Repository navigation
Make the DuckDB warehouse writable by the Superset container - #5
Merged
Merged
Conversation
Superset runs as uid 1000 and opens the DuckDB file read-write. The
bind-mounted shared/db/datamart.duckdb belongs to whoever created it on
the host, so on a host whose uid is not 1000 Superset cannot open the
warehouse at all:
IO Error: Cannot open file
"/app/superset_home/db/datamart.duckdb": Permission denied
This surfaced as `superset hook exited with status 1` during the
post_start dashboard import, but it affects rendering dashboards too, not
just the import. It goes unnoticed on macOS, where Docker Desktop
virtualizes bind-mount ownership, and on Linux hosts that happen to run as
uid 1000.
A new init-db-permissions service relaxes the mode as root before Superset
starts. Two alternatives were ruled out first: running Superset as the
host uid breaks its own metadata database, which is owned by uid 1000 in
the image; and access_mode=read_only does not reach DuckDB, because
`superset import-dashboards` defines the connection from the URI embedded
in dashboard.zip and connects read-write regardless.
The CI chmod that worked around this is removed, so CI now exercises the
real fix.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the Superset / DuckDB permission bug that the new CI surfaced on its first run.
The bug
Superset runs as uid 1000 and opens the DuckDB warehouse read-write. The bind-mounted
shared/db/datamart.duckdbbelongs to whoever created it on the host, so on any host whose uid isn't 1000, Superset can't open it:It shows up as
superset hook exited with status 1during thepost_startdashboard import, but it isn't limited to the import — Superset needs that file to render anything.It goes unnoticed on macOS, where Docker Desktop virtualizes bind-mount ownership, and on Linux hosts that happen to run as uid 1000 — which is the common desktop default. Anywhere else the stack comes up looking healthy with a Superset that can't read the warehouse.
The fix
A small
init-db-permissionsservice relaxes the mode as root before Superset starts:Superset gains a
service_completed_successfullydependency on it, so the chmod is guaranteed to finish first. That required converting Superset'sdepends_onfrom the list form to the map form; the existing dependency is preserved ascondition: service_started, which is what the list form already meant.Two alternatives ruled out first
Run Superset as the host uid. Breaks Superset itself — its metadata SQLite database under
/app/superset_homeis created at build time owned by uid 1000, and Superset must write it.access_mode=read_onlyon the connection. Semantically the right thing for a BI tool, and a directduckdb.connect(..., read_only=True)inside the container does open the file fine at mode 644 owned by another uid. But it never takes effect:superset import-dashboardsdefines the database connection from the URI embedded indashboard.zip, overriding whatset_database_uristored, and connects read-write anyway. Tested and closed in #4.Verification
The
chmodworkaround previously added to the CI prep step is removed in this PR, so the pipeline now exercises the real fix rather than masking it.🤖 Generated with Claude Code