fix: [outline] align datastore ownership with the application user

Outline runs as an unprivileged user in the image (``nodejs`` since
1.10.0, ``root`` up to 1.6.1) while the datastore is provisioned by
``root``.  Without realignment the application cannot write its
``uploads``, ``public`` and ``avatars`` buckets, so every attachment
upload fails with "Permission denied writing to ... Check the host
machine file system permissions".  This was seen on elabore.coop
after the 1.6.1 to 1.10.0 upgrade.

The ``init`` hook now reads the image's ``Config.User`` and chowns the
datastore to that user, skipping root-based images.  It is idempotent
and version-agnostic: the realignment also covers buckets added by
future Outline versions.
This commit is contained in:
Stéphan Sainléger
2026-09-16 23:43:01 +02:00
parent 9947900389
commit fda96565ad
2 changed files with 54 additions and 0 deletions

View File

@@ -71,4 +71,42 @@ $SERVICE_NAME:
#DEBUG: \"http\"
"
## The datastore is bind-mounted into the container. Outline runs as
## an unprivileged user (image Config.User: root up to 1.6.1, "nodejs"
## since 1.10.0) and must write its uploads, public and avatars
## buckets. Provisioned by root, the datastore is not writable by
## that user and every upload fails with "Permission denied writing
## to ... Check the host machine file system permissions". Align the
## datastore ownership with the image user; skip images running as
## root. See README.org, "Datastore ownership alignment".
app_user=
if [ -n "$DOCKER_BASE_IMAGE" ]; then
app_user=$(docker image inspect "$DOCKER_BASE_IMAGE" \
--format '{{.Config.User}}') || exit 1
fi
case "$app_user" in
""|0|0:0|root)
## image runs as root: nothing to align
;;
*:*)
uid="${app_user%%:*}"
gid="${app_user#*:}"
;;
*)
uid_gid=($(docker_get_uid_gid "$SERVICE_NAME" "$app_user" "$app_user")) || exit 1
uid="${uid_gid[0]}"
gid="${uid_gid[1]}"
;;
esac
if [ -n "${uid:-}" ]; then
mkdir -p "$SERVICE_DATASTORE"
chown -R "$uid:$gid" "$SERVICE_DATASTORE" || {
err "Failed to align datastore ownership on '$uid:$gid'."
exit 1
}
info "Datastore ownership aligned on '$uid:$gid'."
fi