Skip to content

fix(influxdb): only read init secret files before setup - #923

Open
devanbenz wants to merge 1 commit into
masterfrom
db/fix-secret-file-read-errors
Open

devanbenz wants to merge 1 commit into
masterfrom
db/fix-secret-file-read-errors

Conversation

@devanbenz

Copy link
Copy Markdown
Contributor

Closes influxdata/influxdb#26673

The DOCKER_INFLUXDB_INIT_*_FILE secrets were read at the top of entrypoint.sh, which runs twice: once as root, then again after stepping down to influxdb. With root-only secret files (e.g. 0600 Docker secrets), the second pass logged Permission denied plus a misleading file not existing message on every start, even though setup had already used the secrets.

  • Read the secret files only right before setup/upgrade (read_init_secret_files).
  • Log separate warnings for missing vs. unreadable files.
  • Applied to 2.7, 2.8, 2.9 (Debian + Alpine).
  • New e2e case test-auto-setup-secret-files: fails on current images, passes with this change on 2.7/2.8/2.9 (both variants).

The *_FILE secrets were read at the top of the entrypoint, so they were read again after stepping down from root to the influxdb user. Root-only secret files then logged "Permission denied" and a misleading "file not existing" message on every start, even though setup had already used them.

Read them only right before setup/upgrade, and log distinct warnings for missing and unreadable files.
@devanbenz
devanbenz requested review from jdstrand and a balanced review from Copilot September 28, 2026 18:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation consistently resolves the privilege-transition issue and includes targeted regression coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Moves secret-file reads into initialization to avoid permission errors after privilege reduction.

Changes:

  • Adds deferred secret loading with distinct missing/unreadable warnings.
  • Applies behavior consistently across InfluxDB 2.7–2.9 Debian and Alpine images.
  • Adds an end-to-end regression test for root-only secrets.
File Description
influxdb/​2.7/​entrypoint.sh Defers secret reads before initialization.
influxdb/​2.7/​alpine/​entrypoint.sh Applies the Alpine equivalent.
influxdb/​2.8/​entrypoint.sh Defers secret reads before initialization.
influxdb/​2.8/​alpine/​entrypoint.sh Applies the Alpine equivalent.
influxdb/​2.9/​entrypoint.sh Defers secret reads before initialization.
influxdb/​2.9/​alpine/​entrypoint.sh Applies the Alpine equivalent.
influxdb/​test/​cases/​test-auto-setup-secret-files Tests setup and restart with root-only secrets.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[2.x] False errors in docker compose for reading secrets

2 participants