blumeops/docs/changelog.d
Erich Blume 678f26b0e7 C0: fix homepage container /app/config write permissions
The previous Dockerfile chowned /app/config to 1000:1000 so the runtime
user could seed missing skeleton configs (e.g. proxmox.yaml) and write
/app/config/logs. The nix derivation didn't replicate that, so the new
amd64 image crashed with EACCES on cold start (fixed-forward — caught
during ringtail cutover, ArgoCD #348).

Add fakeRootCommands to dockerTools to create /app and /app/config and
chown them at build time. The deployment's ConfigMap subPath mounts
leave the parent directory as image filesystem, so its ownership has to
be set at build time, not at runtime.
2026-05-10 20:49:22 -07:00
..
+agent-file-neutralization.ai.md
+alloy-main-sha-rebuild.infra.md
+alloy-native-macos-v1.16.0.infra.md
+argocd-resource-limits.infra.md
+blumeops-tasks-due-recurrence.feature.md
+claude-md-import-agents.ai.md
+compliance-mute-categories.doc.md C0: docs — explanation article on compliance mute categories 2026-05-04 18:19:53 -07:00
+container-build-suggest-runner-logs.misc.md
+fix-forge-static-assets.bugfix.md
+frigate-notify-local.infra.md
+homepage-config-perms-fix.bugfix.md C0: fix homepage container /app/config write permissions 2026-05-10 20:49:22 -07:00
+prowler-rebuild-on-main.infra.md
+remove-devpi-container-build.misc.md
+review-cc-ephemeral-privileged-jobs.misc.md
+review-cc-init-container-isolation.misc.md C0: review CC init-container-isolation — defer retirement to post-ringtail 2026-05-04 18:31:13 -07:00
+review-cc-trusted-ci-only.misc.md
+review-compliance-image-iac.feature.md
+review-contributing-doc.doc.md
+review-index-doc.doc.md C0: doc review — index.md, add ringtail to infra overview 2026-05-06 06:14:40 -07:00
+review-navidrome-doc.doc.md
+review-ollama-doc.doc.md
+ringtail-sway-fuzzel.bugfix.md
+rotate-fly-deploy-token-shell-examples.doc.md C0: rotate-fly-deploy-token — fish+bash one-shot, op validator gotcha 2026-05-04 13:42:57 -07:00
+runner-logs-auth.feature.md
+tailscale-main-sha-rebuild.infra.md C0: tailscale main-SHA rebuild for ringtail proxyclass 2026-05-06 06:52:39 -07:00
+transmission-doc-review.doc.md
+valkey-main-tag-bump.infra.md C0: valkey — bump kustomization tags to main-branch SHA 2026-05-01 17:47:16 -07:00
+zot-v2.1.16.infra.md C0: zot — upgrade indri registry to v2.1.16 2026-05-04 17:41:07 -07:00
.gitkeep
alloy-v1.16.0.infra.md
cleanup-cv-docs-minikube-artifacts.misc.md
dagger-0-20-6-runner-image-alpine.infra.md
forgejo-runner-v12-8-server-connections.infra.md
homepage-to-ringtail.infra.md C1: migrate homepage dashboard to ringtail k3s 2026-05-10 20:37:03 -07:00
migrate-cv-docs-to-indri.infra.md
migrate-devpi-to-indri.infra.md
mirror-tailscale-container.infra.md C1: mirror tailscale container locally for ringtail proxyclass (#347) 2026-05-06 06:50:31 -07:00
prowler-iac-mutelist.infra.md
update-tooling-deps-2026-04.doc.md
update-tooling-deps-2026-04.infra.md
valkey-mirror.infra.md