\
UV_LINK_MODE=copy \
PORT=8191 \
XDG_CACHE_HOME=/cache \
HOME=/tmp
HOME=/home/byparr
RUN apt-get update &&\
apt-get install -y --no-install-recommends curl ca-certificates git tini &&\
@@ -44,9 +44,9 @@ RUN mkdir -p /cache &&\
COPY . .
# Make app and cache world-readable; cache must be writable for runtime browser/profile data
RUN chmod -R o+rX /app /cache &&\
chmod -R o+w /cache
RUN mkdir -p /home/byparr &&\
chmod -R o+rX /app &&\
chmod -R a+rwX /cache /home/byparr
FROM app AS test
RUN \