diff --git a/Dockerfile b/Dockerfile index f20d98f5..22bac201 100644 --- a/Dockerfile +++ b/Dockerfile @@ -133,6 +133,11 @@ RUN apk --update --no-cache add -t build-dependencies \ && echo "foreach (glob(\"${LIBRENMS_PATH}/config.d/*.php\") as \$filename) include \$filename;" >> config.php \ && chown -R librenms:librenms ${LIBRENMS_PATH} \ && su librenms -s /bin/sh -c "COMPOSER_CACHE_DIR=/tmp composer install --no-dev --no-interaction --no-ansi" \ + # vendor and composer files are only written by plugin/composer installs, and the container + # commonly runs under a custom PUID/PGID - the runtime permission fix intentionally skips + # them for that reason (https://github.com/librenms/docker/issues/557), so make them writable here + && chmod -R a+rwX vendor \ + && chmod a+rw composer.json composer.lock \ && apk del build-dependencies \ && rm -rf .git \ html/plugins/Test \ diff --git a/rootfs/etc/cont-init.d/03-config.sh b/rootfs/etc/cont-init.d/03-config.sh index 5b02a259..82358605 100644 --- a/rootfs/etc/cont-init.d/03-config.sh +++ b/rootfs/etc/cont-init.d/03-config.sh @@ -217,9 +217,12 @@ for plugin in ${plugins}; do done # Fix perms +# the vendor tree and composer files are not chowned below: chowning the ~13k vendor files +# delays every start with custom PUID/PGID (https://github.com/librenms/docker/issues/557) and +# is only needed for plugin/composer installs, for which the image build sets write permissions echo "Fixing perms..." chown librenms:librenms /data/config /data/monitoring-plugins /data/plugins /data/rrd /data/weathermap /data/alert-templates -find /data/logs ${LIBRENMS_PATH}/composer* ${LIBRENMS_PATH}/config.d ${LIBRENMS_PATH}/bootstrap ${LIBRENMS_PATH}/logs ${LIBRENMS_PATH}/storage ${LIBRENMS_PATH}/vendor \( ! -user librenms -o ! -group librenms \) -exec chown librenms:librenms {} + +find /data/logs ${LIBRENMS_PATH}/config.d ${LIBRENMS_PATH}/bootstrap ${LIBRENMS_PATH}/logs ${LIBRENMS_PATH}/storage \( ! -user librenms -o ! -group librenms \) -exec chown librenms:librenms {} + chmod ug+rw /data/logs /data/rrd ${LIBRENMS_PATH}/bootstrap/cache ${LIBRENMS_PATH}/storage ${LIBRENMS_PATH}/storage/framework/* # Check additional Monitoring plugins