在OpenShift 3.0 Starter中运行Cassandra镜像遇权限问题求助
Hey there, I feel your frustration with this Cassandra deployment issue—OpenShift's strict root user restrictions can be a real pain, especially in Starter environments. Let's break down some practical solutions to get this working:
1. Build a Custom Non-Root Cassandra Image
The most reliable way around this is to create your own Cassandra image that runs as a non-root user. Here's a simple Dockerfile to get you started:
# Use the official Cassandra base image FROM cassandra:3.11 # Create a non-root user and grant ownership to Cassandra data/log directories RUN useradd -m -u 1001 cassandra-runner && \ chown -R cassandra-runner:cassandra-runner /var/lib/cassandra /var/log/cassandra /etc/cassandra # Switch to the non-root user USER cassandra-runner
Build this image, push it to a container registry you can access from OpenShift, then deploy it using oc new-app with your custom image URL.
2. Adjust Deployment Security Context (If the Image Supports It)
If you don't want to build a custom image, check if the Cassandra image you're using has a pre-configured non-root user. You can force OpenShift to run the pod as a non-root UID (like 1001, OpenShift's default restricted user) with this command:
oc new-app cassandra \ --name=cassandra-cluster \ --security-context-run-as-user=1001 \ --security-context-fs-group=1001
Note: This only works if the image's file permissions are set to allow the 1001 user access to Cassandra's data and log folders. If you get permission errors, you'll need to go with the custom image approach.
3. Why the openshift-cassandra Image Might Have Failed
That specific image might not play nice with OpenShift 3.0's older security constraints. If you still want to give it another go, double-check:
- The image's Dockerfile actually switches to a non-root user (some older versions might skip this step)
- You're setting the right environment variables to let Cassandra run without root privileges
- OpenShift 3.0's restricted Security Context Constraint (SCC) allows the user ID specified in the image
If none of those check out, the custom image method is your safest bet.
Give these steps a shot, and let me know if you hit any roadblocks—I'm happy to help troubleshoot further!
内容的提问来源于stack exchange,提问作者christian130

