Files
neural-hunt/V4.2.5_WORKER_IDENTITY_PERMISSION_FIX.md
jbergner eefe6dd415
release-tag / release-image (push) Successful in 4m41s
RC-9-A: Bugfix
2026-08-11 20:33:43 +02:00

1.1 KiB
Raw Permalink Blame History

V4.2.5 – Worker identity volume permission fix

Managed workers persist /identity/identity.json in a Docker named volume. A new named volume is normally root-owned, while identities from older releases may already be mode 0600 and owned by a different UID. With the hardened worker capability set this could make the client fail immediately with:

open /identity/identity.json: permission denied

V4.2.5 makes the worker image normalize only /identity and the fixed /identity/identity.json path before startup. The entrypoint starts as root, fixes ownership, and immediately executes /app/neuralhunt-client as the unprivileged app user via su-exec.

Customer Service still drops all Linux capabilities and adds back only the four bootstrap capabilities needed by that entrypoint: CHOWN, DAC_OVERRIDE, SETUID, and SETGID. Workers still receive no Docker socket and retain a read-only root filesystem.

Existing worker identity volumes are intentionally kept. Rebuilding/pulling the worker image and restarting an affected worker is sufficient; deleting the worker/volume would destroy its identity and is not required.