From 01238ae5f78dfb9fdf50a069f23205067dcbd165 Mon Sep 17 00:00:00 2001 From: Joseph Hale Date: Tue, 17 Feb 2026 16:39:59 -0700 Subject: [PATCH] Replace dcron with supercronic for non-root cron support The container was failing to start on Ubuntu with Permission denied when trying to launch crond, because the container runs as the nginx user (non-root) and dcron requires root privileges. Key Decisions: - Supercronic over a sleep loop to preserve full cron expression support - Supercronic over sudo because sudo defeats non-root security model - Grouped crontab setup with supercronic startup for better code organization Supercronic was chosen because it's designed specifically for containers, runs without root, handles signals gracefully, and adds only ~2MB to image. --- Dockerfile | 11 +++++++++-- entrypoint.sh | 24 ++++++++++-------------- 2 files changed, 19 insertions(+), 16 deletions(-) diff --git a/Dockerfile b/Dockerfile index 5616726..e1ee212 100644 --- a/Dockerfile +++ b/Dockerfile @@ -9,8 +9,15 @@ RUN apk add --no-cache \ bash \ jq \ coreutils \ - bc \ - dcron + bc + +# Install Supercronic (cron for containers) +ENV SUPERCRONIC_URL=https://github.com/aptible/supercronic/releases/download/v0.2.43/supercronic-linux-amd64 \ + SUPERCRONIC_SHA1SUM=f97b92132b61a8f827c3faf67106dc0e4467ccf2 +RUN curl -fsSLO "$SUPERCRONIC_URL" \ + && echo "${SUPERCRONIC_SHA1SUM} supercronic-linux-amd64" | sha1sum -c - \ + && chmod +x supercronic-linux-amd64 \ + && mv supercronic-linux-amd64 /usr/local/bin/supercronic # Install Ookla Speedtest CLI RUN ARCH=$(uname -m) && \ diff --git a/entrypoint.sh b/entrypoint.sh index 500c017..33e5c4b 100644 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -6,17 +6,6 @@ export HOME=${HOME:-/tmp} mkdir -p "$HOME/.config/ookla" cp "$HOME/speedtest-cli.json" "$HOME/.config/ookla/" -# Setup cron job -CRON_SCHEDULE="${CRON_SCHEDULE:-*/30 * * * *}" -echo "Setting up speedtest cron job with schedule: $CRON_SCHEDULE" - -# Create crontab file for current user -mkdir -p /tmp/crontabs -echo "$CRON_SCHEDULE /app/speedtest_runner.sh >> $HOME/speedtest.log 2>&1" > /tmp/crontabs/speedtest - -# Create log file -touch "$HOME/speedtest.log" - # Generate initial HTML page (before nginx starts) /app/generate_html.sh @@ -27,6 +16,13 @@ NGINX_PID=$! # Run initial speedtest /app/speedtest_runner.sh -# Start cron in foreground (using busybox crond with user crontab) -echo "Starting cron daemon..." -crond -f -l 8 -L "$HOME/cron.log" -c /tmp/crontabs +# Setup and start supercronic (cron for containers, runs as non-root) +CRON_SCHEDULE="${CRON_SCHEDULE:-*/30 * * * *}" +echo "Setting up speedtest cron job with schedule: $CRON_SCHEDULE" + +mkdir -p /tmp/crontabs +echo "$CRON_SCHEDULE /app/speedtest_runner.sh >> $HOME/speedtest.log 2>&1" > /tmp/crontabs/speedtest +touch "$HOME/speedtest.log" + +echo "Starting supercronic..." +exec supercronic -passthrough-logs /tmp/crontabs/speedtest -- 2.51.2