Conversation
The image still runs as root by default, but it now also runs as the 'firebird' user (UID 84) or as any UID with GID 0, which is how OpenShift's restricted SCC runs containers. - Dockerfile: runtime-writable paths (/opt/firebird itself, firebird.conf, SYSDBA.password, firebird.log, fb_guard, replication.log, security*.fdb, /tmp/firebird and the data directory) are owned by firebird:0 with g=u. Binaries, libraries and plugins stay owned by root. The installer's stale lock files in /tmp/firebird are removed. - entrypoint: every local isql connection names its user explicitly. Local connections otherwise take the OS user name, which is SYSDBA only for root: UID 84 became 'FIREBIRD' and a random UID failed to create FIREBIRD_USER. - entrypoint: warn on startup when a non-root user cannot write to /opt/firebird or the data directory. - tests: test tmpfs mirrors the image's data directory ownership; new tests for file ownership, full initialization as 84:84 and 12345:0, database ownership without FIREBIRD_USER, and the warning. - README: new "Running as a non-root user" section. - DECISIONS.md: D-020.
This was referenced Sep 26, 2026
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #46.
The image still runs as
rootby default, so nothing changes for existing users. It can now also run fully as thefirebirduser (UID 84) or as any UID with GID 0, which is how OpenShift'srestrictedSCC runs containers (random UID, no/etc/passwdentry). This is option B from the discussion in #46. Switching the default toUSER firebirdis left for a major release.I'm not using "Fixes #46", so the issue stays open until the reporter confirms it works on OKD/MicroShift.
Problem
Measured on the current
5.0.4image:--user 84:84starts the server, but the entrypoint fails as soon as it has to write:FIREBIRD_CONF_*/FIREBIRD_USE_LEGACY_AUTH:sed -icannot create its temporary file in theroot:root 0755directory/opt/firebird.FIREBIRD_ROOT_PASSWORD:rmof theroot:root 0400fileSYSDBA.passwordfails.FIREBIRD_DATABASE: writing/opt/firebird/.firebird_envfails.fb_guard,firebird.log,security*.fdb, the data directory and the installer's leftover files in/tmp/firebirdare owned byfirebird:firebird.isqlconnections take the OS user name as the Firebird user.rootmaps to SYSDBA, but UID 84 becomesFIREBIRD, and a random UID has no name at all. As a result:CREATE USERforFIREBIRD_USERfails withno permission for INSERT access to TABLE PLG$SRP_VIEW.FIREBIRD_USER, databases and init-script objects end up owned byFIREBIRDinstead of SYSDBA.Fix
src/Dockerfile.template:firebird:0withg=u:/opt/firebirditself,SYSDBA.password,firebird.conf,firebird.log,fb_guard,replication.log,security*.fdb,/tmp/firebirdand$FIREBIRD_DATA.firebirdkeeps--user firebirdworking, and group 0 covers any UID in the root group.root.$FIREBIRD_DATAis aVOLUME, so its ownership is set in the image layer./tmp/firebird(~6 MB, one of them root-only) are removed. Firebird recreates them at startup.src/entrypoint.sh:isqlconnection names its user explicitly:-user SYSDBAincreate_userandcreate_db.process_sqluses-u SYSDBAwhenFIREBIRD_USERis not set.check_permissions: a non-root user that cannot write to/opt/firebirdor the data directory gets a clear warning that lists the supported users.src/image.tests.ps1:firebird:0,0775). Previously it was root-owned and hid the image's ownership.Runtime_paths_are_owned_by_firebird_and_group_root(binaries stay root-owned).Can_run_as_firebird_user(84:84) andCan_run_as_arbitrary_uid_with_group_root(12345:0). Each runs the whole initialization:FIREBIRD_CONF_*, SYSDBA password change,FIREBIRD_USER,FIREBIRD_DATABASEand an init script. It then checks the server's UID, remote logins, removal ofSYSDBA.password, and object ownership.Without_FIREBIRD_USER_database_is_owned_by_SYSDBA_for_any_user, for0:0,84:84and12345:0.Unsupported_user_shows_permission_warning.README.md/src/README.md.template: new "Running as a non-root user" section. It covers Docker, KubernetessecurityContextand OpenShift, and notes that databases created as root needchown -R 84:0before a non-root container can open them.DECISIONS.md: D-020. This will conflict trivially with Fix SYSDBA.password not working in Firebird 3 images #49's D-019, since both append at the end. Keep both entries.generated/: regenerated withInvoke-Build Prepare.Test plan
5.0.4/trixie:Invoke-Build Build+Invoke-Build Test, 34/34 green. That's the 28 existing tests, which run as root and are unchanged, plus the new ones.0:0,84:84and12345:0, with all variables set. For all three: the server runs as the requested UID,aliceand SYSDBA can log in remotely, the init script ran, andSYSDBA.passwordwas removed.1000:1000shows the warning.workflow_dispatchwithdistro-filter=trixie, all versions: 36271557110 passed.bullseye, whose security packages now return 404 after its end of life. That affectsmasterand every branch and is tracked in Debian bullseye images can no longer be built (bullseye reached end of life); proposal: stop building them #50.