Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

External Redis not working: redis-session.ini: Permission denied

未关闭
#883 1 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

@antoinetran 已经在做这个了。

开始于 2026年9月16日。

  • #886 来自 @antoinetran —— 未关闭

评估

难度
3/5
预计耗时
1-2 天
新手友好度
55/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
活跃
技术栈
helm, kubernetes

调研方向

从 values.yaml 和报告中提到的 chart 的 entrypoint.sh 路径开始,然后在启用 externalRedis 并使用所示 non-root 安全上下文的情况下复现部署。追踪 entrypoint.sh 无法创建 redis-session.ini 的原因;当外部 Redis 在受支持的强化安全设置下运行且不再出现权限错误时即完成。

由索引模型根据 Issue 内容生成。

描述

Describe your Issue

I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.

I already tried the following things:

  • removing the custom userid set in the security context (still no permission)
  • using an empty dir (will delete the other php inis there, which causes other errors)
  • configuring redis myself (no success yet. It is difficult as i cannot set the redis-host env var, which triggers the entrypoint.sh)
Logs and Errors
=> Configuring PHP session handler...
==> Using Redis as PHP session handler...
/entrypoint.sh: 121: cannot create /usr/local/etc/php/conf.d/redis-session.ini: Permission denied

Describe your Environment

  • Kubernetes distribution: k3s

  • Helm Version (or App that manages helm): ArgoCD 3.5.2

  • Helm Chart Version: 9.2.6

  • values.yaml:

resources:
  limits:
    cpu: 1000m
    memory: 1024Mi
  requests:
    cpu: 200m
    memory: 512Mi

nextcloud:
  defaultConfigs:
    imaginary.config.php: true
  host: nextcloud.abc.de
  configs:
    trustedDomains.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_domains' => array (
          0 => 'localhost',
          1 => 'nextcloud.abc.de',
          2 => 'nextcloud.cde.de',
        )
      );
    proxy.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_proxies' => array(
          0 => '10.42.0.0/16',  # Traefik IP-Range in K3s
        ),
        'forwarded_for_headers' => array(
          0 => 'HTTP_X_FORWARDED_FOR',
        ),
        'overwriteprotocol' => 'https',
      );
    maintenance.config.php: |-
      <?php
      $CONFIG = array (
        'maintenance_window_start' => 1,
      );
    previews.config.php: |-
      <?php
      $CONFIG = array (
        'enable_previews' => true,
        'preview_max_x' => 1024,
        'preview_max_y' => 1024,
      );
    filePermissions.config.php: |-
      <?php
      $CONFIG = array (
        'check_data_directory_permissions' => false,
      );
    region.config.php: |-
      <?php
      $CONFIG = array (
        'default_language' => 'de',
        'default_locale' => 'de',
        'default_phone_region' => 'de',
        'default_timezone' => 'Europe/Berlin',
      );
    # needs to be overwridden with NC_serverid if we scale nextcloud
    serverid.config.php: |-
      <?php
      $CONFIG = array (
        'serverid' => '259',
      );

  mail:
    enabled: false
  existingSecret:
    enabled: true
    secretName: nextcloud
    usernameKey: nextcloud-username
    passwordKey: nextcloud-password
  securityContext:
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: true
    readOnlyRootFilesystem: false # cannot login if activated. It seems that we need to have an emptyDir for the session storage
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
      add:
        - NET_BIND_SERVICE
  podSecurityContext:
    fsGroup: 33
    fsGroupChangePolicy: "Always"
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: false
    seccompProfile:
      type: RuntimeDefault
  extraVolumes:
    - name: apache2
      emptyDir: {}
  extraVolumeMounts:
    - name: apache2
      mountPath: "/var/run/apache2"
  datadir: /var/www/html/data
  extraSidecarContainers:
  - name: nextcloud-logger
    image: busybox
    command: [/bin/sh, -c, 'while ! test -f "/run/nextcloud/data/nextcloud.log"; do sleep 1; done; tail -n+1 -f /run/nextcloud/data/nextcloud.log']
    volumeMounts:
    - name: nextcloud-data
      mountPath: /run/nextcloud/data

ingress:
  enabled: true
  className: "traefik"
  tls:
    - hosts:
      - nextcloud.abc.de

service:
  annotations:
    traefik.ingress.kubernetes.io/service.sticky.cookie: "true"

internalDatabase:
  enabled: false

externalDatabase:
  enabled: true
  type: mysql
  host: "mariadb.mariadb.svc.cluster.local:3306"
  database: nextcloud
  user: nextcloud
  existingSecret:
    enabled: true
    secretName: nextcloud-db
    usernameKey: db-username
    passwordKey: db-password

persistence:
  # Nextcloud Data (/var/www/html)
  enabled: true
  size: 4Gi
  storageClass: "longhorn-replicated"
  nextcloudData:
    enabled: true
    storageClass: "smb-csi-storage-box"
    size: 50Gi

livenessProbe:
  enabled: false
readinessProbe:
  enabled: false

cronjob:
  enabled: true
  type: "cronjob"

metrics:
  enabled: true
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 50m
      memory: 32Mi
    requests:
      cpu: 10m
      memory: 16Mi

imaginary:
  enabled: true
  image:
    registry: ghcr.io
    repository: nextcloud-releases/aio-imaginary
    tag: 20260825_084538@sha256:fa648f3a72b2d2eea6cc33e4f01d152c299e22ef83c97e578fc093737edd6ec6
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
      - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 200m
      memory: 256Mi
    requests:
      cpu: 10m
      memory: 150Mi

externalRedis:
  enabled: true
  host: "redis-standalone"
  port: "6379"
  existingSecret:
    enabled: true
    secretName: redis
    passwordKey: password

Additional context, if any

I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.

主要语言
Go Template
星标
536
派生
316
平均合并
4 天 16 小时
30 天内合并 PR
2

环境准备

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

nextcloud/helm 的其他 Issue

查看 nextcloud/helm 的全部 Issue

相似的 Issue

更多 Databases Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。