From 731efa7579b0d1613f4616373b8629fe1a2cafae Mon Sep 17 00:00:00 2001 From: Claude Date: Thu, 13 Aug 2026 05:02:17 +0000 Subject: [PATCH] fix(docker): support OpenShift arbitrary-UID runs on the stock image OpenShift's restricted SCC starts containers as a random non-root UID that is always in group 0. The published image only grants owner (root) write on /app, so the runtime DB schema step (prisma generate + migrate) fails and customers have to rebuild the image with their own permission fixes. Align group perms with owner perms on /app in the builder stage so the runtime COPY layers carry them without duplicating the venv layer, give the runtime stage HOME=/app so arbitrary UIDs get a writable cache home, and make /app itself group-writable for lazily created dirs like /app/.cache --- Dockerfile | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/Dockerfile b/Dockerfile index 66ce3af4a65..148b1805476 100644 --- a/Dockerfile +++ b/Dockerfile @@ -95,6 +95,13 @@ RUN HOME=/opt/prisma XDG_CACHE_HOME=/opt/prisma/.cache PRISMA_BINARY_CACHE_DIR=/ RUN sed -i 's/\r$//' docker/entrypoint.sh && chmod +x docker/entrypoint.sh && \ sed -i 's/\r$//' docker/prod_entrypoint.sh && chmod +x docker/prod_entrypoint.sh +# OpenShift-style platforms run the container as an arbitrary UID that is +# always in group 0. Aligning group perms with owner perms here (not in the +# runtime stage) lets the COPY layers below carry them, so that UID can run +# the DB schema step (prisma generate + migrate) on the stock image without +# duplicating the venv in an extra runtime chmod layer. +RUN chgrp -R 0 /app && chmod -R g=u /app + # Runtime stage FROM $LITELLM_RUNTIME_IMAGE AS runtime @@ -104,7 +111,10 @@ USER root RUN apk add --no-cache bash openssl tzdata nodejs python3 libsndfile WORKDIR /app +# HOME=/app gives arbitrary-UID (OpenShift) runs a writable home for caches +# that default to $HOME/.cache; /root is unreadable to those UIDs. ENV PATH="/app/.venv/bin:${PATH}" \ + HOME=/app \ PRISMA_BINARY_CACHE_DIR=/opt/prisma/binaries \ PRISMA_CLI_PATH=/opt/prisma/binaries/node_modules/.bin/prisma \ PRISMA_CLI_QUERY_ENGINE_TYPE=binary \ @@ -132,6 +142,9 @@ COPY --from=builder /opt/prisma /opt/prisma RUN find /app/.venv -type f -path "*/tornado/test/*" -delete && \ find /app/.venv -type d -path "*/tornado/test" -delete && \ + mkdir -p /app/.cache && \ + chgrp 0 /app /app/.cache && \ + chmod g=u /app /app/.cache && \ chmod -R a+rX /opt/prisma && \ test -x /opt/prisma/binaries/node_modules/.bin/prisma && \ test -f /opt/prisma/binaries/node_modules/prisma/build/index.js && \