External Redis not working: redis-session.ini: Permission denied
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 55/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Active
- Tech stack
- helm, kubernetes
- Domain
- databases, infrastructure
Research direction
Start with values.yaml and the chart's entrypoint.sh path mentioned in the report, then reproduce the deployment with externalRedis enabled and the shown non-root security context. Trace why entrypoint.sh cannot create redis-session.ini; done when external Redis works under the supported hardened security settings without the permission error.
Written by the indexing model from the issue text.
Description
Describe your Issue
I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.
I already tried the following things:
- removing the custom userid set in the security context (still no permission)
- using an empty dir (will delete the other php inis there, which causes other errors)
- configuring redis myself (no success yet. It is difficult as i cannot set the redis-host env var, which triggers the entrypoint.sh)
Logs and Errors
=> Configuring PHP session handler...
==> Using Redis as PHP session handler...
/entrypoint.sh: 121: cannot create /usr/local/etc/php/conf.d/redis-session.ini: Permission denied
Describe your Environment
-
Kubernetes distribution: k3s
-
Helm Version (or App that manages helm): ArgoCD 3.5.2
-
Helm Chart Version: 9.2.6
-
values.yaml:
resources:
limits:
cpu: 1000m
memory: 1024Mi
requests:
cpu: 200m
memory: 512Mi
nextcloud:
defaultConfigs:
imaginary.config.php: true
host: nextcloud.abc.de
configs:
trustedDomains.config.php: |-
<?php
$CONFIG = array (
'trusted_domains' => array (
0 => 'localhost',
1 => 'nextcloud.abc.de',
2 => 'nextcloud.cde.de',
)
);
proxy.config.php: |-
<?php
$CONFIG = array (
'trusted_proxies' => array(
0 => '10.42.0.0/16', # Traefik IP-Range in K3s
),
'forwarded_for_headers' => array(
0 => 'HTTP_X_FORWARDED_FOR',
),
'overwriteprotocol' => 'https',
);
maintenance.config.php: |-
<?php
$CONFIG = array (
'maintenance_window_start' => 1,
);
previews.config.php: |-
<?php
$CONFIG = array (
'enable_previews' => true,
'preview_max_x' => 1024,
'preview_max_y' => 1024,
);
filePermissions.config.php: |-
<?php
$CONFIG = array (
'check_data_directory_permissions' => false,
);
region.config.php: |-
<?php
$CONFIG = array (
'default_language' => 'de',
'default_locale' => 'de',
'default_phone_region' => 'de',
'default_timezone' => 'Europe/Berlin',
);
# needs to be overwridden with NC_serverid if we scale nextcloud
serverid.config.php: |-
<?php
$CONFIG = array (
'serverid' => '259',
);
mail:
enabled: false
existingSecret:
enabled: true
secretName: nextcloud
usernameKey: nextcloud-username
passwordKey: nextcloud-password
securityContext:
runAsUser: 33
runAsGroup: 33
runAsNonRoot: true
readOnlyRootFilesystem: false # cannot login if activated. It seems that we need to have an emptyDir for the session storage
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
podSecurityContext:
fsGroup: 33
fsGroupChangePolicy: "Always"
runAsUser: 33
runAsGroup: 33
runAsNonRoot: false
seccompProfile:
type: RuntimeDefault
extraVolumes:
- name: apache2
emptyDir: {}
extraVolumeMounts:
- name: apache2
mountPath: "/var/run/apache2"
datadir: /var/www/html/data
extraSidecarContainers:
- name: nextcloud-logger
image: busybox
command: [/bin/sh, -c, 'while ! test -f "/run/nextcloud/data/nextcloud.log"; do sleep 1; done; tail -n+1 -f /run/nextcloud/data/nextcloud.log']
volumeMounts:
- name: nextcloud-data
mountPath: /run/nextcloud/data
ingress:
enabled: true
className: "traefik"
tls:
- hosts:
- nextcloud.abc.de
service:
annotations:
traefik.ingress.kubernetes.io/service.sticky.cookie: "true"
internalDatabase:
enabled: false
externalDatabase:
enabled: true
type: mysql
host: "mariadb.mariadb.svc.cluster.local:3306"
database: nextcloud
user: nextcloud
existingSecret:
enabled: true
secretName: nextcloud-db
usernameKey: db-username
passwordKey: db-password
persistence:
# Nextcloud Data (/var/www/html)
enabled: true
size: 4Gi
storageClass: "longhorn-replicated"
nextcloudData:
enabled: true
storageClass: "smb-csi-storage-box"
size: 50Gi
livenessProbe:
enabled: false
readinessProbe:
enabled: false
cronjob:
enabled: true
type: "cronjob"
metrics:
enabled: true
securityContext:
runAsUser: 1000
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
resources:
limits:
cpu: 50m
memory: 32Mi
requests:
cpu: 10m
memory: 16Mi
imaginary:
enabled: true
image:
registry: ghcr.io
repository: nextcloud-releases/aio-imaginary
tag: 20260825_084538@sha256:fa648f3a72b2d2eea6cc33e4f01d152c299e22ef83c97e578fc093737edd6ec6
securityContext:
runAsUser: 1000
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
resources:
limits:
cpu: 200m
memory: 256Mi
requests:
cpu: 10m
memory: 150Mi
externalRedis:
enabled: true
host: "redis-standalone"
port: "6379"
existingSecret:
enabled: true
secretName: redis
passwordKey: password
Additional context, if any
I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.
- Dominant language
- Go Template
- Stars
- 536
- Forks
- 316
- Avg merge
- 4d 16h
- Merged PRs (30d)
- 2
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from nextcloud/helm
-
No native support for REDIS_USER enviroment varPossibly taken @jholmes802 claimed this 3 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
nextcloud.openmetrics.allowedClients is silently ignored unless nextcloud.configs is setPossibly taken @JanWelker claimed this 20 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 78/100
-
Difficulty 3/5 1-2 days Newbie friendliness 55/100
Similar issues
-
Add: CartoonitoOpencheck:failed feeds:add
Difficulty 2/5 1-3 hours Newbie friendliness 63/100
iptv-org/database#37390 · 1 comment ·
Maintainers usually reply within 9 days
-
[BUG] LazyStackedTensorDictStore zeroes the last byte of a new key set on the last elementPossibly taken @peterdsharpe claimed this today. Openbug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
pytorch/tensordict#2307 ·
Maintainers usually reply within 1 day
-
Add Group doesn't trim the group name, so a spaces-only name creates a blank group and "fossy " bypasses the duplicate checkPossibly taken @bhuvan-somisetty claimed this today. Open
Difficulty 2/5 1-3 hours Newbie friendliness 90/100
fossology/fossology#3917 · 1 comment ·
Maintainers usually reply within 2 days
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
area: sql provider: sybase
Difficulty 1/5 Under an hour Newbie friendliness 83/100
Maintainers usually reply within 1 day