Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

External Redis not working: redis-session.ini: Permission denied

Abierto
#883 1 comentario 1 reacción 0 asignados Ver en GitHub

@antoinetran ya está trabajando en esto.

Desde el 16/9/2026.

  • #886 de @antoinetran — abierto

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
55/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
helm, kubernetes

Línea de trabajo

Comienza con values.yaml y la ruta de entrypoint.sh del chart mencionada en el informe, y luego reproduce el despliegue con externalRedis habilitado y el contexto de seguridad non-root mostrado. Traza por qué entrypoint.sh no puede crear redis-session.ini; estará terminado cuando Redis externo funcione con los ajustes de seguridad reforzados compatibles sin el error de permisos.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Describe your Issue

I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.

I already tried the following things:

  • removing the custom userid set in the security context (still no permission)
  • using an empty dir (will delete the other php inis there, which causes other errors)
  • configuring redis myself (no success yet. It is difficult as i cannot set the redis-host env var, which triggers the entrypoint.sh)
Logs and Errors
=> Configuring PHP session handler...
==> Using Redis as PHP session handler...
/entrypoint.sh: 121: cannot create /usr/local/etc/php/conf.d/redis-session.ini: Permission denied

Describe your Environment

  • Kubernetes distribution: k3s

  • Helm Version (or App that manages helm): ArgoCD 3.5.2

  • Helm Chart Version: 9.2.6

  • values.yaml:

resources:
  limits:
    cpu: 1000m
    memory: 1024Mi
  requests:
    cpu: 200m
    memory: 512Mi

nextcloud:
  defaultConfigs:
    imaginary.config.php: true
  host: nextcloud.abc.de
  configs:
    trustedDomains.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_domains' => array (
          0 => 'localhost',
          1 => 'nextcloud.abc.de',
          2 => 'nextcloud.cde.de',
        )
      );
    proxy.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_proxies' => array(
          0 => '10.42.0.0/16',  # Traefik IP-Range in K3s
        ),
        'forwarded_for_headers' => array(
          0 => 'HTTP_X_FORWARDED_FOR',
        ),
        'overwriteprotocol' => 'https',
      );
    maintenance.config.php: |-
      <?php
      $CONFIG = array (
        'maintenance_window_start' => 1,
      );
    previews.config.php: |-
      <?php
      $CONFIG = array (
        'enable_previews' => true,
        'preview_max_x' => 1024,
        'preview_max_y' => 1024,
      );
    filePermissions.config.php: |-
      <?php
      $CONFIG = array (
        'check_data_directory_permissions' => false,
      );
    region.config.php: |-
      <?php
      $CONFIG = array (
        'default_language' => 'de',
        'default_locale' => 'de',
        'default_phone_region' => 'de',
        'default_timezone' => 'Europe/Berlin',
      );
    # needs to be overwridden with NC_serverid if we scale nextcloud
    serverid.config.php: |-
      <?php
      $CONFIG = array (
        'serverid' => '259',
      );

  mail:
    enabled: false
  existingSecret:
    enabled: true
    secretName: nextcloud
    usernameKey: nextcloud-username
    passwordKey: nextcloud-password
  securityContext:
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: true
    readOnlyRootFilesystem: false # cannot login if activated. It seems that we need to have an emptyDir for the session storage
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
      add:
        - NET_BIND_SERVICE
  podSecurityContext:
    fsGroup: 33
    fsGroupChangePolicy: "Always"
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: false
    seccompProfile:
      type: RuntimeDefault
  extraVolumes:
    - name: apache2
      emptyDir: {}
  extraVolumeMounts:
    - name: apache2
      mountPath: "/var/run/apache2"
  datadir: /var/www/html/data
  extraSidecarContainers:
  - name: nextcloud-logger
    image: busybox
    command: [/bin/sh, -c, 'while ! test -f "/run/nextcloud/data/nextcloud.log"; do sleep 1; done; tail -n+1 -f /run/nextcloud/data/nextcloud.log']
    volumeMounts:
    - name: nextcloud-data
      mountPath: /run/nextcloud/data

ingress:
  enabled: true
  className: "traefik"
  tls:
    - hosts:
      - nextcloud.abc.de

service:
  annotations:
    traefik.ingress.kubernetes.io/service.sticky.cookie: "true"

internalDatabase:
  enabled: false

externalDatabase:
  enabled: true
  type: mysql
  host: "mariadb.mariadb.svc.cluster.local:3306"
  database: nextcloud
  user: nextcloud
  existingSecret:
    enabled: true
    secretName: nextcloud-db
    usernameKey: db-username
    passwordKey: db-password

persistence:
  # Nextcloud Data (/var/www/html)
  enabled: true
  size: 4Gi
  storageClass: "longhorn-replicated"
  nextcloudData:
    enabled: true
    storageClass: "smb-csi-storage-box"
    size: 50Gi

livenessProbe:
  enabled: false
readinessProbe:
  enabled: false

cronjob:
  enabled: true
  type: "cronjob"

metrics:
  enabled: true
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 50m
      memory: 32Mi
    requests:
      cpu: 10m
      memory: 16Mi

imaginary:
  enabled: true
  image:
    registry: ghcr.io
    repository: nextcloud-releases/aio-imaginary
    tag: 20260825_084538@sha256:fa648f3a72b2d2eea6cc33e4f01d152c299e22ef83c97e578fc093737edd6ec6
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
      - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 200m
      memory: 256Mi
    requests:
      cpu: 10m
      memory: 150Mi

externalRedis:
  enabled: true
  host: "redis-standalone"
  port: "6379"
  existingSecret:
    enabled: true
    secretName: redis
    passwordKey: password

Additional context, if any

I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.

Lenguaje dominante
Go Template
Estrellas
536
Forks
316
Merge medio
4 d 16 h
PR fusionados (30 d)
2

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de nextcloud/helm

Todos los issues de nextcloud/helm

Issues similares

Más issues de Databases

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.