Bitnami Nginx Docker镜像中cp命令权限拒绝问题求助
Let's break down the root cause first: The /app directory in the Bitnami Nginx 1.16 image is defined as a Docker volume. When your container starts, Docker (or OpenShift) will mount an empty volume (or an external one you've configured) over the /app directory, completely overriding the files you copied during the build stage. That's why your --chown=1001 flag didn't fix the permission issue—those files aren't even present when the entrypoint script runs!
Here's how to resolve this properly:
1. Use Bitnami's Default Static File Directory
Bitnami's Nginx image uses /opt/bitnami/nginx/html as the default root directory for static content, and this path is not a volume. This means files copied here during the build will persist when the container starts, and the permissions are already configured for the runtime user (UID 1001).
Update your production stage in the Dockerfile:
# Production stage FROM bitnami/nginx:1.16 as production-stage # Copy build artifacts to Bitnami's default static directory COPY --from=build-stage --chown=1001 /app/dist /opt/bitnami/nginx/html COPY nginx.conf /opt/bitnami/nginx/conf/nginx.conf COPY --chown=1001 entrypoint.sh / # Fix script permission (use +x for executable, not +w) RUN chmod +x /entrypoint.sh CMD ["/entrypoint.sh"]
2. Adjust Your Entrypoint Script Paths
Update the file path in your entrypoint.sh to target the new directory:
#!/bin/bash function join_by { local IFS="$1"; shift; echo "$*"; } vars=$(env | grep VUE_APP_ | awk -F = '{print "$"$1}') vars=$(join_by ' ' $vars) # Target the new static file directory for file in /opt/bitnami/nginx/html/js/app.*; do cp $file $file.tmpl envsubst "$vars" < $file.tmpl > $file rm $file.tmpl done exec "$@"
3. Optional: Verify OpenShift Compatibility
Since you're running in OpenShift, keep in mind that OpenShift typically runs containers with a random UID instead of the fixed 1001. Luckily, Bitnami's images are designed to support this—they set file permissions on /opt/bitnami/nginx/html to allow write access for any user in the root group, so your script will still work without extra changes.
Why Your Original Approach Failed
- The
/appvolume mount overrides the files you copied during the build. - Even if you tried to modify permissions on
/app, the volume's ownership is controlled by the container runtime (Docker/OpenShift), not the image's build steps.
This approach ensures your static files are available, editable by the runtime user, and compatible with both Docker and OpenShift environments.
内容的提问来源于stack exchange,提问作者vahdet

