Runnig docker as nonRoot with --user $(id -u) cant create /var/lib/

Viewed 1065

Hello im fairly new to docker and i am trying to get influxdb and grafana up and running.

I already went through some problem solving and want to get you on the same page with a little summary.

  1. Got a docker-compose file from here
  2. did sudo docker-compose up -d
  3. ran into the problem, that arguments like INFLUXDB_DB=db0 insdide the docker-compose.yml are not applied by the containers. So the databaes db0 wasnt created for example.
  4. changes to the containers though would persist. So i could create a database and after a restart it was still there
  5. tested each container as standalone with docker run
  6. figured out if I used bind mount instead of docker volumes it worked for influxdb
  7. the grafana container wouldn't start
sudo docker run --volume "$PWD/data:/var/lib/grafana" -p 3000:3000 grafana/grafana:latest
GF_PATHS_DATA='/var/lib/grafana' is not writable.
You may have issues with file permissions, more information here: http://docs.grafana.org/installation/docker/#migration-from-a-previous-version-of-the-docker-container-to-5-1-or-later
mkdir: can't create directory '/var/lib/grafana/plugins': Permission denied
  1. read here that I need do define a user with $(id -u) if I want to use bind mount with grafana
  2. did that, but then the user has no permission to create the /var/lib/grafana directory
 sudo docker run --user $(id -u) --volume "$PWD/data:/var/lib/grafana" -p 3000:3000 grafana/grafana:latest
GF_PATHS_DATA='/var/lib/grafana' is not writable.
You may have issues with file permissions, more information here: http://docs.grafana.org/installation/docker/#migration-from-a-previous-version-of-the-docker-container-to-5-1-or-later
mkdir: can't create directory '/var/lib/grafana/plugins': Permission denied
  1. when i set the --user argument to root with 0:0 it works but i read some best practices where running as root for testing is ok but for production it would be not ideal.
  2. i also read that i can add a user to the docker group to give the user the permissions
  3. there was no docker group on my system so i read here, that i can create one and then adding the docker.socket to that group via /etc/docker/daemon.json but that file doesnt exist and i cant create it and i think i am pretty deep down the rabbit hole to just stop and ask if i am on the wrong path and did something wrong.

How can i start the containers as nonRoot without giving them to much permissions is my main question i think.

using: Distributor ID: Ubuntu Description: Ubuntu 18.04.4 LTS Release: 18.04 Codename: bionic

2 Answers

I solved this by running the container as root, chown the data dir and then su to grafana user. In docker-compose, this looks like:

grafana:
    image: grafana/grafana:8.2.3
    volumes:
        - ./data/grafana:/var/lib/grafana
    user: root
    entrypoint:
        - /bin/sh
        - -c
        - |
          chown grafana /var/lib/grafana
          exec su grafana -s /bin/sh -c /run.sh

I remember dealing with similar issues long ago.

I recommend

one time

mkdir data/grafana

and then

sudo docker run --volume "$PWD/data:/var/lib" -p 3000:3000 grafana/grafana:latest

because as I recall whenever you volume mount something it mounts as owned by root. There is no way to change the ownership of the mounted volume.

But you can change the ownership of files and directories inside the mounted volume and they do not have to be root.

So in my solution you are just mounting data to /var/lib, /var/lib will be owned by root but /var/lib/grafana will be owned by a regular user.

This would obviously hide the contents of any other folders in the /var/lib directory but maybe there is not anything important there. If there is then could you configure the program to look for /var/lib/grafana at some other location. For example /srv/grafana then change the invocation to

sudo docker run --env GRAFANA_DIR=/srv/grafana --volume "$PWD/data:/srv" -p 3000:3000 grafana/grafana:latest

Lastly, I do not see why it would be a security issue to run as root. That is something I am not sure I agree with.

Related