Slackbot
01/08/2024, 9:43 PMGabor Maghera
01/08/2024, 9:54 PMls -lad on /home/atlantis/ and /home/atlantis/.atlantis and then look at the process table to see which user owns the atlantis process.
I’ve only read the readme on the recent permission changes, but my hunch is that a temporary directory was created inside the image with one user, and now you’re trying to put subdirectories and files under it with another. If that’s the case, starting over with a fresh container or chown against one of those two directories should fix it.Evey Eve
01/08/2024, 10:19 PMwhoami (forced the pod to stay alive).Evey Eve
01/08/2024, 10:27 PMRB
01/09/2024, 1:05 AMUSER root in your docker container but it’s not recommended to run as rootEvey Eve
01/09/2024, 2:56 PMVinicius Oliveira
01/09/2024, 3:10 PMFROM <http://ghcr.io/runatlantis/atlantis:v0.27.0|ghcr.io/runatlantis/atlantis:v0.27.0>
USER root
COPY generator/requirements.txt /tmp/
COPY generator/generator.py /usr/local/bin/
ENV VIRTUAL_ENV=/opt/venv
RUN apk add --no-cache python3 py3-pip
RUN python3 -m venv $VIRTUAL_ENV
ENV PATH="$VIRTUAL_ENV/bin:$PATH"
RUN pip install -r /tmp/requirements.txt
USER atlantis
Not sure if you need to force the UID on your deployment, but this should be enough to make sure the user running in the image to be atlantisEvey Eve
01/09/2024, 7:46 PMRB
01/09/2024, 7:48 PMFROM <http://ghcr.io/runatlantis/atlantis:v0.27.0|ghcr.io/runatlantis/atlantis:v0.27.0>
USER root
# .. anything ...
USER atlantisEvey Eve
01/09/2024, 7:49 PMFROM <http://ghcr.io/runatlantis/atlantis:v0.27.0|ghcr.io/runatlantis/atlantis:v0.27.0>
COPY . /app
WORKDIR /app
USER 0
RUN chown -R atlantis:root /home/atlantis; \
chmod 770 /home/atlantis;
USER 1001
CMD ["/bin/bash", "docker-entrypoint.sh"]
``````RB
01/09/2024, 7:49 PMRB
01/09/2024, 7:49 PMEvey Eve
01/09/2024, 7:50 PMRB
01/09/2024, 7:50 PMVinicius Oliveira
01/09/2024, 7:58 PMEvey Eve
01/09/2024, 8:00 PMUSER 1001 to USER atlantis but thanks ran into issues. Thanks to @Gabor Maghera we discovered while in the container (we forced it to stay alive after deployment) that we were running as user 100905000. We can't change this, we can't configure the OCP deployments fully (enterprise restrictions). Luckily with the details of how the pod was running and who owned what, groups, etc. we were able to find the solution aboveEvey Eve
01/09/2024, 8:01 PMUSER 0 and USER 1001. Newbies such as me and those unfamiliar with Docker and OCP will follow what's given. So will the other software devs.RB
01/09/2024, 8:02 PMEvey Eve
01/09/2024, 8:03 PMrootRB
01/09/2024, 8:07 PMRB
01/09/2024, 8:08 PMHans Lambermont
01/15/2024, 4:34 PMRB
01/15/2024, 4:51 PM