Directories belong to the number that runs inside
The lab named both failures in one run: the store restarted forever on a conf file it could not read, and the forge could not traverse into the directory that held its files. Both are the same fault — a file the mesh declares root-owned, consumed by a container process that dropped to a uid the machine has never heard of. The forge's data now belongs to 1000, the user its container runs as. The store's conf, ACL file and data belong to 999, which is what redis becomes after its entrypoint drops privileges. The package registry's conf directory belongs to 10001, which writes htpasswd into it. Made expressible by the host in the commit beside this one: an owner may be numeric, because a container's user has no name on the machine.
This commit is contained in:
@@ -47,21 +47,24 @@
|
||||
"id": "data",
|
||||
"type": "directory",
|
||||
"path": "/services/redis/data",
|
||||
"mode": "0700"
|
||||
"mode": "0700",
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "server-conf",
|
||||
"type": "file",
|
||||
"path": "/var/lib/redis-module/redis.conf",
|
||||
"mode": "0600",
|
||||
"content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n"
|
||||
"content": "requirepass ${secret:default}\naclfile /data/users.acl\nappendonly yes\ndir /data\n",
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "acl-seed",
|
||||
"type": "file",
|
||||
"path": "/services/redis/data/users.acl",
|
||||
"mode": "0600",
|
||||
"content": ""
|
||||
"content": "",
|
||||
"owner": "999:999"
|
||||
},
|
||||
{
|
||||
"id": "net",
|
||||
|
||||
Reference in New Issue
Block a user