--allow-root was routing around wp-cli's own safety check rather than addressing why root was there in the first place: docker exec defaults to the container's root user because the image never sets a non-root user for exec sessions — it was never about the actual web-facing attack surface, which already runs as www-data (verified: php-fpm's worker processes, the ones executing plugin/theme code for real requests, run as uid 33, not root; only our own deliberate admin commands were root). wp-config.php and the rest of wp-core are already owned by www-data (the official entrypoint sets this up), so there's no actual reason for our own commands to run as anything else. Verified: a full clean deploy and a bookstore-core wp-cli command both work identically running as www-data, no functional change, just removed an unnecessary privilege. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
38 lines
1.0 KiB
Makefile
38 lines
1.0 KiB
Makefile
ENV ?= dev
|
|
export ENVIRONMENT = $(ENV)
|
|
# DB_PASSWORD/DB_ROOT_PASSWORD are stripped from what Compose loads — they
|
|
# only flow through secrets/ now, and Compose warns "variable not set" on
|
|
# any $-shaped value in --env-file even when nothing consumes it. Rewritten
|
|
# fresh on every `make` invocation, so it can't drift from .env.$(ENV).
|
|
COMPOSE_ENV_FILE := .env.$(ENV).compose
|
|
$(shell grep -Ev '^(DB_PASSWORD|DB_ROOT_PASSWORD)=' .env.$(ENV) > $(COMPOSE_ENV_FILE) 2>/dev/null)
|
|
COMPOSE = docker compose -p bookstore-$(ENV) -f docker-compose.yml -f docker-compose.$(ENV).yml --env-file $(COMPOSE_ENV_FILE)
|
|
|
|
.PHONY: up down ps logs shell wp deploy backup
|
|
|
|
up:
|
|
$(COMPOSE) up -d --build
|
|
|
|
down:
|
|
$(COMPOSE) down
|
|
|
|
ps:
|
|
$(COMPOSE) ps
|
|
|
|
logs:
|
|
$(COMPOSE) logs -f
|
|
|
|
# add -u root yourself for one-off root debugging (installing a package, etc.)
|
|
shell:
|
|
$(COMPOSE) exec -u www-data wordpress bash
|
|
|
|
# make wp ENV=staging ARGS="plugin list"
|
|
wp:
|
|
$(COMPOSE) exec -u www-data wordpress wp $(ARGS)
|
|
|
|
deploy:
|
|
./deploy/deploy.sh $(ENV)
|
|
|
|
backup:
|
|
./deploy/backup.sh $(ENV)
|