From 7bd3a5e6ab9d3f34dbf747504572b9b15b0f1206 Mon Sep 17 00:00:00 2001 From: Yassin Kortam Date: Wed, 5 Aug 2026 13:38:46 -0700 Subject: [PATCH] fix(docker): bake the componentized prisma engines at /opt/prisma so any uid can start (#35989) The gateway and backend images generated the prisma client under HOME=/home/nonroot, so the engine paths baked into the client sat inside a directory the base image ships at mode 0700. Only uid 65532 can search it, and prisma resolves those baked paths eagerly with an existence check that propagates EACCES, so a container started under any other uid dies with a PermissionError out of pathlib before the PRISMA_QUERY_ENGINE_BINARY override is ever read. A chart that sets runAsUser, a docker run --user, or an OpenShift namespace assigning an arbitrary uid all produce that shape, and the gateway is the request-serving component, so the proxy does not serve at all. Bake to /opt/prisma instead, the fixed world-readable path the other three images already use, and assert at build time that every baked path lands there. chmod a+rX rather than a+r because prisma executes the engine to check it can run on this machine. The runtime PRISMA_BINARY_CACHE_DIR pin keeps the CLI wrapper's own resolution pointing at the bake rather than at a /home/nonroot/.cache that no longer exists. --- backend/Dockerfile | 15 +++++++++------ gateway/Dockerfile | 15 +++++++++------ 2 files changed, 18 insertions(+), 12 deletions(-) diff --git a/backend/Dockerfile b/backend/Dockerfile index 9c93259adc3..853c74b05ca 100644 --- a/backend/Dockerfile +++ b/backend/Dockerfile @@ -59,9 +59,9 @@ RUN --mount=type=cache,target=/root/.cache/uv \ --extra semantic-router \ --python python3 -RUN mkdir -p /home/nonroot && \ - HOME=/home/nonroot prisma generate --schema=./schema.prisma && \ - chown -R nonroot:nonroot /home/nonroot/.cache +RUN HOME=/opt/prisma XDG_CACHE_HOME=/opt/prisma/.cache PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries \ + npm_config_cache=/root/.npm \ + prisma generate --schema=./schema.prisma RUN sed -i 's/\r$//' docker/component_entrypoint.sh && chmod +x docker/component_entrypoint.sh @@ -83,13 +83,16 @@ ENV HOME=/home/nonroot \ PATH="/app/.venv/bin:${PATH}" \ PYTHONPATH="/app" \ PYTHONDONTWRITEBYTECODE=1 \ - PYTHONUNBUFFERED=1 + PYTHONUNBUFFERED=1 \ + PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries COPY --from=builder --chown=nonroot:nonroot /app /app -COPY --from=builder --chown=nonroot:nonroot /home/nonroot/.cache /home/nonroot/.cache +COPY --from=builder /opt/prisma /opt/prisma RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \ - find /app/.venv -type d -path "*/tornado/test" -delete + find /app/.venv -type d -path "*/tornado/test" -delete && \ + chmod -R a+rX /opt/prisma && \ + python -c "from prisma.client import BINARY_PATHS; paths = list(BINARY_PATHS.query_engine.values()); assert paths and all(p.startswith('/opt/prisma/') for p in paths), paths" USER nonroot diff --git a/gateway/Dockerfile b/gateway/Dockerfile index 3b4f94d5dc9..223df524d7c 100644 --- a/gateway/Dockerfile +++ b/gateway/Dockerfile @@ -61,9 +61,9 @@ RUN --mount=type=cache,target=/root/.cache/uv \ --extra bedrock-realtime \ --python python3 -RUN mkdir -p /home/nonroot && \ - HOME=/home/nonroot prisma generate --schema=./schema.prisma && \ - chown -R nonroot:nonroot /home/nonroot/.cache +RUN HOME=/opt/prisma XDG_CACHE_HOME=/opt/prisma/.cache PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries \ + npm_config_cache=/root/.npm \ + prisma generate --schema=./schema.prisma RUN sed -i 's/\r$//' docker/component_entrypoint.sh && chmod +x docker/component_entrypoint.sh @@ -85,13 +85,16 @@ ENV HOME=/home/nonroot \ PATH="/app/.venv/bin:${PATH}" \ PYTHONPATH="/app" \ PYTHONDONTWRITEBYTECODE=1 \ - PYTHONUNBUFFERED=1 + PYTHONUNBUFFERED=1 \ + PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries COPY --from=builder --chown=nonroot:nonroot /app /app -COPY --from=builder --chown=nonroot:nonroot /home/nonroot/.cache /home/nonroot/.cache +COPY --from=builder /opt/prisma /opt/prisma RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \ - find /app/.venv -type d -path "*/tornado/test" -delete + find /app/.venv -type d -path "*/tornado/test" -delete && \ + chmod -R a+rX /opt/prisma && \ + python -c "from prisma.client import BINARY_PATHS; paths = list(BINARY_PATHS.query_engine.values()); assert paths and all(p.startswith('/opt/prisma/') for p in paths), paths" USER nonroot