[{"data":1,"prerenderedAt":191},["ShallowReactive",2],{"$f36s2i3m4a60zc":3},{"title":4,"date":5,"tags":6,"categories":9,"draft":11,"_id":12,"slug":13,"path":14,"document":15,"excerpt":189,"readingTimeMinutes":190},"Docker Volume Permissions with SELinux","2019-12-26T00:00:00.000Z",[7,8],"docker","selinux",[10],"linux",false,"content:blog:docker-selinux-volumes","docker-selinux-volumes","\u002Fblog\u002Fdocker-selinux-volumes",{"frontmatter":16,"meta":17,"nodes":18},{},{},[19,23,27,44,47,115,126,150,153,161,167,184,187],[20,21,22],"p",{},"Unfamiliar with running Docker on a SELinux enabled system, I found myself\nrunning into a bunch of file permission errors while creating volumes.",[24,25,26],null,{},"more",[28,29,32],"pre",{"language":30,"class":31},"txt","shiki shiki-themes tokyo-night dark:tokyo-night",[33,34,36],"code",{"class":35},"language-txt",[37,38,41],"span",{"class":39,"style":40},"line","display: inline",[37,42,43],{},"mkdir: can't create directory '\u002Fdata': Permission denied",[45,46],"hr",{},[28,48,50],{"language":49,"class":31},"bash",[33,51,53,80,81,80,86,80,101,80,110],{"class":52},"language-bash",[37,54,55,59,63,66,70,74,77],{"class":39,"style":40},[37,56,58],{"style":57},"color:#C0CAF5","$",[37,60,62],{"style":61},"color:#9ECE6A"," docker",[37,64,65],{"style":61}," info",[37,67,69],{"style":68},"color:#E0AF68"," --format",[37,71,73],{"style":72},"color:#89DDFF"," '",[37,75,76],{"style":61},"{{json .SecurityOptions}}",[37,78,79],{"style":72},"'","\n",[37,82,83],{"class":39,"style":40},[37,84,85],{"style":72},"[",[37,87,88,91,94,97],{"class":39,"style":40},[37,89,90],{"style":72},"  \"",[37,92,93],{"style":61},"name=seccomp,profile=\u002Fetc\u002Fdocker\u002Fseccomp.json",[37,95,96],{"style":72},"\"",[37,98,100],{"style":99},"color:#A9B1D6",",",[37,102,103,105,108],{"class":39,"style":40},[37,104,90],{"style":72},[37,106,107],{"style":61},"name=selinux",[37,109,96],{"style":72},[37,111,112],{"class":39,"style":40},[37,113,114],{"style":72},"]",[20,116,117,118,121,122,125],{},"It turns out that this can be resolved by appending the ",[33,119,120],{},":z"," flag to the volume\nmappings in the ",[33,123,124],{},"docker-compose.yml"," file, indicating that the volume content\nis shared.",[28,127,128],{"class":31},[33,129,130,80,135,80,140,80,145],{},[37,131,132],{"class":39,"style":40},[37,133,134],{},"services:",[37,136,137],{"class":39,"style":40},[37,138,139],{},"  server:",[37,141,142],{"class":39,"style":40},[37,143,144],{},"    volumes:",[37,146,147],{"class":39,"style":40},[37,148,149],{},"      - .\u002Fdata:\u002Fdata:z",[20,151,152],{},"From the Docker documentation:",[154,155,156,157,160],"blockquote",{},"The ",[33,158,159],{},"z"," option tells Docker that two containers share the volume content. As\na result, Docker labels the content with a shared content label. Shared\nvolume labels allow all containers to read\u002Fwrite content.",[20,162,163],{},[164,165,166],"strong",{},"References",[168,169,170,178],"ul",{},[171,172,173],"li",{},[174,175,177],"a",{"href":176},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Freference\u002Fcommandline\u002Finfo\u002F","Docker Docs: Docker Info",[171,179,180],{},[174,181,183],{"href":182},"https:\u002F\u002Fdocs.docker.com\u002Fengine\u002Freference\u002Fcommandline\u002Frun\u002F#mount-volumes-from-container---volumes-from","Docker Docs: Mounting Volumes",[185,186],"component",{},[185,188],{},"Unfamiliar with running Docker on a SELinux enabled system, I found myself running into a bunch of file permission errors while creating volumes.",1,1790648870266]