Cloud Run Gen2部署Atlantis时Git克隆权限报错求助
问题
在Cloud Run Gen2上部署Atlantis并通过gcsfuse挂载GCS存储桶时,Atlantis服务器可正常启动,但执行atlantis plan克隆Git仓库时出现以下错误:
running git clone --branch f/gcsfuse-cloudrun --depth=1 --single-branch https://xxxxxxxx:<redacted>@github.com/xxxxxxxx/xxxxxxxx.git /app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default: Cloning into '/app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default'... error: chmod on /app/atlantis/repos/xxxxxxxx/xxxxxxxx/29/default/.git/config.lock failed: Operation not permitted fatal: could not set 'core.filemode' to 'false' : exit status 128
附当前使用的Dockerfile和入口脚本:
Dockerfile
FROM ghcr.io/runatlantis/atlantis:v0.21.1-pre.20221213-debian USER root # Install Python ENV PYTHONUNBUFFERED=1 RUN apt-get update -y RUN apt-get install -y python3 python3-pip # Install system dependencies RUN set -e; \ apt-get update -y && apt-get install -y \ tini \ lsb-release; \ gcsFuseRepo=gcsfuse-`lsb_release -c -s`; \ echo "deb http://packages.cloud.google.com/apt $gcsFuseRepo main" | \ tee /etc/apt/sources.list.d/gcsfuse.list; \ curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | \ apt-key add -; \ apt-get update; \ apt-get install -y gcsfuse \ && apt-get clean # Set fallback mount directory ENV MNT_DIR /app/atlantis # Create mount directory for service RUN mkdir -p ${MNT_DIR} RUN chown -R atlantis /app/atlantis/ RUN chmod -R 777 /app/atlantis/ WORKDIR $MNT_DIR # Copy local code to the container image. ENV APP_HOME /app WORKDIR $APP_HOME COPY gcsfuse_run.sh ./ # Make the script an executable RUN chmod +x /app/gcsfuse_run.sh ENTRYPOINT ["/app/gcsfuse_run.sh"]
入口脚本 gcsfuse_run.sh
#!/usr/bin/env bash set -eo pipefail echo "Mounting GCS Fuse to $MNT_DIR" gcsfuse -o allow_other -file-mode=777 -dir-mode=777 --implicit-dirs --debug_gcs --debug_fuse $BUCKET $MNT_DIR echo "Mounting completed." # This is a atlantis provided docker script that comes from the base image /usr/local/bin/docker-entrypoint.sh server
解决方案
错误核心原因是gcsfuse不支持部分POSIX文件系统操作(如chmod修改文件模式),而Git尝试修改core.filemode时触发了该限制,以下是具体修复步骤:
1. 调整gcsfuse挂载参数
添加-o default_permissions和--disable-mod-times参数,规避gcsfuse的权限操作限制:
gcsfuse -o allow_other -o default_permissions -file-mode=777 -dir-mode=777 --implicit-dirs --disable-mod-times --debug_gcs --debug_fuse $BUCKET $MNT_DIR
2. 全局禁用Git的core.filemode
在Dockerfile中添加Git全局配置,避免Git尝试修改文件权限模式:
RUN git config --global core.filemode false
3. 切换回atlantis用户启动服务
在入口脚本中使用atlantis用户执行Atlantis启动命令,避免root用户操作带来的权限冲突:
su - atlantis -c "/usr/local/bin/docker-entrypoint.sh server"
修改后的完整文件
修改后的Dockerfile
FROM ghcr.io/runatlantis/atlantis:v0.21.1-pre.20221213-debian USER root # Install Python ENV PYTHONUNBUFFERED=1 RUN apt-get update -y RUN apt-get install -y python3 python3-pip # Install system dependencies RUN set -e; \ apt-get update -y && apt-get install -y \ tini \ lsb-release; \ gcsFuseRepo=gcsfuse-`lsb_release -c -s`; \ echo "deb http://packages.cloud.google.com/apt $gcsFuseRepo main" | \ tee /etc/apt/sources.list.d/gcsfuse.list; \ curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | \ apt-key add -; \ apt-get update; \ apt-get install -y gcsfuse git \ && apt-get clean # 全局禁用Git的core.filemode,避免权限修改操作 RUN git config --global core.filemode false # Set fallback mount directory ENV MNT_DIR /app/atlantis # Create mount directory for service RUN mkdir -p ${MNT_DIR} RUN chown -R atlantis /app/atlantis/ RUN chmod -R 777 /app/atlantis/ WORKDIR $MNT_DIR # Copy local code to the container image. ENV APP_HOME /app WORKDIR $APP_HOME COPY gcsfuse_run.sh ./ # Make the script an executable RUN chmod +x /app/gcsfuse_run.sh ENTRYPOINT ["/app/gcsfuse_run.sh"]
修改后的入口脚本 gcsfuse_run.sh
#!/usr/bin/env bash set -eo pipefail echo "Mounting GCS Fuse to $MNT_DIR" # 添加default_permissions和disable-mod-times参数 gcsfuse -o allow_other -o default_permissions -file-mode=777 -dir-mode=777 --implicit-dirs --disable-mod-times --debug_gcs --debug_fuse $BUCKET $MNT_DIR echo "Mounting completed." # 切换回atlantis用户启动Atlantis su - atlantis -c "/usr/local/bin/docker-entrypoint.sh server"
内容的提问来源于stack exchange,提问作者Bruno Schaatsbergen
相关产品推荐
相关产品推荐

