-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AccessDeniedException error with build using native image on linux with Docker Desktop #37193
Comments
Maybe you can run maven with |
Treat Docker Desktop as "rootless" since the way it binds mounts does not transparently map the host user ID and GID see https://docs.docker.com/desktop/faqs/linuxfaqs/#how-do-i-enable-file-sharing Closes quarkusio#37193
I was able to reproduce the issue on Fedora linux and prepared a fix in #37242 Thanks for the issue report @johnmanko |
@zakkak wow, amazing turnaround on putting together a fix. Thanks! |
Treat Docker Desktop as "rootless" since the way it binds mounts does not transparently map the host user ID and GID see https://docs.docker.com/desktop/faqs/linuxfaqs/#how-do-i-enable-file-sharing Closes quarkusio#37193 (cherry picked from commit 81818c7)
Treat Docker Desktop as "rootless" since the way it binds mounts does not transparently map the host user ID and GID see https://docs.docker.com/desktop/faqs/linuxfaqs/#how-do-i-enable-file-sharing Closes quarkusio#37193
Treat Docker Desktop as "rootless" since the way it binds mounts does not transparently map the host user ID and GID see https://docs.docker.com/desktop/faqs/linuxfaqs/#how-do-i-enable-file-sharing Closes quarkusio#37193
This MR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [flow-bin](https://github.com/flowtype/flow-bin) ([changelog](https://github.com/facebook/flow/blob/master/Changelog.md)) | devDependencies | minor | [`^0.222.0` -> `^0.223.0`](https://renovatebot.com/diffs/npm/flow-bin/0.222.0/0.223.2) | | [io.quarkus:quarkus-maven-plugin](https://github.com/quarkusio/quarkus) | build | minor | `3.5.3` -> `3.6.0` | | [io.quarkus:quarkus-universe-bom](https://github.com/quarkusio/quarkus-platform) | import | minor | `3.5.3` -> `3.6.0` | --- ### Release Notes <details> <summary>flowtype/flow-bin</summary> ### [`v0.223.2`](flow/flow-bin@5bb7bcf...6e1e3f7) [Compare Source](flow/flow-bin@5bb7bcf...6e1e3f7) ### [`v0.223.0`](flow/flow-bin@84a68f1...5bb7bcf) [Compare Source](flow/flow-bin@84a68f1...5bb7bcf) </details> <details> <summary>quarkusio/quarkus</summary> ### [`v3.6.0`](https://github.com/quarkusio/quarkus/releases/tag/3.6.0) [Compare Source](quarkusio/quarkus@3.5.3...3.6.0) ##### Major changes - [#​37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling ##### Complete changelog - [#​37242](quarkusio/quarkus#37242) - Support Docker Desktop for building native executables - [#​37241](quarkusio/quarkus#37241) - Make improvements to REST Client SSE handling - [#​37240](quarkusio/quarkus#37240) - Updates Infinispan to 14.0.21.Final - [#​37238](quarkusio/quarkus#37238) - Build cache - Only store if the access key is around - [#​37236](quarkusio/quarkus#37236) - Api to read minimum and recommended Java versions from catalog metadata - [#​37221](quarkusio/quarkus#37221) - Image updates (including Java 21 base image) - [#​37218](quarkusio/quarkus#37218) - Fix OpenTelemetry trace exclusion of endpoints served from the management interface - [#​37213](quarkusio/quarkus#37213) - Add basic Range header support - [#​37205](quarkusio/quarkus#37205) - Resteasy-reactive Partial Content support (Range: bytes http header) - [#​37204](quarkusio/quarkus#37204) - Allow to define allowed roles as configuration expressions inside `@SecureField` annotation - [#​37201](quarkusio/quarkus#37201) - Fixed sample code for KotlinModule initialization - [#​37198](quarkusio/quarkus#37198) - Some minor refinements for build scans - [#​37193](quarkusio/quarkus#37193) - AccessDeniedException error with build using native image on linux with Docker Desktop - [#​37185](quarkusio/quarkus#37185) - Removed DependencyFlags.REMOVED - [#​37170](quarkusio/quarkus#37170) - Fix snapshots following a collision of pull requests - [#​37166](quarkusio/quarkus#37166) - Support custom Authorization schemes for OIDC bearer tokens - [#​37162](quarkusio/quarkus#37162) - Bump org.apache.commons:commons-text from 1.10.0 to 1.11.0 - [#​37161](quarkusio/quarkus#37161) - Bump io.quarkus:quarkus-platform-bom-maven-plugin from 0.0.97 to 0.0.99 - [#​37158](quarkusio/quarkus#37158) - Bump com.unboundid:unboundid-ldapsdk from 6.0.9 to 6.0.10 - [#​37153](quarkusio/quarkus#37153) - Bump smallrye-jwt version to 4.4.0 - [#​37149](quarkusio/quarkus#37149) - Bump com.squareup.okio:okio from 1.17.2 to 1.17.6 in /bom/application - [#​37107](quarkusio/quarkus#37107) - Rest client able to get full SSE event - [#​37101](quarkusio/quarkus#37101) - Remove `smallrye-opentracing` from native tests modules in CI - [#​37094](quarkusio/quarkus#37094) - Bump jakarta.json:jakarta.json-api from 2.1.2 to 2.1.3 - [#​37092](quarkusio/quarkus#37092) - Bump mongo-client.version from 4.11.0 to 4.11.1 - [#​37067](quarkusio/quarkus#37067) - SmallRye GraphQL 2.6 + custom scalar registration - [#​37053](quarkusio/quarkus#37053) - Clarify dynamic Environment Variables name conversion - [#​37004](quarkusio/quarkus#37004) - Move failsafe config to the root instead of in an execution - [#​36976](quarkusio/quarkus#36976) - Error in JBossLoggerFinder during integration test - [#​36804](quarkusio/quarkus#36804) - `@SecureField` add expression support - [#​36801](quarkusio/quarkus#36801) - Add note that endpointdisabled does not work native - [#​36746](quarkusio/quarkus#36746) - Allow using a random test port within Google Cloud Function tests - [#​35476](quarkusio/quarkus#35476) - Random test port does not work together with google-cloud-functions extensions </details> <details> <summary>quarkusio/quarkus-platform</summary> ### [`v3.6.0`](quarkusio/quarkus-platform@3.5.3...3.6.0) [Compare Source](quarkusio/quarkus-platform@3.5.3...3.6.0) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever MR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This MR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4yNC4wIiwidXBkYXRlZEluVmVyIjoiMzQuMjQuMCJ9-->
Hey @zakkak , are you sure this error was specific to docker desktop? I'm getting a very similar error using a build of Quarkus from the Reproducer: not sure this will help, but here you go: https://github.com/yrodiere/quarkus-playground/tree/i37193 Podman version:
Mandrel builder image:
Logs:
|
Hi @yrodiere. I can't reproduce this on Fedora 39 using podman 4.8.0 in rootless mode
What I tried:
Could you please share the part of the logs showing how podman was invoked? It should look like this:
|
Update: I can reproduce with Quarkus 58834c2, apparently I tested with a different version. |
Great, thanks for having a look @zakkak!
FWIW it was already included in my message:
|
Treat Docker Desktop as "rootless" since the way it binds mounts does not transparently map the host user ID and GID see https://docs.docker.com/desktop/faqs/linuxfaqs/#how-do-i-enable-file-sharing Closes quarkusio#37193
Describe the bug
I'm new to Quarkus, and just checkout the sample application. That works fine, so I now want to try a native build using the provided containers.
I'm running Docker Desktop 4.23.0 on Ubuntu 23.10, and I verified my home directory is share with DD:
When attempting
./mvnw install -Dnative -Dquarkus.native.container-build=true -Dquarkus.native.container-runtime=docker
:Considering I'm just following the tutorials, this is either a bug or I'm missing something obvious. Help is appreciated.
Expected behavior
Build completes successfully.
Actual behavior
Fails to build.
How to Reproduce?
No response
Output of
uname -a
orver
❯ uname -a Linux jm 6.5.0-10-generic #10-Ubuntu SMP PREEMPT_DYNAMIC Fri Oct 13 13:49:38 UTC 2023 x86_64 x86_64 x86_64 GNU/Linux
Output of
java -version
Java HotSpot(TM) 64-Bit Server VM Oracle GraalVM 21.0.1+12.1 (build 21.0.1+12-jvmci-23.1-b19, mixed mode, sharing)
Mandrel or GraalVM version (if different from Java)
No response
Quarkus version or git rev
3.5.2
Build tool (ie. output of
mvnw --version
orgradlew --version
)Apache Maven 3.9.5 (57804ffe001d7215b5e7bcb531cf83df38f93546)
Additional information
No response
The text was updated successfully, but these errors were encountered: