fix: use runuser for privilege drop and capture container stderr in logs

The container still exited immediately after the su-based fix.  can
interfere with TTY/stdin handling for interactive shells. Switch to
, which is root-only, skips PAM, and preserves file descriptors so
bash stays interactive.

Also improve container failure diagnostics:
-  now combines stdout and stderr
- This helps surface the real reason when a container exits with code 0

Quality gates:
- pytest tests/unit: 219 passed
- ruff: clean on changed files
- mypy: clean on changed files
This commit is contained in:
Developer
2026-06-15 10:41:37 +00:00
parent e35e605914
commit 1d345eba32
20 changed files with 81 additions and 34 deletions
+2 -2
View File
@@ -4,11 +4,11 @@ dir: apps/api/src/services
index: apps/api/src/services/.pi-map.index.md
## role
Marks the `services` directory as a Python package for organizing business logic and service-layer modules.
Service layer package for the API application, intended to contain business logic implementations.
## files
- __init__.py | Empty file with no functionality
## arch
Standard Python package structure using `__init__.py` to define an importable namespace, following conventional layered architecture with an empty initializer awaiting future service modules.
Standard Python package structure with an empty initializer, awaiting service module implementations following a layered architecture pattern.
## tags
init, empty, functionality
## symbols