1.1 KiB
V4.2.5 – Worker identity volume permission fix
Managed workers persist /identity/identity.json in a Docker named volume. A
new named volume is normally root-owned, while identities from older releases
may already be mode 0600 and owned by a different UID. With the hardened
worker capability set this could make the client fail immediately with:
open /identity/identity.json: permission denied
V4.2.5 makes the worker image normalize only /identity and the fixed
/identity/identity.json path before startup. The entrypoint starts as root,
fixes ownership, and immediately executes /app/neuralhunt-client as the
unprivileged app user via su-exec.
Customer Service still drops all Linux capabilities and adds back only the four
bootstrap capabilities needed by that entrypoint: CHOWN, DAC_OVERRIDE,
SETUID, and SETGID. Workers still receive no Docker socket and retain a
read-only root filesystem.
Existing worker identity volumes are intentionally kept. Rebuilding/pulling the worker image and restarting an affected worker is sufficient; deleting the worker/volume would destroy its identity and is not required.