From 6ebf51d3126501c4eac958e529c5a84a7e43eb1e Mon Sep 17 00:00:00 2001 From: jochen Date: Sun, 13 Sep 2026 01:26:23 +0200 Subject: [PATCH] postgres's runtime carries the client it provisions through Its provisioner runs DDL by shelling out to psql, which the runtime base has no reason to hold. Every create failed with ENOENT and retried for ever. --- modules/postgres/Dockerfile | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/modules/postgres/Dockerfile b/modules/postgres/Dockerfile index 9371d75..a0fc42b 100644 --- a/modules/postgres/Dockerfile +++ b/modules/postgres/Dockerfile @@ -22,6 +22,13 @@ RUN node /app/node_modules/typescript/bin/tsc client.ts index.ts provisioner/ind --module NodeNext --moduleResolution NodeNext --target ES2022 --outDir dist FROM ${RUNTIME_BASE} +# **This module talks to its database through psql, so psql has to be here.** The client is how +# postgres's provisioner runs DDL — it does not carry a driver — and the runtime base holds only +# what every module needs. Root to install it, then back to the base's unprivileged user: a +# provisioner holding the superuser password has no business also being root in its container. +USER root +RUN apk add --no-cache postgresql-client +USER node COPY --from=build /app/modules/postgres/dist /app/modules/postgres/dist # What a tool host should load from this module: its event consumer and its tools, which are # separate entrypoints because they are loaded by different things. The provisioner is the third,