diff --git a/docker-compose.yml b/docker-compose.yml index 27334fa..5ea14ef 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -133,13 +133,6 @@ services: stoic: image: ghcr.io/lexx27/stoic:latest - # Runs as root — the app container's entrypoint.sh chowns the whole - # storage/ tree to www-data on every boot (docker/entrypoint.sh), - # and Stoic's own image user isn't www-data or in its group, so it - # can't write thumbnails into storage/app/public/stoic/ otherwise - # (libvips reports this as "Failed to write VipsImage to file"). - # Same fix already applied in docker-compose.dev.yml. - user: root ports: - "127.0.0.1:${STOIC_PORT:-2727}:2727" environment: diff --git a/docker/entrypoint.sh b/docker/entrypoint.sh index 3dee436..3e4697d 100644 --- a/docker/entrypoint.sh +++ b/docker/entrypoint.sh @@ -27,6 +27,14 @@ mkdir -p storage/app/public storage/framework/cache storage/framework/sessions s chown -R www-data:www-data storage bootstrap/cache chmod -R 775 storage bootstrap/cache +# The stoic container writes thumbnails directly into this shared storage +# volume (see docker/stoic/stoic_config.yml's thumbs_path) as its own +# image user, which is neither www-data nor in its group — the chown/chmod +# above alone would lock it out. Scoped to just this one directory rather +# than opening up all of storage/ to every user. +mkdir -p storage/app/public/stoic +chmod 777 storage/app/public/stoic + # Composer packages (dev) may have just changed above, or (production) this is a # freshly built image — either way, clear any cached config/routes/compiled views # left over from a previous boot before anything below reads them. Production