komga + audiobookshelf: revert to root (user:1000 fallback)

Live try-then-fallback: pinning user 1000:1000 crash-loops both — their named
config/metadata volumes are Docker-created root-owned and the pinned process can't
write them (komga: SQLite /config open fails; audiobookshelf: EACCES mkdir
/metadata/logs; neither has a PUID-style root-init chown). Reverted to root; they
rely on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser browses/reads).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-06-14 22:13:29 +02:00
parent 69611cec18
commit 0d60a5cb2e
2 changed files with 8 additions and 7 deletions
+4 -4
View File
@@ -10,16 +10,16 @@
# Storage layout (felhom userdata convention):
# Hangoskönyvek → ${USERDATA_PATH}/media/audiobooks (írható)
# Podcastok → ${USERDATA_PATH}/media/podcasts (írható)
# Run-identity: user 1000:1000 so files land group-writable for the shared content group
# (GID 1000); the userdata dirs are setgid 2775. If the image fails to start healthy as
# 1000, the controller/operator reverts to root and relies on setgid (see REPORT).
# Run-identity: ROOT (fallback). user "1000:1000" was tried but the image creates its /metadata named
# volume as root at init and fails (`EACCES mkdir /metadata/logs`) when pinned to 1000. So it runs as
# root and relies on the setgid 2775 userdata dirs (files land group 1000 → FileBrowser can browse/read).
# (Verified live; see REPORT.)
services:
audiobookshelf:
image: ghcr.io/advplyr/audiobookshelf:2.19.5
container_name: audiobookshelf
restart: unless-stopped
user: "1000:1000"
environment:
- TZ=Europe/Budapest
volumes: