fix: resolve Docker volume permission denied on startup
Root cause: Docker named volumes are created as root, but the container ran as the unprivileged 'oxicloud' user (UID 1001). Services like thumbnail_service, image_transcode, and dedup_service call create_dir_all under /app/storage during initialization, which fails with 'Permission denied (os error 13)'. Changes: - Add entrypoint.sh that runs as root to chown /app/storage, then drops privileges via su-exec before executing the application - Update Dockerfile to install su-exec, copy entrypoint, and use ENTRYPOINT instead of USER+CMD - Downgrade id_mapping_service initial write failure from ERROR to WARN (empty in-memory map is perfectly valid, will persist on next save) - Improve panic message in main.rs to hint at Docker permission issue Fixes #<issue>
This commit is contained in:
@@ -181,11 +181,11 @@ impl IdMappingService {
|
||||
}
|
||||
}
|
||||
|
||||
// Write empty map to file
|
||||
// Write empty map to file (best-effort: the in-memory map is valid even if disk write fails)
|
||||
match serde_json::to_string_pretty(&empty_map) {
|
||||
Ok(json) => {
|
||||
if let Err(e) = fs::write(map_path, json).await {
|
||||
tracing::error!("Failed to write initial empty ID map: {}", e);
|
||||
tracing::warn!("Could not write initial empty ID map (will retry on next save): {}", e);
|
||||
} else {
|
||||
tracing::info!("Created initial empty ID map at {}", map_path.display());
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user