Skip to content

Commit 7c51cb5

Browse files
committed
fix: rootless Alpine container support
Patch out chown calls that fail without CAP_CHOWN in rootless containers. Use find instead of hardcoded gem paths so patches survive Ruby and gem version changes. Signed-off-by: Simon Lauger <simon@lauger.de>
1 parent f9ba621 commit 7c51cb5

1 file changed

Lines changed: 12 additions & 2 deletions

File tree

openvoxserver/Containerfile.alpine

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -223,8 +223,18 @@ RUN for d in \
223223
RUN sed -i 's/^ *USER="puppet"/USER=""/' /etc/default/puppetserver
224224
# `puppetserver setup` forces symlinking the "old" cadir to the "new" one for puppet 6 compatibility
225225
# reasons. this won't work because after creating a link ruby tries to call chown
226-
RUN sed -i '/Puppetserver::Ca::Utils::Config\.symlink_to_old_cadir/ s/^/# /' \
227-
/usr/lib/ruby/gems/3.4.0/gems/openvoxserver-ca-3.0.0/lib/puppetserver/ca/action/setup.rb
226+
RUN find /usr/lib/ruby/gems -name setup.rb \
227+
-path '*/openvoxserver-ca-*/lib/puppetserver/ca/action/*' \
228+
-exec sed -i '/Puppetserver::Ca::Utils::Config\.symlink_to_old_cadir/ s/^/# /' {} +
229+
# `FileUtils.chown` calls fail in rootless containers because the process
230+
# lacks CAP_CHOWN. The ownership is already handled by the g=u / SGID pattern above.
231+
RUN find /usr/lib/ruby/gems -name file_system.rb \
232+
-path '*/openvoxserver-ca-*/lib/puppetserver/ca/utils/*' \
233+
-exec sed -i 's/FileUtils\.chown/# FileUtils.chown/' {} +
234+
# `install --owner/--group` in the foreground script requires CAP_CHOWN which
235+
# is not available in rootless containers. Replace with a simple touch + chmod.
236+
RUN sed -i 's|printf.*install -D --owner.*restartfile.*|touch "$restartfile" \&\& chmod 0644 "$restartfile"|' \
237+
/opt/puppetlabs/server/apps/puppetserver/cli/apps/foreground
228238

229239
USER puppet:0
230240

0 commit comments

Comments
 (0)