fix(docker): support OpenShift arbitrary-UID runs on the stock image

OpenShift's restricted SCC starts containers as a random non-root UID that
is always in group 0. The published image only grants owner (root) write on
/app, so the runtime DB schema step (prisma generate + migrate) fails and
customers have to rebuild the image with their own permission fixes.

Align group perms with owner perms on /app in the builder stage so the
runtime COPY layers carry them without duplicating the venv layer, give the
runtime stage HOME=/app so arbitrary UIDs get a writable cache home, and
make /app itself group-writable for lazily created dirs like /app/.cache
This commit is contained in:
Claude 2026-08-13 05:02:17 +00:00
parent d86336a7c6
commit 731efa7579
No known key found for this signature in database

View file

@ -95,6 +95,13 @@ RUN HOME=/opt/prisma XDG_CACHE_HOME=/opt/prisma/.cache PRISMA_BINARY_CACHE_DIR=/
RUN sed -i 's/\r$//' docker/entrypoint.sh && chmod +x docker/entrypoint.sh && \
sed -i 's/\r$//' docker/prod_entrypoint.sh && chmod +x docker/prod_entrypoint.sh
# OpenShift-style platforms run the container as an arbitrary UID that is
# always in group 0. Aligning group perms with owner perms here (not in the
# runtime stage) lets the COPY layers below carry them, so that UID can run
# the DB schema step (prisma generate + migrate) on the stock image without
# duplicating the venv in an extra runtime chmod layer.
RUN chgrp -R 0 /app && chmod -R g=u /app
# Runtime stage
FROM $LITELLM_RUNTIME_IMAGE AS runtime
@ -104,7 +111,10 @@ USER root
RUN apk add --no-cache bash openssl tzdata nodejs python3 libsndfile
WORKDIR /app
# HOME=/app gives arbitrary-UID (OpenShift) runs a writable home for caches
# that default to $HOME/.cache; /root is unreadable to those UIDs.
ENV PATH="/app/.venv/bin:${PATH}" \
HOME=/app \
PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries \
PRISMA_CLI_PATH=/opt/prisma/binaries/node_modules/.bin/prisma \
PRISMA_CLI_QUERY_ENGINE_TYPE=binary \
@ -132,6 +142,9 @@ COPY --from=builder /opt/prisma /opt/prisma
RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \
find /app/.venv -type d -path "*/tornado/test" -delete && \
mkdir -p /app/.cache && \
chgrp 0 /app /app/.cache && \
chmod g=u /app /app/.cache && \
chmod -R a+rX /opt/prisma && \
test -x /opt/prisma/binaries/node_modules/.bin/prisma && \
test -f /opt/prisma/binaries/node_modules/prisma/build/index.js && \