Describe your Issue
I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.
I already tried the following things:
- removing the custom userid set in the security context (still no permission)
- using an empty dir (will delete the other php inis there, which causes other errors)
- configuring redis myself (no success yet. It is difficult as i cannot set the redis-host env var, which triggers the entrypoint.sh)
Logs and Errors
=> Configuring PHP session handler...
==> Using Redis as PHP session handler...
/entrypoint.sh: 121: cannot create /usr/local/etc/php/conf.d/redis-session.ini: Permission denied
Describe your Environment
-
Kubernetes distribution: k3s
-
Helm Version (or App that manages helm): ArgoCD 3.5.2
-
Helm Chart Version: 9.2.6
-
values.yaml:
resources:
limits:
cpu: 1000m
memory: 1024Mi
requests:
cpu: 200m
memory: 512Mi
nextcloud:
defaultConfigs:
imaginary.config.php: true
host: nextcloud.abc.de
configs:
trustedDomains.config.php: |-
<?php
$CONFIG = array (
'trusted_domains' => array (
0 => 'localhost',
1 => 'nextcloud.abc.de',
2 => 'nextcloud.cde.de',
)
);
proxy.config.php: |-
<?php
$CONFIG = array (
'trusted_proxies' => array(
0 => '10.42.0.0/16', # Traefik IP-Range in K3s
),
'forwarded_for_headers' => array(
0 => 'HTTP_X_FORWARDED_FOR',
),
'overwriteprotocol' => 'https',
);
maintenance.config.php: |-
<?php
$CONFIG = array (
'maintenance_window_start' => 1,
);
previews.config.php: |-
<?php
$CONFIG = array (
'enable_previews' => true,
'preview_max_x' => 1024,
'preview_max_y' => 1024,
);
filePermissions.config.php: |-
<?php
$CONFIG = array (
'check_data_directory_permissions' => false,
);
region.config.php: |-
<?php
$CONFIG = array (
'default_language' => 'de',
'default_locale' => 'de',
'default_phone_region' => 'de',
'default_timezone' => 'Europe/Berlin',
);
# needs to be overwridden with NC_serverid if we scale nextcloud
serverid.config.php: |-
<?php
$CONFIG = array (
'serverid' => '259',
);
mail:
enabled: false
existingSecret:
enabled: true
secretName: nextcloud
usernameKey: nextcloud-username
passwordKey: nextcloud-password
securityContext:
runAsUser: 33
runAsGroup: 33
runAsNonRoot: true
readOnlyRootFilesystem: false # cannot login if activated. It seems that we need to have an emptyDir for the session storage
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
add:
- NET_BIND_SERVICE
podSecurityContext:
fsGroup: 33
fsGroupChangePolicy: "Always"
runAsUser: 33
runAsGroup: 33
runAsNonRoot: false
seccompProfile:
type: RuntimeDefault
extraVolumes:
- name: apache2
emptyDir: {}
extraVolumeMounts:
- name: apache2
mountPath: "/var/run/apache2"
datadir: /var/www/html/data
extraSidecarContainers:
- name: nextcloud-logger
image: busybox
command: [/bin/sh, -c, 'while ! test -f "/run/nextcloud/data/nextcloud.log"; do sleep 1; done; tail -n+1 -f /run/nextcloud/data/nextcloud.log']
volumeMounts:
- name: nextcloud-data
mountPath: /run/nextcloud/data
ingress:
enabled: true
className: "traefik"
tls:
- hosts:
- nextcloud.abc.de
service:
annotations:
traefik.ingress.kubernetes.io/service.sticky.cookie: "true"
internalDatabase:
enabled: false
externalDatabase:
enabled: true
type: mysql
host: "mariadb.mariadb.svc.cluster.local:3306"
database: nextcloud
user: nextcloud
existingSecret:
enabled: true
secretName: nextcloud-db
usernameKey: db-username
passwordKey: db-password
persistence:
# Nextcloud Data (/var/www/html)
enabled: true
size: 4Gi
storageClass: "longhorn-replicated"
nextcloudData:
enabled: true
storageClass: "smb-csi-storage-box"
size: 50Gi
livenessProbe:
enabled: false
readinessProbe:
enabled: false
cronjob:
enabled: true
type: "cronjob"
metrics:
enabled: true
securityContext:
runAsUser: 1000
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
resources:
limits:
cpu: 50m
memory: 32Mi
requests:
cpu: 10m
memory: 16Mi
imaginary:
enabled: true
image:
registry: ghcr.io
repository: nextcloud-releases/aio-imaginary
tag: 20260825_084538@sha256:fa648f3a72b2d2eea6cc33e4f01d152c299e22ef83c97e578fc093737edd6ec6
securityContext:
runAsUser: 1000
runAsNonRoot: true
allowPrivilegeEscalation: false
capabilities:
drop:
- ALL
podSecurityContext:
runAsNonRoot: true
seccompProfile:
type: RuntimeDefault
resources:
limits:
cpu: 200m
memory: 256Mi
requests:
cpu: 10m
memory: 150Mi
externalRedis:
enabled: true
host: "redis-standalone"
port: "6379"
existingSecret:
enabled: true
secretName: redis
passwordKey: password
Additional context, if any
I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.
Describe your Issue
I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.
I already tried the following things:
Logs and Errors
Describe your Environment
Kubernetes distribution: k3s
Helm Version (or App that manages helm): ArgoCD 3.5.2
Helm Chart Version: 9.2.6
values.yaml:Additional context, if any
I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.