fix: [outline] align datastore ownership with the application user

Outline runs as an unprivileged user in the image (``nodejs`` since
1.10.0, ``root`` up to 1.6.1) while the datastore is provisioned by
``root``.  Without realignment the application cannot write its
``uploads``, ``public`` and ``avatars`` buckets, so every attachment
upload fails with "Permission denied writing to ... Check the host
machine file system permissions".  This was seen on elabore.coop
after the 1.6.1 to 1.10.0 upgrade.

The ``init`` hook now reads the image's ``Config.User`` and chowns the
datastore to that user, skipping root-based images.  It is idempotent
and version-agnostic: the realignment also covers buckets added by
future Outline versions.
This commit is contained in:
Stéphan Sainléger
2026-09-16 23:43:01 +02:00
parent 9947900389
commit fda96565ad
2 changed files with 54 additions and 0 deletions

View File

@@ -64,6 +64,22 @@ there is no drift, and blocks the deployment (=exit 1=) if the
realignment fails, so the problem is visible at deploy time instead
of as a cryptic crash-loop.
* Datastore ownership alignment
The =init= hook aligns the ownership of the service datastore with
the user the Outline container runs as. Since 1.10.0 the image runs
as the unprivileged =nodejs= user (older images, up to 1.6.1, ran as
=root=), while the datastore is provisioned by =root=. Without
realignment the application cannot write its =uploads=, =public= and
=avatars= buckets and every attachment upload fails with "Permission
denied writing to ... Check the host machine file system
permissions". This was seen on 2026-09-11 on elabore.coop after the
1.6.1 to 1.10.0 upgrade, on every existing datastore.
The hook reads the user from the image's =Config.User=, so it stays
version-agnostic: images running as =root= are left untouched, and
re-running the hook on an already aligned datastore is a no-op.
* Building a new image
We use the official image with an added patch due to 2 bugs: