Skip to content

Conversation

@cdoyle-temple
Copy link
Member

Dockerfile: Runs during image build (no environment variables available)
Entrypoint: Runs when container starts (environment variables available)

mkdir -p /secure-tmp && chmod 700 /secure-tmp && \
mkdir -p /secure-tmp/log && chmod 700 /secure-tmp/log && \
rails users:sync_initial
mkdir -p /secure-tmp/log && chmod 700 /secure-tmp/log
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

if /secure-tmp/ is a volume mount then I think it makes more sense to move creating this direcotry in the entrypoint script because that happens after the container and volumes are mounted vs. here where volumens are not mounted yet.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@dkinzer This is following a pattern that we have moved to in our other Kubernetes applications. This setup replaces the setup-tmp-dir initContainer that we used to have in our projects. This needs to exist before the containers start to spin up because the tmp directory needs to exist in order for the db-migrate init container to successfully run.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sensei100 I'd like for all of us to do a zoom together to test this because i'm still confused how this could be working.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't really want to do a zoom on a Friday afternoon, but we can look at it together on Monday. This is fully working in Tupress and centralized metadata right now if you want to look at where projects where it has already been implemented.

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CM is working inspite of these changes not because of it. If you look inside cm container there is no /secure-tmp/log folder even though it gets created in Dockerfile.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After a team discussion, we agreed to move the secure-tmp/log line into the entry point.sh file.

@cdoyle-temple cdoyle-temple requested a review from dkinzer October 29, 2025 17:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants