fix(docker): fix data volume ownership on fresh bind mounts

/app/data is a bind mount, so the chown baked into the image is
overwritten by the host directory's ownership at runtime. On a fresh
prod deploy Docker creates ./data as root-owned, but the container ran
as the non-root nextjs user, so Prisma couldn't open lovelope.db
("unable to open database file").

Add an entrypoint that starts as root, chowns /app/data, then drops to
nextjs via su-exec before running migrations and starting the server.
This commit is contained in:
2026-07-30 16:40:45 +02:00
parent cd36fc5723
commit 75ea9b7416
2 changed files with 10 additions and 4 deletions
+4 -4
View File
@@ -28,7 +28,7 @@ RUN npm run build
# ── Stage 3: runner ──────────────────────────────────────────────────────────── # ── Stage 3: runner ────────────────────────────────────────────────────────────
FROM node:20-alpine AS runner FROM node:20-alpine AS runner
RUN apk add --no-cache libc6-compat openssl RUN apk add --no-cache libc6-compat openssl su-exec
WORKDIR /app WORKDIR /app
ENV NODE_ENV=production ENV NODE_ENV=production
@@ -48,11 +48,11 @@ COPY --from=builder --chown=nextjs:nodejs /app/.next/static ./.next/static
RUN mkdir -p /app/data && chown nextjs:nodejs /app/data RUN mkdir -p /app/data && chown nextjs:nodejs /app/data
USER nextjs COPY --chmod=755 docker-entrypoint.sh ./docker-entrypoint.sh
EXPOSE 3000 EXPOSE 3000
ENV PORT=3000 ENV PORT=3000
ENV HOSTNAME="0.0.0.0" ENV HOSTNAME="0.0.0.0"
# Run migrations then start the server # Fix ownership of the bind-mounted /app/data volume, then drop to nextjs
CMD ["sh", "-c", "npx prisma migrate deploy && node server.js"] ENTRYPOINT ["./docker-entrypoint.sh"]
+6
View File
@@ -0,0 +1,6 @@
#!/bin/sh
set -e
chown -R nextjs:nodejs /app/data
exec su-exec nextjs sh -c "npx prisma migrate deploy && node server.js"