Broken NPM cache folder settings do not allow running image without root
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 4/5
- Tempo estimado
- 3-5 dias
- Facilidade para iniciantes
- 48/100
- Tipo de issue
- Bug
- Clareza
- Razoavelmente clara
- Status de atividade
- Pouca atividade
- Stack de tecnologia
- docker, node.js
- Domínio
- devops, infrastructure
Direção de pesquisa
Comece inspecionando a configuração da imagem Docker em busca de npm_config_prefix, npm_config_userconfig, HOME e locais de cache graváveis. Reproduza o pipeline do Jenkins reportado como um usuário não root e com um sistema de arquivos raiz somente leitura. Está concluído quando npm ci, npm run build e npm publish funcionarem sem exigir root nem uma substituição do cache por execução.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Environment
- Platform: Linux
- Docker Version: Docker Engine v29 (but can be replicated with older versions)
- Node.js Version: LTS 24 and 22 (can be replicated with all versions from v16)
- Image Tag: 22.22.2-alpine
Expected Behavior
Unmodified Node.js Docker image should be runnable without root privileges.
Current Behavior
The image is completely broken as a base build image in environments where one could not modify a running user, e.g., on Jenkins pipelines which by default run under Jenkins user and the UID is most probably not the same as UID 1000 which is used in the image. The same issue can be observed on the free GitHub Actions runners.
It is also broken as a base runtime image on read-only root filesystem environments, e.g., Kubernetes containers with readOnlyRootFilesystem: true.
The source of these issues is that npm_config_prefix is set to /usr/local and npm_config_userconfig is not set at all, so NPM is trying to use HOME folder which in the docker image is set to /. That folder is not writable by any of the users except root.
The only workaround on Jenkins is to set NPM_CONFIG_CACHE to something like /tmp/jenkins/.npm. GitLab/GitHub runners can be fixed in similar manner.
Possible Solution
The real fix should be to create .npm cache folder somewhere writable by any user on the docker image, so at least it works by default on CI pipelines. Maybe create some kind of documented folder specified via npm_config_userconfig so anyone can map it and modify the behaviour of a running user.
Steps to Reproduce
Create a Jenkins pipeline for any Node.js project using NPM and try to build it:
pipeline {
agent {
docker {
image 'node:22.22.2'
}
}
stages {
stage('Build and publish') {
steps {
sh "npm ci"
sh "npm run build"
sh "npm publish"
}
}
}
}
12:51:45 npm error code EACCES
12:51:45 npm error syscall mkdir
12:51:45 npm error path /.npm
12:51:45 npm error errno EACCES
12:51:45 npm error
12:51:45 npm error Your cache folder contains root-owned files, due to a bug in
12:51:45 npm error previous versions of npm which has since been addressed.
12:51:45 npm error
12:51:45 npm error To permanently fix this problem, please run:
12:51:45 npm error sudo chown -R 1002:1002 "/.npm"
Additional Information
I chose Jenkins as an example. The same issue can be reproduced in any CI/CD environment which doesn't run under root user: rootless Docker, GitHub Actions, etc.
As evident from the past, considering cryptic and sometimes incorrect error messages coming from NPM, people constantly struggle to understand why it doesn't work for them in one way or another:
https://github.com/nodejs/docker-node/issues/1734
https://github.com/npm/cli/issues/3910
I know that there are some practices documented how to run this image without a root user, but that's not the point of this ticket. It can be fixed at the source of this image without the need to use all those workarounds.
- Linguagem predominante
- Dockerfile
- Estrelas
- 8.6k
- Forks
- 2k
- Merge médio
- 10h 19min
- PRs com merge (30d)
- 16
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de nodejs/docker-node
-
build process docs
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
nodejs/docker-node#2564 · 2 comentários ·
-
build process
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
nodejs/docker-node#2437 ·
-
build process
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 64/100
nodejs/docker-node#2436 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
nodejs/docker-node#1779 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
nodejs/docker-node#1707 · 3 comentários · 7 reações ·
Todas as issues de nodejs/docker-node
Issues semelhantes
-
kind/bug needs-triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 72/100
matrixorigin/matrixone#29223 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 84/100
copse-dev/agent-pane#2953 ·
-
bug ci-failure high priority
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
vllm-project/vllm-omni#7972 · 1 comentário ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 90/100
simonw/sqlite-utils#872 ·
-
bug good first issue
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 88/100
amponce/archive-movie-browser#166 ·