docs: add operator remediation for install dirs locked to 0700 by older images

The Dockerfile fix in #93757 only helps newly built images, and an
image upgrade (container recreate) resets the permission because
/opt/hermes lives in the image layer. The one stranded case is an old
image whose container was stopped and restarted after the lockout: it
keeps the 0700 install dir and runs code without the guard.

Document the one-line in-place recovery (chmod 0755 /opt/hermes as
root) in the Docker troubleshooting section.

Follow-up to #93757.
This commit is contained in:
Ben Barclay
2026-08-25 10:56:24 +10:00
parent 98f0e0df07
commit e26e25d618
+10
View File
@@ -802,6 +802,16 @@ docker run -d \
`docker exec hermes <cmd>` automatically drops to UID 10000 too — see [`docker exec` automatically drops to the `hermes` user](#docker-exec-automatically-drops-to-the-hermes-user) for details and the per-invocation opt-out.
### "Permission denied" on every `docker exec` (install dir locked to 0700)
Images built before late August 2026 had a bug where writing a credential file directly under `/opt/hermes` restricted that directory to `0700`, locking the `hermes` user (UID 10000) out of the install tree. Every new `docker exec` then fails with `Permission denied`.
Pulling a newer image and recreating the container fixes it permanently (the install dir ships as `0755` and current releases no longer restrict it). If you need to recover a running container in place without recreating it:
```sh
docker exec -u root hermes chmod 0755 /opt/hermes
```
### Browser tools not working
Playwright needs shared memory. Add `--shm-size=1g` to your Docker run command: