Files
twooeyandClaude Sonnet 5 6299391f23 Run wp-cli as www-data instead of root; drop --allow-root
--allow-root was routing around wp-cli's own safety check rather than
addressing why root was there in the first place: docker exec defaults to
the container's root user because the image never sets a non-root user
for exec sessions — it was never about the actual web-facing attack
surface, which already runs as www-data (verified: php-fpm's worker
processes, the ones executing plugin/theme code for real requests, run as
uid 33, not root; only our own deliberate admin commands were root).

wp-config.php and the rest of wp-core are already owned by www-data (the
official entrypoint sets this up), so there's no actual reason for our
own commands to run as anything else. Verified: a full clean deploy and
a bookstore-core wp-cli command both work identically running as
www-data, no functional change, just removed an unnecessary privilege.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-27 13:39:19 -04:00

38 lines
1.0 KiB
Makefile

ENV ?= dev
export ENVIRONMENT = $(ENV)
# DB_PASSWORD/DB_ROOT_PASSWORD are stripped from what Compose loads — they
# only flow through secrets/ now, and Compose warns "variable not set" on
# any $-shaped value in --env-file even when nothing consumes it. Rewritten
# fresh on every `make` invocation, so it can't drift from .env.$(ENV).
COMPOSE_ENV_FILE := .env.$(ENV).compose
$(shell grep -Ev '^(DB_PASSWORD|DB_ROOT_PASSWORD)=' .env.$(ENV) > $(COMPOSE_ENV_FILE) 2>/dev/null)
COMPOSE = docker compose -p bookstore-$(ENV) -f docker-compose.yml -f docker-compose.$(ENV).yml --env-file $(COMPOSE_ENV_FILE)
.PHONY: up down ps logs shell wp deploy backup
up:
$(COMPOSE) up -d --build
down:
$(COMPOSE) down
ps:
$(COMPOSE) ps
logs:
$(COMPOSE) logs -f
# add -u root yourself for one-off root debugging (installing a package, etc.)
shell:
$(COMPOSE) exec -u www-data wordpress bash
# make wp ENV=staging ARGS="plugin list"
wp:
$(COMPOSE) exec -u www-data wordpress wp $(ARGS)
deploy:
./deploy/deploy.sh $(ENV)
backup:
./deploy/backup.sh $(ENV)