You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用redhat-actions/buildah-build@v2构建镜像遇权限错误求助

问题分析与解决方案

核心问题定位

报错chown /home/runner/.local/share/containers/storage/overlay/l: operation not permitted是由于GitHub Actions Linux Runner的非root运行环境与Buildah默认使用的overlay存储驱动不兼容导致的。在用户命名空间下,Buildah无法对overlay存储层进行chown操作,这和你使用的openshift/origin-cli基础镜像无关。

具体修复步骤

1. 修改Build步骤的存储驱动

在buildah-build动作中添加additional-build-args参数,强制使用vfs存储驱动(该驱动不需要权限修改,适配非root环境):

- name: Build
  id: build-image
  uses: redhat-actions/buildah-build@v2
  with:
    image: some-image
    tags: latest
    containerfiles: ./config/Dockerfile
    tls-verify: false
    additional-build-args: "--storage-driver vfs"

2. 简化Podman登录流程

你手动创建config.json的操作多余且易引发权限问题,直接删除Pre-Login步骤,并调整podman-login的auth_file_path到Runner有权限的路径:

- name: Login
  uses: redhat-actions/podman-login@v1
  with:
    registry: some.repo.com
    username: ${{ secrets.USERNAME }}
    password: ${{ secrets.PASSWORD }}
    auth_file_path: /home/runner/.docker/config.json

3. 修复Dockerfile冗余命令

切换到USER root后无需再使用sudo,同时修正Maven命令拼写(正确命令为mvn):

FROM .../openshift/origin-cli:4.10
USER root

RUN yum update -y && yum install -y maven

RUN mvn -version
RUN oc version

额外优化建议

  • 若Buildah存储问题仍无法解决,可尝试替换为docker/build-push-action动作,GitHub官方Linux Runner对Docker的适配性更完善。
  • 若坚持使用Buildah,可在Workflow中修改storage.conf,将存储根目录设置到/tmp(Runner对该目录有完全权限):
- name: Adjust Storage Config
  run: |
    sudo sed -i 's|graphroot = "/var/lib/containers/storage"|graphroot = "/tmp/containers/storage"|' /etc/containers/storage.conf

内容的提问来源于stack exchange,提问作者lpkej

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.08 19:01:19