Hi i run into docker/sdk up problem with permissio...
# docker
s
Hi i run into docker/sdk up problem with permission issue: Copy and merge schema files UnexpectedValueException - Exception: There is no existing directory at "/var/log/spryker/DE/ZED" and its not buildable: Permission denied in /data/vendor/monolog/monolog/src/Monolog/Handler/StreamHandler.php (172) any idea to solve that quickly?
h
Hello. Try this: docker/sdk clean-data && docker/sdk up That will delete all volumes along with logs volume.
s
ok i try but this happens on different stages during build up
nope doesnt help. now it dies during propel schema copy
h
OS?
s
Ubuntu 20.04 latest docker
h
docker/sdk cli ls -al /var/log/spryker
Is it possible to run?
Is it possible to reproduce the error locally?
s
The folder inside the cli container exists but is owned by 1000:spryker and not writeable
I will investigate it later it looks like a overlay2 issue ...
h
Is that latest docker/sdk version?
s
Yes 1.15.0
I not tested version bevor, i will do that ..
h
What is the mode? deploy.ymldockermount:?
s
Ok will check ..
h
Copy code
# Create log directory
ARG SPRYKER_LOG_DIRECTORY
ENV SPRYKER_LOG_DIRECTORY=${SPRYKER_LOG_DIRECTORY}
RUN mkdir -p ${SPRYKER_LOG_DIRECTORY} && \
chown spryker:spryker ${SPRYKER_LOG_DIRECTORY}
We have this to initialize.
In baked mode user is always spryker.
In dev (mount) mode we have the following:
Copy code
ARG USER_UID
RUN usermod -u ${USER_UID} spryker && find / -user 1000 -exec chown -h spryker {} \ || true;
So I wonder why chown does not work for it. OR volume is mounted weirdly…
Can you inspect cli container?
s
Yes, but not right now. Have to put kids into suspend mode :)
h
Try to find right button :)))
👍 1
s
ok mike im now on my notebook
Copy code
mount:
    native:
        platforms:
            - linux
hmm the logs: is mounted rw .. strange .. any idea where to look for logs?
ok tested docker/sdk:1.14.3 other error due startup of jenkins which could not find the templates
docker/sdk cli ls -la /var/log * DEVELOPMENT MODE total 24 drwxr-xr-x 1 root root 4096 Jul 3 19:39 . drwxr-xr-x 1 root root 4096 May 29 12:12 .. drwxrwxrwx 2 root root 4096 May 29 12:13 newrelic drwxr-xr-x 4 spryker spryker 4096 Jul 3 19:44 spryker
mount looks better
[2020-07-03T194650.274013+00:00] Zed.CRITICAL: Twig\Error\LoaderError - Unable to find template "jenkins.docker.xml.twig" (looked into: /data/config/Zed/cronjobs, /data/vendor/spryker/scheduler-jenkins/src/Spryker/Zed/SchedulerJenkins/Business/TemplateGenerator/Template). in "/data/vendor/twig/twig/src/Loader/FilesystemLoader.php::265" {"exception":"[object] (Twig\\Error\\LoaderError(code: 0): Unable to find template \"jenkins.docker.xml.twig\" (looked into: /data/config/Zed/cronjobs, /data/vendor/spryker/scheduler-jenkins/src/Spryker/Zed/SchedulerJenkins/Business/TemplateGenerator/Template). at /data/vendor/twig/twig/src/Loader/FilesystemLoader.php:265) [stacktrace] #0 /data/vendor/twig/twig/src/Loader/FilesystemLoader.php(161): Twig\\Loader\\FilesystemLoader->findTemplate('jenkins.docker....') #1 /data/vendor/twig/twig/src/Environment.php(351): Twig\\Loader\\FilesystemLoader->getCacheKey('jenkins.docker....') #2 /data/vendor/twig/twig/src/Environment.php(445): Twig\\Environment->getTemplateClass('jenkins.docker....') #3 /data/vendor/twig/twig/src/Environment.php(423): Twig\\Environment->loadTemplate('jenkins.docker....') #4 /data/vendor/twig/twig/src/Environment.php(384): Twig\\Environment->load('jenkins.docker....') #5 /data/vendor/spryker/scheduler-jenkins/src/Spryker/Zed/SchedulerJenkins/Dependency/TwigEnvironment/SchedulerJenkinsToTwigEnvironmentBridge.php(33): Twig\\Environment->render('jenkins.docker....', Array)
docker/sdk cli ls /data/config/Zed/cronjobs/ * DEVELOPMENT MODE README jenkins.php
file exists ... strange
h
I assume I know the reason of your primal issue.
docker/sdk:1.14.3 will demand jenkins template.
Before removing volume
After removing:
So my assumption is that volume artifacts that were created before mounts kept wrong user id
If you run clea-data volume should be deleted… I wonder why it does not help.
Did you have docker/sdk environment before an update to 1.15?
s
nope, i just did a clean checkout of suit .. i try to cleanup the whole docker env .. maybe this helps ..
@high-pencil-62400 ok i tested a couple of sdk and none works ..
h
I hope you do not run docker/sdk under root…
s
nope 🙂 i created docker grp and configured all correct 🙂
currently i run into issue with based on wrong suite and sdk ..
right now i test latest sdk (1.15.0) and latest suite ..
h
Suite and sdk must be compatible, yes. But we need to solve volume permission. We are using docker/sdk on linux and no such problems appear….
s
ok, latest suite latest sdk no volumes, no images no container, no networks ..
and now: UnexpectedValueException - Exception: There is no existing directory at "/var/log/spryker/DE/ZED" and its not buildable: Permission denied in /data/vendor/monolog/monolog/src/Monolog/Handler/StreamHandler.php (172)
h
host:
id
docker/sdk cli id
s
--> DEVELOPMENT MODE uid=1001(spryker) gid=82(www-data) groups=82(www-data)
❯ id uid=1001(marcokaiser) gid=1001(marcokaiser) groups=1001(marcokaiser),27(sudo),998(docker)
h
that’s expected.
s
checked that .. id is correct 🙂
h
docker run -it --rm spryker_app ls -al /var/log
s
Unable to find image 'spryker_app:latest' locally docker: Error response from daemon: pull access denied for spryker_app, repository does not exist or may require 'docker login': denied: requested access to the resource is denied. See 'docker run --help'.
dev maybe?
h
docker run -it --rm spryker_app:dev ls -al /var/log
right
s
❯ docker run -it --rm spryker_app:dev ls -al /var/log total 20 drwxr-xr-x 1 root root 4096 Jul 3 12:48 . drwxr-xr-x 1 root root 4096 May 29 12:12 .. drwxrwxrwx 2 root root 4096 May 29 12:13 newrelic drwxr-xr-x 2 1000 spryker 4096 Jul 3 12:48 spryker
wrong group ..
err wrong owner
h
group - is ok
wrong owner - yep…
Copy code
ARG USER_UID
RUN usermod -u ${USER_UID} spryker && find / -user 1000 -exec chown -h spryker {} \; || true;
That should set proper owner.
s
is there any log during build to watch?
h
PROGRESS_TYPE=plain docker/sdk build images
Please, check that step and output.
s
how?
h
I assume it will be cached.
docker builder prune
s
ok
h
Just run
docker builder prune
PROGRESS_TYPE=plain docker/sdk build images
Then scroll and find
RUN usermod -u ${USER_UID} spryker…
s
try new
#7 [2/3] RUN usermod -u 1001 spryker && find / -user 1000 -exec chown -h sp... #7 CACHED
tried
Copy code
ARG CACHEBUST=1
now its not cached .. try up now
nope doesnt changed anything ..
ok removed all, checkout suite tag 1.6 and now sdk 1.14.3 ..
ok i had to change something in the build scripts
my local user id is not 1000 its 1001
after changing all usermod from ${USER_ID} to 1001 it worked .. how is the userid passed into the build process .. maybe something goeing wrong here
Copy code
--build-arg USER_UID=${USER_UID:-1000} \
--build-arg USER_GID=${USER_GID:-1000} \
how can i pass my correct UID and GID?
h
It does actually use
id
to get those.
And that works in your case. As spryker(1001) inside container.
But WHY it does not change ownership of /var/log/spryker - that’s the question.
I have an idea… add in your deploy.dev.yml docker: logs: path: /home/spyrker/logs
It will put the folder into home directory and it will be automatically under the correct user.
However the code below should do the same:
Copy code
RUN usermod -u ${USER_UID} spryker && find / -user 1000 -exec chown -h spryker {} \; || true;
s
First of all i change my host uid from 1001 to 100 0 which resolves the first issue here .. i will try to reproduce this issue on a second machine maybe i find a solution for this. looks like a docker namepspacing issue on ubuntu 20.04 …
h
if your id is the same - that is solution. However it won’t fit everybody. I will create a ticket for investigation on our side.
a
I'm running docker/sdk on Ubuntu flawlessly. Previously on 19.04 and 19.10, now on 20.04.
h
@average-branch-45579 What ID of the user you use?
on the host?
In your case it is good as you have ID=1000 , the same ID that baked in Spryker image. 🙂
It was good for me in Tiny Linux with different ID.
a
Ok, then I just didn't read the whole thread good enough, sorry. 🙂
h
I’ve created a ticket to investigate the case.
The workaround is to use 1000 user on the host.
s
@high-pencil-62400 i run into new issues and have investigated more .. do you do something like changing permission of owner files etc? see: https://vsupalov.com/docker-shared-permissions/
h
Yes. We are using “Build the right image” section of the article.
However in different manner, as user is already exists.
s
hmm really strange ..
h
Yep. It works for me in Tiny Linux VM