Docker Compose部署Airflow挂载CIFS驱动器写入权限拒绝问题
Apache Airflow挂载网络驱动器后写入权限被拒的问题
我正在尝试为Apache Airflow添加一个可读写的网络驱动器,目前已能读取该目录,但通过DAG执行写入操作时收到"Permission Denied"错误。请问是否需要修复权限配置以实现写入?
docker-compose.yml 配置
--- version: '3' x-airflow-common: &airflow-common # In order to add custom dependencies or upgrade provider packages you can use your extended image. # Comment the image line, place your Dockerfile in the directory where you placed the docker-compose.yaml # and uncomment the "build" line below, Then run `docker-compose build` to build the images. #image: ${AIRFLOW_IMAGE_NAME:-apache/airflow:2.3.3} build: . env_file: - .env environment: &airflow-common-env AIRFLOW__CORE__EXECUTOR: CeleryExecutor AIRFLOW__DATABASE__SQL_ALCHEMY_CONN: postgresql+psycopg2://airflow:airflow@postgres/airflow # For backward compatibility, with Airflow <2.3 AIRFLOW__CORE__SQL_ALCHEMY_CONN: postgresql+psycopg2://airflow:airflow@postgres/airflow AIRFLOW__CELERY__RESULT_BACKEND: db+postgresql://airflow:airflow@postgres/airflow AIRFLOW__CELERY__BROKER_URL: redis://:@redis:6379/0 AIRFLOW__CORE__FERNET_KEY: '' AIRFLOW__CORE__DAGS_ARE_PAUSED_AT_CREATION: 'true' AIRFLOW__CORE__LOAD_EXAMPLES: 'false' AIRFLOW__API__AUTH_BACKENDS: 'airflow.api.auth.backend.basic_auth' AIRFLOW__EMAIL__EMAIL_BACKEND: 'airflow.utils.email.send_email_smtp' AIRFLOW__EMAIL__DEFAULT_EMAIL_ON_RETRY: True AIRFLOW__EMAIL__DEFAULT_EMAIL_ON_FAILURE: True AIRFLOW__SMTP__SMTP_HOST: 'mail.precorp.org' AIRFLOW__SMTP__SMTP_STARTTLS: True AIRFLOW__SMTP__SMTP_SSL: False AIRFLOW__SMTP__SMTP_PORT: 25 AIRFLOW__SMTP__SMTP_MAIL_FROM: 'gis@precorp.coop' AIRFLOW__WEBSERVER__BASE_URL: 'http://10.54.0.25:8080' _PIP_ADDITIONAL_REQUIREMENTS: ${_PIP_ADDITIONAL_REQUIREMENTS:-} volumes: - ./dags:/opt/airflow/dags - ./logs:/opt/airflow/logs - ./plugins:/opt/airflow/plugins - gissa:/gissa user: "${AIRFLOW_UID:-50000}:0" depends_on: &airflow-common-depends-on redis: condition: service_healthy postgres: condition: service_healthy services: postgres: image: postgres:13 environment: POSTGRES_USER: airflow POSTGRES_PASSWORD: airflow POSTGRES_DB: airflow volumes: - postgres-db-volume:/var/lib/postgresql/data healthcheck: test: ["CMD", "pg_isready", "-U", "airflow"] interval: 5s retries: 5 restart: always redis: image: redis:latest expose: - 6379 healthcheck: test: ["CMD", "redis-cli", "ping"] interval: 5s timeout: 30s retries: 50 restart: always airflow-webserver: <<: *airflow-common command: webserver ports: - 8080:8080 healthcheck: test: ["CMD", "curl", "--fail", "http://localhost:8080/health"] interval: 10s timeout: 10s retries: 5 restart: always depends_on: <<: *airflow-common-depends-on airflow-init: condition: service_completed_successfully airflow-scheduler: <<: *airflow-common command: scheduler healthcheck: test: ["CMD-SHELL", 'airflow jobs check --job-type SchedulerJob --hostname "$${HOSTNAME}"'] interval: 10s timeout: 10s retries: 5 restart: always depends_on: <<: *airflow-common-depends-on airflow-init: condition: service_completed_successfully airflow-worker: <<: *airflow-common command: celery worker healthcheck: test: - "CMD-SHELL" - 'celery --app airflow.executors.celery_executor.app inspect ping -d "celery@$${HOSTNAME}"' interval: 10s timeout: 10s retries: 5 env_file: - .env environment: <<: *airflow-common-env # Required to handle warm shutdown of the celery workers properly # See https://airflow.apache.org/docs/docker-stack/entrypoint.html#signal-propagation DUMB_INIT_SETSID: "0" restart: always depends_on: <<: *airflow-common-depends-on airflow-init: condition: service_completed_successfully airflow-triggerer: <<: *airflow-common command: triggerer healthcheck: test: ["CMD-SHELL", 'airflow jobs check --job-type TriggererJob --hostname "$${HOSTNAME}"'] interval: 10s timeout: 10s retries: 5 restart: always depends_on: <<: *airflow-common-depends-on airflow-init: condition: service_completed_successfully airflow-init: <<: *airflow-common entrypoint: /bin/bash # yamllint disable rule:line-length command: - -c - | function ver() { printf "%04d%04d%04d%04d" $${1//./ } } airflow_version=$$(AIRFLOW__LOGGING__LOGGING_LEVEL=INFO && gosu airflow airflow version) airflow_version_comparable=$$(ver $${airflow_version}) min_airflow_version=2.2.0 min_airflow_version_comparable=$$(ver $${min_airflow_version}) if (( airflow_version_comparable < min_airflow_version_comparable )); then echo echo -e "\033[1;31mERROR!!!: Too old Airflow version $${airflow_version}!\e[0m" echo "The minimum Airflow version supported: $${min_airflow_version}. Only use this or higher!" echo exit 1 fi if [[ -z "${AIRFLOW_UID}" ]]; then echo echo -e "\033[1;33mWARNING!!!: AIRFLOW_UID not set!\e[0m" echo "If you are on Linux, you SHOULD follow the instructions below to set " echo "AIRFLOW_UID environment variable, otherwise files will be owned by root." echo "For other operating systems you can get rid of the warning with manually created .env file:" echo " See: https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html#setting-the-right-airflow-user" echo fi one_meg=1048576 mem_available=$$(($$(getconf _PHYS_PAGES) * $$(getconf PAGE_SIZE) / one_meg)) cpus_available=$$(grep -cE 'cpu[0-9]+' /proc/stat) disk_available=$$(df / | tail -1 | awk '{print $$4}') warning_resources="false" if (( mem_available < 4000 )) ; then echo echo -e "\033[1;33mWARNING!!!: Not enough memory available for Docker.\e[0m" echo "At least 4GB of memory required. You have $$(numfmt --to iec $$((mem_available * one_meg)))" echo warning_resources="true" fi if (( cpus_available < 2 )); then echo echo -e "\033[1;33mWARNING!!!: Not enough CPUS available for Docker.\e[0m" echo "At least 2 CPUs recommended. You have $${cpus_available}" echo warning_resources="true" fi if (( disk_available < one_meg * 10 )); then echo echo -e "\033[1;33mWARNING!!!: Not enough Disk space available for Docker.\e[0m" echo "At least 10 GBs recommended. You have $$(numfmt --to iec $$((disk_available * 1024 )))" echo warning_resources="true" fi if [[ $${warning_resources} == "true" ]]; then echo echo -e "\033[1;33mWARNING!!!: You have not enough resources to run Airflow (see above)!\e[0m" echo "Please follow the instructions to increase amount of resources available:" echo " https://airflow.apache.org/docs/apache-airflow/stable/start/docker.html#before-you-begin" echo fi mkdir -p /sources/logs /sources/dags /sources/plugins chown -R "${AIRFLOW_UID}:0" /sources/{logs,dags,plugins} chown -R "${AIRFLOW_UID}:0" /gissa exec /entrypoint airflow version # yamllint enable rule:line-length env_file: - .env environment: <<: *airflow-common-env _AIRFLOW_DB_UPGRADE: 'true' _AIRFLOW_WWW_USER_CREATE: 'true' _AIRFLOW_WWW_USER_USERNAME: ${_AIRFLOW_WWW_USER_USERNAME:-airflow} _AIRFLOW_WWW_USER_PASSWORD: ${_AIRFLOW_WWW_USER_PASSWORD:-airflow} _PIP_ADDITIONAL_REQUIREMENTS: '' user: "0:0" volumes: - .:/sources airflow-cli: <<: *airflow-common profiles: - debug env_file: - .env environment: <<: *airflow-common-env CONNECTION_CHECK_MAX_COUNT: "0" # Workaround for entrypoint issue. See: https://github.com/apache/airflow/issues/16252 command: - bash - -c - airflow # You can enable flower by adding "--profile flower" option e.g. docker-compose --profile flower up # or by explicitly targeted on the command line e.g. docker-compose up flower. # See: https://docs.docker.com/compose/profiles/ flower: <<: *airflow-common command: celery flower profiles: - flower ports: - 5555:5555 healthcheck: test: ["CMD", "curl", "--fail", "http://localhost:5555/"] interval: 10s timeout: 10s retries: 5 restart: always depends_on: <<: *airflow-common-depends-on airflow-init: condition: service_completed_successfully volumes: gissa: driver: local driver_opts: type: cifs o: "username=${NETWORKDRIVE_USER},password=${NETWORKDRIVE_PWD},uid=${AIRFLOW_UID},gid=${AIRFLOW_GID},forceuid,forcegid" device: "//NETWORKDRIVE/FOLDER_IN_NETWORK_DRIV postgres-db-volume:
Dockerfile 配置
FROM apache/airflow:2.3.3 COPY requirements.txt . USER root # Install ODBC-driver 17 RUN apt-get update \ && apt-get install -y curl apt-transport-https gnupg2 \ && curl https://packages.microsoft.com/keys/microsoft.asc | apt-key add - \ && curl https://packages.microsoft.com/config/debian/9/prod.list > /etc/apt/sources.list.d/mssql-release.list \ && apt-get update \ && ACCEPT_EULA=Y apt-get install -y msodbcsql17 mssql-tools \ && apt-get install unixodbc-dev -y RUN apt-get install -y libgdal-dev g++ --no-install-recommends && \ apt-get clean -y ENV CPLUS_INCLUDE_PATH=/usr/include/gdal ENV C_INCLUDE_PATH=/usr/include/gdal RUN mkdir /gissa RUN chmod -R 777 /gissa USER airflow RUN pip install GDAL==$(gdal-config --version | awk -F'[.]' '{print $1"."$2}') RUN pip install -r requirements.txt RUN pip install apache-airflow-providers-microsoft-mssql
解决方案
是的,必须调整权限配置才能实现写入,核心问题出在CIFS卷挂载参数和容器用户权限匹配上,按以下步骤修复:
补全并修正CIFS卷配置
- 首先修复
docker-compose.yml中gissa卷的device字段,补全路径和引号:device: "//NETWORKDRIVE/FOLDER_IN_NETWORK_DRIVE" - 在挂载选项
o中添加file_mode=0777,dir_mode=0777,强制设置挂载后文件和目录的读写权限,修改后的选项如下:o: "username=${NETWORKDRIVE_USER},password=${NETWORKDRIVE_PWD},uid=${AIRFLOW_UID},gid=${AIRFLOW_GID},forceuid,forcegid,file_mode=0777,dir_mode=0777"
- 首先修复
移除Dockerfile中无效的权限设置
Dockerfile中创建/gissa目录并设置777权限的操作会被卷挂载覆盖,因为卷挂载会替换容器内的目录,所以可以删除以下两行:RUN mkdir /gissa RUN chmod -R 777 /gissa验证用户ID匹配
确保.env文件中的AIRFLOW_UID和AIRFLOW_GID与Airflow容器使用的用户ID一致。可以进入worker容器执行id airflow查看实际用户ID,保证环境变量中的值与之匹配。重启服务生效
修改配置后,执行以下命令重建并重启所有服务:docker-compose down -v docker-compose build docker-compose up -d
内容的提问来源于stack exchange,提问作者WMueller
相关产品推荐
相关产品推荐

