Skip to content

External Redis not working: redis-session.ini: Permission denied #883

Description

@alexander-dammeier

Describe your Issue

I configured an external redis instance. If it is enabled i got a Permission denied error from the /entrypoint.sh as it tries to set php ini config.

I already tried the following things:

  • removing the custom userid set in the security context (still no permission)
  • using an empty dir (will delete the other php inis there, which causes other errors)
  • configuring redis myself (no success yet. It is difficult as i cannot set the redis-host env var, which triggers the entrypoint.sh)

Logs and Errors

=> Configuring PHP session handler...
==> Using Redis as PHP session handler...
/entrypoint.sh: 121: cannot create /usr/local/etc/php/conf.d/redis-session.ini: Permission denied

Describe your Environment

  • Kubernetes distribution: k3s

  • Helm Version (or App that manages helm): ArgoCD 3.5.2

  • Helm Chart Version: 9.2.6

  • values.yaml:

resources:
  limits:
    cpu: 1000m
    memory: 1024Mi
  requests:
    cpu: 200m
    memory: 512Mi

nextcloud:
  defaultConfigs:
    imaginary.config.php: true
  host: nextcloud.abc.de
  configs:
    trustedDomains.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_domains' => array (
          0 => 'localhost',
          1 => 'nextcloud.abc.de',
          2 => 'nextcloud.cde.de',
        )
      );
    proxy.config.php: |-
      <?php
      $CONFIG = array (
        'trusted_proxies' => array(
          0 => '10.42.0.0/16',  # Traefik IP-Range in K3s
        ),
        'forwarded_for_headers' => array(
          0 => 'HTTP_X_FORWARDED_FOR',
        ),
        'overwriteprotocol' => 'https',
      );
    maintenance.config.php: |-
      <?php
      $CONFIG = array (
        'maintenance_window_start' => 1,
      );
    previews.config.php: |-
      <?php
      $CONFIG = array (
        'enable_previews' => true,
        'preview_max_x' => 1024,
        'preview_max_y' => 1024,
      );
    filePermissions.config.php: |-
      <?php
      $CONFIG = array (
        'check_data_directory_permissions' => false,
      );
    region.config.php: |-
      <?php
      $CONFIG = array (
        'default_language' => 'de',
        'default_locale' => 'de',
        'default_phone_region' => 'de',
        'default_timezone' => 'Europe/Berlin',
      );
    # needs to be overwridden with NC_serverid if we scale nextcloud
    serverid.config.php: |-
      <?php
      $CONFIG = array (
        'serverid' => '259',
      );

  mail:
    enabled: false
  existingSecret:
    enabled: true
    secretName: nextcloud
    usernameKey: nextcloud-username
    passwordKey: nextcloud-password
  securityContext:
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: true
    readOnlyRootFilesystem: false # cannot login if activated. It seems that we need to have an emptyDir for the session storage
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
      add:
        - NET_BIND_SERVICE
  podSecurityContext:
    fsGroup: 33
    fsGroupChangePolicy: "Always"
    runAsUser: 33
    runAsGroup: 33
    runAsNonRoot: false
    seccompProfile:
      type: RuntimeDefault
  extraVolumes:
    - name: apache2
      emptyDir: {}
  extraVolumeMounts:
    - name: apache2
      mountPath: "/var/run/apache2"
  datadir: /var/www/html/data
  extraSidecarContainers:
  - name: nextcloud-logger
    image: busybox
    command: [/bin/sh, -c, 'while ! test -f "/run/nextcloud/data/nextcloud.log"; do sleep 1; done; tail -n+1 -f /run/nextcloud/data/nextcloud.log']
    volumeMounts:
    - name: nextcloud-data
      mountPath: /run/nextcloud/data

ingress:
  enabled: true
  className: "traefik"
  tls:
    - hosts:
      - nextcloud.abc.de

service:
  annotations:
    traefik.ingress.kubernetes.io/service.sticky.cookie: "true"

internalDatabase:
  enabled: false

externalDatabase:
  enabled: true
  type: mysql
  host: "mariadb.mariadb.svc.cluster.local:3306"
  database: nextcloud
  user: nextcloud
  existingSecret:
    enabled: true
    secretName: nextcloud-db
    usernameKey: db-username
    passwordKey: db-password

persistence:
  # Nextcloud Data (/var/www/html)
  enabled: true
  size: 4Gi
  storageClass: "longhorn-replicated"
  nextcloudData:
    enabled: true
    storageClass: "smb-csi-storage-box"
    size: 50Gi

livenessProbe:
  enabled: false
readinessProbe:
  enabled: false

cronjob:
  enabled: true
  type: "cronjob"

metrics:
  enabled: true
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
        - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 50m
      memory: 32Mi
    requests:
      cpu: 10m
      memory: 16Mi

imaginary:
  enabled: true
  image:
    registry: ghcr.io
    repository: nextcloud-releases/aio-imaginary
    tag: 20260825_084538@sha256:fa648f3a72b2d2eea6cc33e4f01d152c299e22ef83c97e578fc093737edd6ec6
  securityContext:
    runAsUser: 1000
    runAsNonRoot: true
    allowPrivilegeEscalation: false
    capabilities:
      drop:
      - ALL
  podSecurityContext:
    runAsNonRoot: true
    seccompProfile:
      type: RuntimeDefault
  resources:
    limits:
      cpu: 200m
      memory: 256Mi
    requests:
      cpu: 10m
      memory: 150Mi

externalRedis:
  enabled: true
  host: "redis-standalone"
  port: "6379"
  existingSecret:
    enabled: true
    secretName: redis
    passwordKey: password

Additional context, if any

I try to harden my nextcloud installation as much as possible. That is very hard given how nextcloud works, unfortunately.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions