docs: add operator remediation for install dirs locked to 0700 by older images
The Dockerfile fix in #93757 only helps newly built images, and an image upgrade (container recreate) resets the permission because /opt/hermes lives in the image layer. The one stranded case is an old image whose container was stopped and restarted after the lockout: it keeps the 0700 install dir and runs code without the guard. Document the one-line in-place recovery (chmod 0755 /opt/hermes as root) in the Docker troubleshooting section. Follow-up to #93757.
This commit is contained in:
@@ -802,6 +802,16 @@ docker run -d \
|
||||
|
||||
`docker exec hermes <cmd>` automatically drops to UID 10000 too — see [`docker exec` automatically drops to the `hermes` user](#docker-exec-automatically-drops-to-the-hermes-user) for details and the per-invocation opt-out.
|
||||
|
||||
### "Permission denied" on every `docker exec` (install dir locked to 0700)
|
||||
|
||||
Images built before late August 2026 had a bug where writing a credential file directly under `/opt/hermes` restricted that directory to `0700`, locking the `hermes` user (UID 10000) out of the install tree. Every new `docker exec` then fails with `Permission denied`.
|
||||
|
||||
Pulling a newer image and recreating the container fixes it permanently (the install dir ships as `0755` and current releases no longer restrict it). If you need to recover a running container in place without recreating it:
|
||||
|
||||
```sh
|
||||
docker exec -u root hermes chmod 0755 /opt/hermes
|
||||
```
|
||||
|
||||
### Browser tools not working
|
||||
|
||||
Playwright needs shared memory. Add `--shm-size=1g` to your Docker run command:
|
||||
|
||||
Reference in New Issue
Block a user