You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器运行Angular构建命令时遭遇EPERM权限错误

问题排查:Docker Compose运行Angular项目时EPERM权限错误

问题描述

尝试用Docker和Docker Compose容器化现有技术栈,镜像构建正常,但执行docker-compose up运行npm run build:test:watch时,出现EPERM权限错误,无法在node_modules目录下复制文件。已在Dockerfile中创建vws用户并设置目录权限,问题仍未解决。

docker-compose.yml配置

version: '3.8'

services:
  #FO
  angularproject:
    container_name: angularproject
    build:
      context: .
      dockerfile: ./bootstrap/front/Dockerfile
      args:
        project: angularproject
    command: npm run build:test:watch
    ports:
      - 4200:4200
    volumes:
      - ./angularproject/:/var/www/html/angularproject
    expose: 
      - 4200
    restart: always
    networks:
      - traefik-public
    labels:
      traefik.enable: true
      traefik.http.routers.angularproject.rule: (Host(`vws.dev`) && PathPrefix(`/angularproject`))
      traefik.http.services.angularproject.loadbalancer.server.port: 4200

  #UTILITY
  reverse-proxy:
    container_name: traefik
    image: traefik:v2.5
    command: --api.insecure=true --providers.docker
    ports:
      - "80:80"
      - "8080:8080"
    volumes:
      - "/var/run/docker.sock:/var/run/docker.sock:ro"
    networks:
      - traefik-public

networks:
  traefik-public:

Dockerfile配置

FROM node:16-buster-slim
ARG project

# set working directory
WORKDIR /var/www/html/

#install qit, openssh, libpq
RUN apt-get update && apt-get install -y openssh-client
RUN apt-get -y update && apt-get -y install git
RUN apt-get -y update && apt-get -y install libpq-dev

#ssh keyscan (we need it because there is git links in package.json)
RUN mkdir -p -m 0700 ~/.ssh
RUN ssh-keyscan bitbucket.org >> ~/.ssh/known_hosts

RUN mkdir /var/www/html/$project
RUN chmod 777 /var/www/html/$project
RUN useradd -ms /bin/bash vws
USER vws

# add `/app/node_modules/.bin` to $PATH
ENV PATH /app/node_modules/.bin:$PATH

COPY --chown=vws ./$project /var/www/html/$project
WORKDIR /var/www/html/$project
RUN rm -rf node_modules
EXPOSE 4200
RUN --mount=type=ssh npm i
# this is needed since we need build-angular dep
RUN --mount=type=ssh npm i --only=dev

错误信息

angularproject  | Error: Error on worker #1: Error: EPERM: operation not permitted, copyfile '/var/www/html/angularproject/node_modules/@asymmetrik/ngx-leaflet/dist/leaflet/layers/control/leaflet-control-layers.wrapper.js' -> '/var/www/html/angularproject/node_modules/@asymmetrik/ngx-leaflet/__ivy_ngcc__/dist/leaflet/layers/control/leaflet-control-layers.wrapper.js'

问题原因及解决方案

核心原因

本地目录挂载覆盖了容器内预构建的node_modules目录,导致权限不匹配:

  • Dockerfile构建阶段以vws用户安装的依赖,被本地挂载的./angularproject目录覆盖(若本地存在node_modules,权限属于本地用户,容器内vws用户无操作权限)
  • 挂载后的目录权限由本地文件系统控制,容器内vws用户对该目录下的node_modules无写入权限

解决方案

  1. 排除node_modules目录的挂载
    修改docker-compose.yml中的volumes配置,添加匿名卷保留容器内的node_modules,避免被本地目录覆盖:

    volumes:
      - ./angularproject/:/var/www/html/angularproject
      - /var/www/html/angularproject/node_modules
    
  2. 调整Dockerfile中的权限设置时机
    将目录权限设置放在创建用户之后,确保vws用户拥有目录所有权:

    RUN useradd -ms /bin/bash vws
    RUN mkdir /var/www/html/$project
    RUN chown -R vws:vws /var/www/html/$project
    USER vws
    

    (原Dockerfile先给目录设777再创建用户,权限逻辑不合理)

  3. 匹配本地目录与容器用户的UID
    若本地目录由root用户创建,容器内vws用户无权限操作,执行以下命令修改本地目录权限:

    chown -R 1000:1000 ./angularproject
    

    (默认useradd创建的vws用户UID为1000,可通过docker exec -it angularproject id vws确认)

  4. 在docker-compose中指定运行用户
    在angularproject服务中添加user配置,确保以vws用户运行:

    user: vws
    

内容的提问来源于stack exchange,提问作者tbarbot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 09:58:12