diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile index 9371d75..a0fc42b 100644 --- a/modules/postgres/Dockerfile +++ b/modules/postgres/Dockerfile @@ -22,6 +22,13 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/ind --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist FROM ${RUNTIME_BASE} +# **This module talks to its database through psql, so psql has to be here.** The client is how +# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only +# what every module needs. Root to install it, then back to the base's unprivileged user: a +# provisioner holding the superuser password has no business also being root in its container. +USER root +RUN apk add --no-cache postgresql-client +USER node COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist # What a tool host should load from this module: its event consumer and its tools, which are # separate entrypoints because they are loaded by different things. The provisioner is the third,