Bound the one log squid's Docker log cap does not reach
squid writes access.log and cache.log to files, not to stdout - the previous commit already explains why - which puts them entirely outside the json-file driver's max-size the rest of the stack just got. Left alone they grow forever on the one service in this file without read_only: true. Bounded the same way /tmp is bounded elsewhere: a size-capped tmpfs, lost on restart rather than kept and unbounded. Needs uid/gid=13 because squid drops to its own "proxy" user before opening these files, and a tmpfs mount point defaults to root-owned like any other - which failed loudly the first time, with squid's own answer to an unopenable log being fatal rather than a quieter fallback. Compose's long tmpfs syntax has no field for that, so this uses the raw mount-options string the top-level tmpfs: list already uses elsewhere in this file. Verified under compose itself, not a bare docker run: no errors at start, and the log files it creates are owned by proxy:proxy as expected. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
15a8fd3d0d
commit
44ca1c5435
|
|
@ -132,6 +132,16 @@ services:
|
||||||
source: ./egress-proxy.squid.conf
|
source: ./egress-proxy.squid.conf
|
||||||
target: /etc/squid/squid.conf
|
target: /etc/squid/squid.conf
|
||||||
read_only: true
|
read_only: true
|
||||||
|
# This is the one service without read_only: true, because squid needs somewhere to write
|
||||||
|
# access.log and cache.log - and unlike Docker's own logging driver above, squid never rotates
|
||||||
|
# those on its own. Bounded here at the container level, the same as /tmp elsewhere in this
|
||||||
|
# file: capped and lost on restart beats unbounded and kept.
|
||||||
|
#
|
||||||
|
# uid/gid=13 is squid's own "proxy" user inside this image, which it drops to before it ever
|
||||||
|
# opens these files. Compose's long tmpfs syntax has no uid/gid field, so this needs the raw
|
||||||
|
# mount-options string the top-level tmpfs: list passes straight through to Docker.
|
||||||
|
tmpfs:
|
||||||
|
- /var/log/squid:rw,size=64m,uid=13,gid=13
|
||||||
cap_drop: [ALL]
|
cap_drop: [ALL]
|
||||||
cap_add: [SETUID, SETGID]
|
cap_add: [SETUID, SETGID]
|
||||||
security_opt: [no-new-privileges:true]
|
security_opt: [no-new-privileges:true]
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue