Skip to content

Commit d5e4c4c

Browse files
committed
Robusta fork: run entrypoint without sudo under non-root UIDs (OpenShift)
OpenShift's restricted-v2 SCC forces containers to run as a random non-root UID *and* sets no_new_privs=1, which blocks sudo outright (even when sudo is only de-escalating from root to nobody). Upstream's run.sh assumed the container always starts as root and unconditionally shelled out to `sudo -E -u nobody`, so the pod crashed before migrations could run. Wrap the privilege drop in a small helper that checks `id -u`: when we're already non-root, invoke the binary directly. This keeps the upstream behavior on platforms that start as root (drop to `nobody`) while letting OpenShift run unchanged. Also relax /app permissions to `chgrp 0 + chmod g=u` so the random UID (which has gid 0 as a supplemental group on OpenShift) can read the release and write to /app/.pgdelta-cache.
1 parent c0c3b8b commit d5e4c4c

2 files changed

Lines changed: 21 additions & 3 deletions

File tree

‎Dockerfile‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,10 +94,15 @@ RUN sed -i '/en_US.UTF-8/s/^# //g' /etc/locale.gen && locale-gen
9494

9595
WORKDIR "/app"
9696

97-
RUN chown nobody /app && mkdir -p /app/.pgdelta-cache && chown nobody /app/.pgdelta-cache
97+
RUN chown nobody:root /app && chmod g=u /app && \
98+
mkdir -p /app/.pgdelta-cache && chown nobody:root /app/.pgdelta-cache && chmod g=u /app/.pgdelta-cache
9899

99100
COPY --from=builder --chown=nobody:root /app/_build/${MIX_ENV}/rel/realtime ./
100101
COPY run.sh run.sh
102+
# Robusta fork: make everything under /app group-accessible so OpenShift's
103+
# arbitrary-UID model (random UID + supplemental gid 0) can read/execute
104+
# the release and write to pgdelta-cache.
105+
RUN chgrp -R 0 /app && chmod -R g=u /app
101106
RUN ls -la /app
102107
ENTRYPOINT ["/usr/bin/tini", "-s", "-g", "--", "/app/run.sh"]
103108
CMD ["/app/bin/server"]

‎run.sh‎

Lines changed: 15 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -94,12 +94,25 @@ if [[ -n "${GENERATE_CLUSTER_CERTS:-}" ]] ; then
9494
generate_certs
9595
fi
9696

97+
# Robusta fork: drop to `nobody` via sudo only when the container starts
98+
# as root. On platforms that already force a non-root UID (notably OpenShift
99+
# under the restricted-v2 SCC, where no_new_privs blocks sudo entirely),
100+
# invoke the binary directly — we're already non-root, there's nothing
101+
# to drop to.
102+
run_as_nobody() {
103+
if [ "$(id -u)" -eq 0 ]; then
104+
sudo -E -u nobody "$@"
105+
else
106+
"$@"
107+
fi
108+
}
109+
97110
echo "Running migrations"
98-
sudo -E -u nobody /app/bin/migrate
111+
run_as_nobody /app/bin/migrate
99112

100113
if [ "${SEED_SELF_HOST-}" = true ]; then
101114
echo "Seeding selfhosted Realtime"
102-
sudo -E -u nobody /app/bin/realtime eval 'Realtime.Release.seeds(Realtime.Repo)'
115+
run_as_nobody /app/bin/realtime eval 'Realtime.Release.seeds(Realtime.Repo)'
103116
fi
104117

105118
echo "Starting Realtime"

0 commit comments

Comments
 (0)