[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

Docker nginx permissions problem

Posted on 2014-12-12
5
Medium Priority
?
1,825 Views
Last Modified: 2014-12-12
After building...

FROM centos-7-nginx-es-export:latest

USER www-data

WORKDIR /etc/nginx

#ENTRYPOINT ["/opt/nginx-es-1.6.1-ssl1.0.1j/sbin/nginx"]
#CMD ['-c', "/etc/nginx/nginx.conf", '-g', "daemon off; client_body_temp_path /data/client_temp;"]

EXPOSE 80
EXPOSE 443


Running the following...

sudo docker run -v /var/log/nginx:/var/log/nginx:rw -v /etc/nginx/sites-enabled:/etc/nginx/sites-enabled:ro -i -t centos-7-nginx-es -c /etc/nginx/nginx.conf -g "daemon off;"

Yields...

nginx: [emerg] mkdir() "/opt/nginx-es-1.6.1-ssl1.0.1j/client_body_temp" failed (13: Permission denied)

How can I troubleshoot and correct this permissions problem?
0
Comment
Question by:bcex
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 29

Expert Comment

by:Jan Springer
ID: 40496848
what do you see with:

   sudo docker info

?
0
 

Author Comment

by:bcex
ID: 40496853
:/usr/local/src/centos-7-nginx-es$ sudo docker info
Containers: 17
Images: 100
Storage Driver: aufs
 Root Dir: /var/lib/docker/aufs
 Dirs: 134
Execution Driver: native-0.2
Kernel Version: 3.13.0-40-generic
WARNING: No swap limit support
0
 
LVL 29

Expert Comment

by:Jan Springer
ID: 40496906
It's not a docker issue then.

Have you seen this document?:

https://wincent.com/wiki/Fixing_nginx_client_body_temp_permission_denied_errors
0
 

Author Comment

by:bcex
ID: 40497212
Hello Jan,

I did come across this page, however, the URL near "The directive required is client_body_temp_path and it's documented here." links to a site that is no longer active.  Do you have any insight as to the specific configuration changes required in order to remedy this?

Thank you
0
 
LVL 29

Accepted Solution

by:
Jan Springer earned 2000 total points
ID: 40497290
Does this help?

http://stackoverflow.com/questions/21494979/file-upload-not-working-with-rails-4-in-development-using-pow-and-nginx

"The problem is not with Rails but with Nginx which is pretty evident from the nginx error.log. This question helped me understand what I was dealing with - Rails 3 + carrierwave + nginx = permission denied.

Nginx uses the client_body_temp_path directive to specify the location where it will temporarily store the uploaded files from the user request. Homebrew had set it by default to /usr/local/var/run/nginx. This folder also contains fastcgi_temp, proxy_temp, scgi_temp and uwsgi_temp for me. Nginx worker processes run with user nobody and they were not able to access these folders. I chowned all these folders to the nobody user, but that did not help.

Finally, I did

client_body_temp_path /tmp/nginx/; inside the HTTP module of my nginx.conf to make it work.

Doing a ls -l shows

drwx------  2 nobody       wheel   68 Feb  1 14:44 nginx

I am not sure why this worked inside /tmp and not inside the original /var/run/nginx. I belive I will face similar issue when I use other temp folders or in production. Will update this thread if and when that happens.

I recommend symlinking the other relevant logs like the nginx access and error log, pow access and app log to the /log directory of your Rails app. It helps in looking up errors in one of these when you face a tricky bug."
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

BIND is the most widely used Name Server. A Name Server is the one that translates a site name to it's IP address. There is a new bug in BIND (https://kb.isc.org/article/AA-01272), affecting all versions of BIND 9 from BIND 9.1.0 (inclusive) thro…
Lease-to-own eliminates the expenditure of hardware replacement and allows you to pay off the server over time. Usually, this is much cheaper than leasing servers. Think of lease-to-own as credit without interest.
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…
This lesson discusses how to use a Mainform + Subforms in Microsoft Access to find and enter data for payments on orders. The sample data comes from a custom shop that builds and sells movable storage structures that are delivered to your property. …

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question