Why is the official Mongo Docker image not reading /docker-entrypoint-initdb.d in an ECS environment?

Viewed 445

I have created a task in Amazon ECS based on the mongo:latest docker image, I have configured the environment with the following:

MONGO_INITDB_DATABASE=mydb
MONGO_INITDB_ROOT_PASSWORD=root_password
MONGO_INITDB_ROOT_USERNAME=root

I have also mapped the following volumes:

/mongo/data:/data/db                          # This is an EFS access point,
/mongo/scripts:/docker-entrypoint-initdb.d    # another EFS access point.

I have a script called secure_mongo.js in the /mongo/scripts access point (I think the use mydb line is superfluous based on the mongo image docs q.v.):

use mydb

db.createUser({
        user: 'user_name',
        pwd: 'password',
        roles: [ { role: 'readWrite', db: 'mydb' } ]
});

According to the mongo:latest docs on Docker Hub:

When a container is started for the first time it will execute files with extensions .sh and .js that are found in /docker-entrypoint-initdb.d. Files will be executed in alphabetical order. .js files will be executed by mongo using the database specified by the MONGO_INITDB_DATABASE variable, if it is present, or test otherwise. You may also switch databases within the .js script.

However it seems that nothing is run, when my application attempts to connect I see the following output:

{"t":{"$date":"2020-09-18T03:48:41.834+00:00"},"s":"I",  "c":"ACCESS",   "id":20251,   "ctx":"conn2","msg":"Supported SASL mechanisms requested for unknown user","attr":{"user":"user_name@mydb"}}
{"t":{"$date":"2020-09-18T03:48:41.836+00:00"},"s":"I",  "c":"ACCESS",   "id":20249,   "ctx":"conn2","msg":"Authentication failed","attr":{"mechanism":"SCRAM-SHA-256","principalName":"user_name","authenticationDatabase":"mydb","client":"10.0.17.73:53488","result":"UserNotFound: Could not find user \"user_name\" for db \"mydb\""}}
{"t":{"$date":"2020-09-18T03:48:41.840+00:00"},"s":"I",  "c":"ACCESS",   "id":20249,   "ctx":"conn2","msg":"Authentication failed","attr":{"mechanism":"SCRAM-SHA-1","principalName":"user_name","authenticationDatabase":"mydb","client":"10.0.17.73:53488","result":"UserNotFound: Could not find user \"user_name\" for db \"mydb\""}}

My application connection url is mongodb://mongo-srvc.local:27017/mydb so it should be authenticating against the mydb database where the user should be. To validate the volume was in place I have connected into the running instance and I can see the script I wrote in the directory /docker-entrypoint-initdb.d. In fact I also added a short shell script foo.sh to this directory:

#!/bin/bash
touch "./baa.txt"

On re-starting the container no baa.txt was to be found so it looks like the content of this folder is never executed. I am also not sure if the environment variables are being used. I attempted to run the mongo shell using:

mongo --username root --password --authenticationDatabase admin

This then prompted for the password, when I gave the password it returned:

connecting to: mongodb://127.0.0.1:27017/?authSource=admin&compressors=disabled&gssapiServiceName=mongodb
Error: Authentication failed. :
connect@src/mongo/shell/mongo.js:374:17
@(connect):2:6
exception: connect failed
exiting with code 1

However I am not an expert on the mongo shell so I could have got that last test incorrect. Any advise on what I can try next, what I have misconfigured or just got plain wrong is very welcome!

0 Answers
Related