From 649ce9bc3b5cab968c377197cfe59ad9ba0ea1b4 Mon Sep 17 00:00:00 2001 From: jochen Date: Tue, 1 Sep 2026 23:45:17 +0200 Subject: [PATCH] Directories belong to the number that runs inside MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The lab named both failures in one run: the store restarted forever on a conf file it could not read, and the forge could not traverse into the directory that held its files. Both are the same fault — a file the mesh declares root-owned, consumed by a container process that dropped to a uid the machine has never heard of. The forge's data now belongs to 1000, the user its container runs as. The store's conf, ACL file and data belong to 999, which is what redis becomes after its entrypoint drops privileges. The package registry's conf directory belongs to 10001, which writes htpasswd into it. Made expressible by the host in the commit beside this one: an owner may be numeric, because a container's user has no name on the machine. --- examples/modules/gitea.json | 3 ++- examples/modules/redis.json | 9 ++++++--- examples/modules/verdaccio.json | 3 ++- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/examples/modules/gitea.json b/examples/modules/gitea.json index c307925..feb28b8 100644 --- a/examples/modules/gitea.json +++ b/examples/modules/gitea.json @@ -53,7 +53,8 @@ "id": "data", "type": "directory", "path": "/services/gitea/gitea", - "mode": "0700" + "mode": "0700", + "owner": "1000:1000" }, { "id": "server", diff --git a/examples/modules/redis.json b/examples/modules/redis.json index 1659609..74045d9 100644 --- a/examples/modules/redis.json +++ b/examples/modules/redis.json @@ -47,21 +47,24 @@ "id": "data", "type": "directory", "path": "/services/redis/data", - "mode": "0700" + "mode": "0700", + "owner": "999:999" }, { "id": "server-conf", "type": "file", "path": "/var/lib/redis-module/redis.conf", "mode": "0600", - "content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n" + "content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n", + "owner": "999:999" }, { "id": "acl-seed", "type": "file", "path": "/services/redis/data/users.acl", "mode": "0600", - "content": "" + "content": "", + "owner": "999:999" }, { "id": "net", diff --git a/examples/modules/verdaccio.json b/examples/modules/verdaccio.json index 2acf0df..34196f2 100644 --- a/examples/modules/verdaccio.json +++ b/examples/modules/verdaccio.json @@ -17,7 +17,8 @@ "id": "conf", "type": "directory", "path": "/services/verdaccio/conf", - "mode": "0755" + "mode": "0755", + "owner": "10001:10001" }, { "id": "storage",