Error: Can't drop privilege as nonroot user: container keeps restarting on Google Cloud Compute Engine

Viewed 2198

I've searched and can't seem to find the answer to this error. "Error: Can't drop privilege as nonroot user" when I create a new VM.

The container keeps restarting. It works just fine on my local MacOS machine.

I'm trying to run the image on a Google Compute Engine VM with the Container Optimized OS. I'm using nginx, php-fpm, and alpine.

The supervisord.conf file looks like this:

[supervisord]
nodaemon=true
logfile=/dev/null
logfile_maxbytes=0
pidfile=/run/supervisord.pid
user=root

[program:php-fpm]
command=php-fpm8 -F
stdout_logfile=/dev/stdout
stdout_logfile_maxbytes=0
stderr_logfile=/dev/stderr
stderr_logfile_maxbytes=0
autostart=true
autorestart=true
priority=5
stdout_events_enabled=true
stderr_events_enabled=true

[program:nginx]
command=nginx -g 'daemon off;'
stdout_logfile=/dev/stdout
stdout_logfile_maxbytes=0
stderr_logfile=/dev/stderr
stderr_logfile_maxbytes=0
autorestart=false
startretries=0

Anyone bumped into this error too?

1 Answers

This looks like you're trying to start Supervisor as a non-root.

Your config file tells the Supervisor to run as root but if you start it as a non-root user then it can't start processes with root privileges. It was changed in 3.3.4 version due to security reasons:

Fixed a bug where supervisord would continue starting up if the [supervisord] section of the config file specified user= but setuid() to that user failed. It will now exit immediately if it cannot drop privileges.

Have a look at this duscussion;

You can remove user=root entirely, which will allow supervisord to start as root or non-root. When run as root, this has the side effect of printing a warning message to the log, since we recommend having a user= when run as root. Assuming the environment that supervisord is started in contains the variable USER and it is set to the current user, you should be able to use user=%(ENV_USER)s to run as either user.

Another simillar issue was discussed at Server Fault.

Related