mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-11 03:13:16 +00:00
Drop the history and roadmap asides: which services predate the collection's
conventions, the unwired Open Web UI plan, the generic clone-and-troubleshoot
boilerplate. Services that publish ports or set `restart:` now simply say so.
couchbase, openvpn-as and traffmonetizer had two-line READMEs; give them the
ports, variables and storage the root README promises. traffmonetizer reads
${TOKEN} and had no .env.example, so add one.
21 lines
945 B
Bash
Executable File
21 lines
945 B
Bash
Executable File
#!/usr/bin/env bash
|
|
# Sets the paseo user's login password from PASEO_PASSWORD, then hands off to
|
|
# the image's own entrypoint.
|
|
#
|
|
# At start rather than at build, so the password never lands in a layer. Here
|
|
# rather than after the base entrypoint, which ends in `exec gosu paseo` and so
|
|
# never returns, and by then is no longer root. Every start, because
|
|
# /etc/shadow is in the image, not the /home/paseo volume, and reverts on each
|
|
# container recreate.
|
|
set -euo pipefail
|
|
|
|
if [[ "$(id -u)" == "0" && -n "${PASEO_PASSWORD:-}" ]]; then
|
|
# Piped rather than passed as an argument: arguments are visible in ps.
|
|
# chpasswd splits on the first colon, so a colon in the password is fine.
|
|
printf 'paseo:%s\n' "$PASEO_PASSWORD" | chpasswd
|
|
fi
|
|
|
|
# With PASEO_PASSWORD unset the account keeps its locked password and sudo just
|
|
# refuses. The base entrypoint already warns about the missing variable.
|
|
exec /usr/local/bin/paseo-docker-entrypoint "$@"
|