fix(deploy): add :Z SELinux labels to bind mounts
Add the :Z (private unshared) SELinux label to all bind-mounted directories in docker-compose.local.yml and docker-compose.dev.yml. On systems with SELinux in Enforcing mode (e.g. Fedora, RHEL, CentOS), containers using bind mounts are denied access to host directories because the default 'user_home_t' context is not accessible to container processes. The :Z label tells the container runtime to relabel the mount point with 'container_file_t' so the container can read/write it. Named volumes in docker-compose.yml are not affected because the runtime already handles their labels automatically. Fixes permission-denied errors on: - ./data:/app/data - ./postgres_data:/var/lib/postgresql/data - ./redis_data:/data
This commit is contained in:
@@ -18,7 +18,7 @@ services:
|
||||
ports:
|
||||
- "${BIND_HOST:-127.0.0.1}:${SERVER_PORT:-8080}:8080"
|
||||
volumes:
|
||||
- ./data:/app/data
|
||||
- ./data:/app/data:Z
|
||||
environment:
|
||||
- AUTO_SETUP=true
|
||||
- SERVER_HOST=0.0.0.0
|
||||
@@ -73,7 +73,7 @@ services:
|
||||
container_name: sub2api-postgres-dev
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./postgres_data:/var/lib/postgresql/data
|
||||
- ./postgres_data:/var/lib/postgresql/data:Z
|
||||
environment:
|
||||
- POSTGRES_USER=${POSTGRES_USER:-sub2api}
|
||||
- POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?POSTGRES_PASSWORD is required}
|
||||
@@ -94,7 +94,7 @@ services:
|
||||
container_name: sub2api-redis-dev
|
||||
restart: unless-stopped
|
||||
volumes:
|
||||
- ./redis_data:/data
|
||||
- ./redis_data:/data:Z
|
||||
command: >
|
||||
sh -c '
|
||||
redis-server
|
||||
|
||||
Reference in New Issue
Block a user