Uh oh!
There was an error while loading. Please reload this page.
Set nextcloud.podSecurityContext.fsGroup to 33 by default and allow users to configure it if needed. - #379
Set nextcloud.podSecurityContext.fsGroup to 33 by default and allow users to configure it if needed.#379jessebot wants to merge 5 commits into
nextcloud.podSecurityContext.fsGroup to 33 by default and allow users to configure it if needed.#379Conversation
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
ef312d3 to
e27d420CompareUh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
5a6eb60 to
4ee5f70Compare82 if the image.flavor is fpm-alpinepodSecurityContext.fsGroup by default; set nextcloud.securityContext by defaultpodSecurityContext.fsGroup by default; set nextcloud.securityContext by defaultpodSecurityContext.fsGroup to 33 by default; set nextcloud.securityContext by defaulta5d1faa to
180635aComparepodSecurityContext.fsGroup to 33 by default; set nextcloud.securityContext by defaultpodSecurityContext.fsGroup to 33 by defaultjessebot
commented
Apr 23, 2023
just need to rebase to fix the commits, but this seems to be okay now I think |
f6816df to
057c957Compareprovokateurin
commented
Apr 24, 2023
The name of the commit/PR is a bit misleading because fsGroup was 33 by default if using apache, so nothing changes for those cases. |
podSecurityContext.fsGroup to 33 by defaultpodSecurityContext.fsGroup to 33, even if nginx is enabledjessebot
commented
Apr 24, 2023
Fixed the PR and can fix the commits. does this work?
Happy to change it to whatever makes most sense. Also, thank you again for all your patience through this. It's been a doozy 😅 |
3f280fa to
2e62198Comparejessebot
commented
Apr 24, 2023
fixed commit message :) |
2e62198 to
8f0fbf9CompareGetting this error still in the linting step in the github workflow: maybe it has something to do with the fact that we changed the default branch from |
jessebot
commented
Apr 24, 2023
seems to be happening on another PR as well, checking something, going to do a test commit here |
jessebot
commented
Apr 24, 2023
477b13c to
8f0fbf9Comparejessebot
commented
Apr 24, 2023
provokateurin
commented
Apr 24, 2023
Yeah, Nextcloud uses a lot of GH actions and there is a max limit per org. I think some people are experimenting with adding our own runners to speed this up. |
jessebot
commented
Apr 24, 2023
Oh, thank you for letting me know! Then I will not try to cancel and re-run them. Sorry about doing that earlier. I only tried to cancel and rerun one of them after it'd been over 15 minutes, because I thought there was something wrong with my own rate limiting, because I do a lot of stuff on github. 😅 |
jessebot
commented
Apr 24, 2023
CI finished, this is a working PR, finally! |
Uh oh!
There was an error while loading. Please reload this page.
add note in README about alpine containers needing to change to 82 manually this ensures our defaults work when using image.flavor fpm or apache Signed-off-by: Jesse Hitch <jessebot@linux.com>
Signed-off-by: JesseBot <jessebot@linux.com> Signed-off-by: Jesse Hitch <jessebot@linux.com>
9d42830 to
fa070ccCompareSigned-off-by: JesseBot <jessebot@linux.com>
I haven't merged this because I switched to using the |
jessebot
commented
Nov 29, 2023
ok, I have to begrudgingly reopen this because I want to solve #367 but if this is not merged, then I cannot test using the fpm container with no nginx container. |
Signed-off-by: JesseBot <jessebot@linux.com>
podSecurityContext.fsGroup to 33, even if nginx is enablednextcloud.podSecurityContext.fsGroup to 33 by default and allow users to configure it if needed.Signed-off-by: JesseBot <jessebot@linux.com>
| | `nextcloud.securityContext` | Optional security context for the NextCloud container | `nil` | | ||
| | `nextcloud.podSecurityContext` | Optional security context for the NextCloud pod (applies to all containers in the pod) | `nil` | | ||
| | `nextcloud.podSecurityContext` | Optional security context for the NextCloud pod (applies to all containers in the pod) | `{fsgroup: 33}` | | ||
| | `nextcloud.podSecurityContext.fsGroup` | special supplemental group that applies to all containers in the NextCloud pod | `33` | |
There was a problem hiding this comment.
duplicated with the line above
There was a problem hiding this comment.
should I combine the description of both? 🤔 Do you prefer we keep the parameter line of 141 or 142? (also congrats on being a collaborator now!! 🎉 )
| # runAsUser: 33 | ||
| # runAsGroup: 33 | ||
| # runAsNonRoot: true | ||
| # readOnlyRootFilesystem: false |
There was a problem hiding this comment.
is not part of podSecurityContext
| {{- toYaml . | nindent 8 }} | ||
| {{- end }} | ||
| securityContext: | ||
| # this is deprecated and will be removed in a future release - use nextcloud.podSecurityContext instead |
There was a problem hiding this comment.
Should we drop securityContext now? And announce it as a breaking change?

Pull Request
Description of the change
Changes default fsGroup to be
33. In allapacheand regularfpm, thewww-datauser is33.The
www-datauser is82in all alpine images (including nginx), so I added a note in the README about it.Previously we relied on if the user was using
nginx.enabledwhich is alpine by default, but usingnginx:alpinedoesn't mean you're usingnextcloud:fpm-alpine.Benefits
If someone uses
image.flavorofapacheorfpm, thefsGroupshould be33by default.Possible drawbacks
If you used an alpine image, you will now have to manually set
nextcloud.podSecurityContext.fsGroupto be82in your values.yaml.Applicable issues
/var/www/html/configalways owned by root #335Additional information
Checklist
Chart.yamlaccording to semver.