使用redhat-actions/buildah-build@v2构建镜像遇权限错误求助
问题分析与解决方案
核心问题定位
报错chown /home/runner/.local/share/containers/storage/overlay/l: operation not permitted是由于GitHub Actions Linux Runner的非root运行环境与Buildah默认使用的overlay存储驱动不兼容导致的。在用户命名空间下,Buildah无法对overlay存储层进行chown操作,这和你使用的openshift/origin-cli基础镜像无关。
具体修复步骤
1. 修改Build步骤的存储驱动
在buildah-build动作中添加additional-build-args参数,强制使用vfs存储驱动(该驱动不需要权限修改,适配非root环境):
- name: Build id: build-image uses: redhat-actions/buildah-build@v2 with: image: some-image tags: latest containerfiles: ./config/Dockerfile tls-verify: false additional-build-args: "--storage-driver vfs"
2. 简化Podman登录流程
你手动创建config.json的操作多余且易引发权限问题,直接删除Pre-Login步骤,并调整podman-login的auth_file_path到Runner有权限的路径:
- name: Login uses: redhat-actions/podman-login@v1 with: registry: some.repo.com username: ${{ secrets.USERNAME }} password: ${{ secrets.PASSWORD }} auth_file_path: /home/runner/.docker/config.json
3. 修复Dockerfile冗余命令
切换到USER root后无需再使用sudo,同时修正Maven命令拼写(正确命令为mvn):
FROM .../openshift/origin-cli:4.10 USER root RUN yum update -y && yum install -y maven RUN mvn -version RUN oc version
额外优化建议
- 若Buildah存储问题仍无法解决,可尝试替换为
docker/build-push-action动作,GitHub官方Linux Runner对Docker的适配性更完善。 - 若坚持使用Buildah,可在Workflow中修改
storage.conf,将存储根目录设置到/tmp(Runner对该目录有完全权限):
- name: Adjust Storage Config run: | sudo sed -i 's|graphroot = "/var/lib/containers/storage"|graphroot = "/tmp/containers/storage"|' /etc/containers/storage.conf
内容的提问来源于stack exchange,提问作者lpkej
相关产品推荐
相关产品推荐

