You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Cloud Run Gen2部署Atlantis时Git克隆权限报错求助

问题

在Cloud Run Gen2上部署Atlantis并通过gcsfuse挂载GCS存储桶时,Atlantis服务器可正常启动,但执行atlantis plan克隆Git仓库时出现以下错误:

running git clone --branch f/gcsfuse-cloudrun --depth=1 --single-branch https://xxxxxxxx:<redacted>@github.com/xxxxxxxx/xxxxxxxx.git /app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default: Cloning into '/app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default'...
error: chmod on /app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default/.git/config.lock failed: Operation not permitted
fatal: could not set 'core.filemode' to 'false'
: exit status 128

附当前使用的Dockerfile和入口脚本:

Dockerfile

FROM ghcr.io/runatlantis/atlantis:v0.21.1-pre.20221213-debian

USER root

# Install Python
ENV PYTHONUNBUFFERED=1
RUN apt-get update -y
RUN apt-get install -y python3 python3-pip

# Install system dependencies
RUN set -e; \
    apt-get update -y && apt-get install -y \
    tini \
    lsb-release; \
    gcsFuseRepo=gcsfuse-`lsb_release -c -s`; \
    echo "deb http://packages.cloud.google.com/apt $gcsFuseRepo main" | \
    tee /etc/apt/sources.list.d/gcsfuse.list; \
    curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | \
    apt-key add -; \
    apt-get update; \
    apt-get install -y gcsfuse \
    && apt-get clean

# Set fallback mount directory
ENV MNT_DIR /app/atlantis

# Create mount directory for service
RUN mkdir -p ${MNT_DIR}

RUN chown -R atlantis /app/atlantis/
RUN chmod -R 777 /app/atlantis/

WORKDIR  $MNT_DIR

# Copy local code to the container image.
ENV APP_HOME /app
WORKDIR $APP_HOME
COPY gcsfuse_run.sh ./

# Make the script an executable
RUN chmod +x /app/gcsfuse_run.sh

ENTRYPOINT ["/app/gcsfuse_run.sh"]

入口脚本 gcsfuse_run.sh

#!/usr/bin/env bash
set -eo pipefail

echo "Mounting GCS Fuse to $MNT_DIR"
gcsfuse -o allow_other -file-mode=777 -dir-mode=777 --implicit-dirs --debug_gcs --debug_fuse $BUCKET $MNT_DIR 
echo "Mounting completed."

# This is a atlantis provided docker script that comes from the base image
/usr/local/bin/docker-entrypoint.sh server

解决方案

错误核心原因是gcsfuse不支持部分POSIX文件系统操作(如chmod修改文件模式),而Git尝试修改core.filemode时触发了该限制,以下是具体修复步骤:

1. 调整gcsfuse挂载参数

添加-o default_permissions和--disable-mod-times参数,规避gcsfuse的权限操作限制:

gcsfuse -o allow_other -o default_permissions -file-mode=777 -dir-mode=777 --implicit-dirs --disable-mod-times --debug_gcs --debug_fuse $BUCKET $MNT_DIR

2. 全局禁用Git的core.filemode

在Dockerfile中添加Git全局配置,避免Git尝试修改文件权限模式:

RUN git config --global core.filemode false

3. 切换回atlantis用户启动服务

在入口脚本中使用atlantis用户执行Atlantis启动命令,避免root用户操作带来的权限冲突:

su - atlantis -c "/usr/local/bin/docker-entrypoint.sh server"

修改后的完整文件

修改后的Dockerfile

FROM ghcr.io/runatlantis/atlantis:v0.21.1-pre.20221213-debian

USER root

# Install Python
ENV PYTHONUNBUFFERED=1
RUN apt-get update -y
RUN apt-get install -y python3 python3-pip

# Install system dependencies
RUN set -e; \
    apt-get update -y && apt-get install -y \
    tini \
    lsb-release; \
    gcsFuseRepo=gcsfuse-`lsb_release -c -s`; \
    echo "deb http://packages.cloud.google.com/apt $gcsFuseRepo main" | \
    tee /etc/apt/sources.list.d/gcsfuse.list; \
    curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | \
    apt-key add -; \
    apt-get update; \
    apt-get install -y gcsfuse git \
    && apt-get clean

# 全局禁用Git的core.filemode,避免权限修改操作
RUN git config --global core.filemode false

# Set fallback mount directory
ENV MNT_DIR /app/atlantis

# Create mount directory for service
RUN mkdir -p ${MNT_DIR}

RUN chown -R atlantis /app/atlantis/
RUN chmod -R 777 /app/atlantis/

WORKDIR  $MNT_DIR

# Copy local code to the container image.
ENV APP_HOME /app
WORKDIR $APP_HOME
COPY gcsfuse_run.sh ./

# Make the script an executable
RUN chmod +x /app/gcsfuse_run.sh

ENTRYPOINT ["/app/gcsfuse_run.sh"]

修改后的入口脚本 gcsfuse_run.sh

#!/usr/bin/env bash
set -eo pipefail

echo "Mounting GCS Fuse to $MNT_DIR"
# 添加default_permissions和disable-mod-times参数
gcsfuse -o allow_other -o default_permissions -file-mode=777 -dir-mode=777 --implicit-dirs --disable-mod-times --debug_gcs --debug_fuse $BUCKET $MNT_DIR 
echo "Mounting completed."

# 切换回atlantis用户启动Atlantis
su - atlantis -c "/usr/local/bin/docker-entrypoint.sh server"

内容的提问来源于stack exchange,提问作者Bruno Schaatsbergen

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 09:00:40