Fix MySQL init script: executable bit + scope shell options in subshell
Without the exec bit the MySQL entrypoint sources the script instead of executing it, leaking set -euo pipefail into MySQL's own startup shell and aborting first-time initialization (container exits -> unhealthy -> compose dependency failure). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
23
db/init/01-powerbi-user.sh
Normal file → Executable file
23
db/init/01-powerbi-user.sh
Normal file → Executable file
@@ -6,19 +6,24 @@
|
|||||||
# grants below take effect as soon as Alembic creates the reporting views.
|
# grants below take effect as soon as Alembic creates the reporting views.
|
||||||
# For an already-initialized database, run scripts/powerbi_grants.sql instead
|
# For an already-initialized database, run scripts/powerbi_grants.sql instead
|
||||||
# (see README → "Power BI").
|
# (see README → "Power BI").
|
||||||
set -euo pipefail
|
#
|
||||||
|
# NOTE: this file must stay executable (git mode 100755). The MySQL image
|
||||||
|
# *sources* non-executable init scripts into its own entrypoint shell, where
|
||||||
|
# stray `set` options can break MySQL's startup. The subshell below keeps
|
||||||
|
# everything scoped even if that happens.
|
||||||
|
(
|
||||||
|
set -e
|
||||||
|
|
||||||
if [ -z "${POWERBI_RO_PASSWORD:-}" ]; then
|
if [ -z "${POWERBI_RO_PASSWORD:-}" ]; then
|
||||||
echo "[init] POWERBI_RO_PASSWORD not set - skipping powerbi_ro user creation."
|
echo "[init] POWERBI_RO_PASSWORD not set - skipping powerbi_ro user creation."
|
||||||
exit 0
|
else
|
||||||
fi
|
mysql -u root -p"${MYSQL_ROOT_PASSWORD}" <<SQL
|
||||||
|
|
||||||
mysql -u root -p"${MYSQL_ROOT_PASSWORD}" <<SQL
|
|
||||||
CREATE USER IF NOT EXISTS 'powerbi_ro'@'%' IDENTIFIED BY '${POWERBI_RO_PASSWORD}';
|
CREATE USER IF NOT EXISTS 'powerbi_ro'@'%' IDENTIFIED BY '${POWERBI_RO_PASSWORD}';
|
||||||
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_full\` TO 'powerbi_ro'@'%';
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_full\` TO 'powerbi_ro'@'%';
|
||||||
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_stage_history\` TO 'powerbi_ro'@'%';
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_stage_history\` TO 'powerbi_ro'@'%';
|
||||||
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_costs\` TO 'powerbi_ro'@'%';
|
GRANT SELECT ON \`${MYSQL_DATABASE}\`.\`vw_ncr_costs\` TO 'powerbi_ro'@'%';
|
||||||
FLUSH PRIVILEGES;
|
FLUSH PRIVILEGES;
|
||||||
SQL
|
SQL
|
||||||
|
echo "[init] powerbi_ro user created with SELECT on reporting views."
|
||||||
echo "[init] powerbi_ro user created with SELECT on reporting views."
|
fi
|
||||||
|
)
|
||||||
|
|||||||
Reference in New Issue
Block a user