fix: use runuser for privilege drop and capture container stderr in logs

The container still exited immediately after the su-based fix.  can
interfere with TTY/stdin handling for interactive shells. Switch to
, which is root-only, skips PAM, and preserves file descriptors so
bash stays interactive.

Also improve container failure diagnostics:
-  now combines stdout and stderr
- This helps surface the real reason when a container exits with code 0

Quality gates:
- pytest tests/unit: 219 passed
- ruff: clean on changed files
- mypy: clean on changed files
This commit is contained in:
Developer
2026-06-15 10:41:37 +00:00
parent e35e605914
commit 1d345eba32
20 changed files with 81 additions and 34 deletions
+2 -2
View File
@@ -4,10 +4,10 @@ dir: apps
index: apps/.pi-map.index.md
## role
Contains the main deployable application modules that compose the project's executable entry points.
Contains the main deployable application modules and entry points for the project.
## files
## arch
Modular monolith or microservices architecture where each subdirectory represents an independent application with its own configuration, dependencies, and lifecycle.
Follows a modular app structure where each subdirectory is an independent application with its own configuration, dependencies, and build setup, typically using a monorepo pattern with shared libraries.
## tags
-
## symbols