如何更改官方docker镜像nginx的nginx进程用户?

ddi*_*hev 8 nginx docker

我正在使用Docker Hub的官方nginx图像:https: //hub.docker.com/_/nginx/

nginx的用户(在/etc/nginx/nginx.conf中定义)是nginx.有没有办法让nginx运行www-data而不必扩展docker镜像?这样做的原因是,我有一个共享卷,所使用的多个集装箱- php-fpm我正在运行的www-data和nginx.文件/目录的共享卷的所有者www-data:www-data和nginx具有访问麻烦-类似错误*1 stat() "/app/frontend/web/" failed (13: Permission denied)

我有一个docker-compose.yml并运行我的所有容器,包括nginx docker-compose up.

  ...
  nginx:
    image: nginx:latest
    ports:
      - "80:80"
    volumes:
      - ./:/app
      - ./vhost.conf:/etc/nginx/conf.d/vhost.conf
    links:
      - fpm

  ...
Run Code Online (Sandbox Code Playgroud)

ash*_*rov 7

FYI

  1. 这是php-fpm图像的问题
  2. 它不是关于用户名,而是关于www-data用户ID

该怎么办

修复你的php-fpm容器,不要破坏好的nginx容器.

解决方案

  • 为什么是1000???nginx 容器中的 Nginx 用户不是“1000”,因此无权读取“php-fpm”创建的文件 (6认同)

ber*_*nie 5

我知道 OP 要求提供一个不扩展 nginx 映像的解决方案,但我已经在没有这种限制的情况下登陆了这里。所以我做了这个Dockerfile来运行 nginx 作为www-data:www-data( 33:33) :

FROM nginx:1.17

# Customization of the nginx user and group ids in the image. It's 101:101 in
# the base image. Here we use 33 which is the user id and group id for www-data
# on Ubuntu, Debian, etc.
ARG nginx_uid=33
ARG nginx_gid=33

# The worker processes in the nginx image run as the user nginx with group
# nginx. This is where we override their respective uid and guid to something
# else that lines up better with file permissions.
# The -o switch allows reusing an existing user id
RUN usermod -u $nginx_uid -o nginx && groupmod -g $nginx_gid -o nginx
Run Code Online (Sandbox Code Playgroud)

它在映像构建期间接受命令行上的 uid 和 gid。制作一个以当前用户 ID 和组 ID 运行的 nginx 镜像,例如:

docker build --build-arg nginx_uid=$(id -u) nginx_uid=$(id -g) .
Run Code Online (Sandbox Code Playgroud)

nginx 用户和组 ID 当前硬编码到101:101图像中。