Skip to content

Permission denied errors when a token is requested #124

Description

When requesting a token, the server explodes with the following traceback:

 | 15:03:15 fail: Microsoft.AspNetCore.Server.Kestrel[13] Connection id "0HNOK0DG2MCE7", Request id "0HNOK0DG2MCE7:00000010": An unhandled exception was thrown by the application. Azure.Identity.AuthenticationFailedException: Azure CLI authentication failed due to an unknown error. See the troubleshooting guide for more information. https://aka.ms/azsdk/net/identity/azclicredential/troubleshoot [Errno 13] Permission denied: '/app/.azure/versionCheck.json' Traceback (most recent call last):
File "/usr/lib/python3.12/site-packages/azure/cli/core/cloud.py", line 555, in get_active_cloud_name
  return cli_ctx.config.get('cloud', 'name')
         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/knack/config.py", line 99, in get
  raise last_ex  # pylint:disable=raising-bad-type
  ^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/knack/config.py", line 94, in get
  return config.get(section, option)
         ^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/knack/config.py", line 208, in get
  return self.config_parser.get(section, option)
         ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/configparser.py", line 759, in get
  d = self._unify_values(section, vars)
      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/configparser.py", line 1132, in _unify_values
  raise NoSectionError(section) from None configparser.NoSectionError: No section: 'cloud'  During handling of the above exception, another exception occurred:  Traceback (most recent call last):
File "<frozen runpy>", line 198, in _run_module_as_main
File "<frozen runpy>", line 88, in _run_code
File "/usr/lib/python3.12/site-packages/azure/cli/__main__.py", line 30, in <module>
  az_cli = get_default_cli()
           ^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/azure/cli/core/__init__.py", line 956, in get_default_cli
  return AzCli(cli_name='az',
         ^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/azure/cli/core/__init__.py", line 87, in __init__
  self.cloud = get_active_cloud(self)
               ^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/azure/cli/core/cloud.py", line 650, in get_active_cloud
  cloud = get_cloud(cli_ctx, get_active_cloud_name(cli_ctx))
                             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
File "/usr/lib/python3.12/site-packages/azure/cli/core/cloud.py", line 558, in get_active_cloud_name
  _set_active_cloud(cli_ctx, default_cloud_name)
File "/usr/lib/python3.12/site-packages/azure/cli/core/cloud.py", line 549, in _set_active_cloud
  cli_ctx.config.set_value('cloud', 'name', cloud_name)
File "/usr/lib/python3.12/site-packages/knack/config.py", line 161, in set_value
  self._config_file_chain[-1].set_value(section, option, value)
File "/usr/lib/python3.12/site-packages/knack/config.py", line 240, in set_value
  self.set(config)
File "/usr/lib/python3.12/site-packages/knack/config.py", line 225, in set
  with open(self.config_path, 'w', encoding=CONFIG_FILE_ENCODING) as configfile:
  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ PermissionError: [Errno 13] Permission denied: '/app/.azure/config'
 at Azure.Identity.AzureCliCredential.RequestCliAccessTokenAsync(Boolean async, TokenRequestContext context, CancellationToken cancellationToken)
 at Azure.Identity.AzureCliCredential.GetTokenImplAsync(Boolean async, TokenRequestContext requestContext, CancellationToken cancellationToken)
 at Azure.Identity.CredentialDiagnosticScope.FailWrapAndThrow(Exception ex, String additionalMessage, Boolean isCredentialUnavailable)
 at Azure.Identity.AzureCliCredential.GetTokenImplAsync(Boolean async, TokenRequestContext requestContext, CancellationToken cancellationToken)
 at Azure.Identity.AzureCliCredential.GetTokenAsync(TokenRequestContext requestContext, CancellationToken cancellationToken)
 at Program.<>c__DisplayClass0_0.<<<Main>$>b__2>d.MoveNext() --- End of stack trace from previous location ---
 at Microsoft.AspNetCore.Http.Generated.<GeneratedRouteBuilderExtensions_g>F545A1E1C15B5951FF8057E2F7C4B68043BDCF8DC765F2F91DCB6DBC28B5CF4D6__GeneratedRouteBuilderExtensionsCore.<>c__DisplayClass4_0.<<MapPost1>g__RequestHandler|5>d.MoveNext() --- End of stack trace from previous location ---
 at Microsoft.AspNetCore.Routing.EndpointMiddleware.<Invoke>g__AwaitRequestTask|7_0(Endpoint endpoint, Task requestTask, ILogger logger)
 at Microsoft.AspNetCore.Server.Kestrel.Core.Internal.Http.HttpProtocol.ProcessRequests[TContext](IHttpApplication`1 application)

After some digging, I realised that this is because the app user running the application is created by the base container which is hard-coded to have a UID of 1654. As the typical UID for most Linux systems these days is 1000 for the first user, this means that if you're working natively in Linux and follow the instructions provided, the proxy server can't operate on your ${HOME}/.azure folder.

To Reproduce

  1. Have a Linux system running a user with a UID other than 1654
  2. Follow the instructions as provided
  3. Boom ;-)

Expected behavior

The token should be issued.

Suggested workaround

I've found that if I modify my compose file to include a user: line, the problem is avoided:

  azure-proxy:
    image: workleap/azure-cli-credentials-proxy:latest
    user: 1000:1000
    volumes:
      - "${HOME}/.azure:/app/.azure/"

...though it should be pointed out that this means that the application runs as the 1000 user, rather than as the app user. This hasn't had any negative effects for me (yet?) though.

A better solution would be for either:

  1. The server could be modified (maybe?) to not need the rights to write to the files in ${HOME}/.azure.
  2. The Docker image could be modified to start the given service with a given UID provided by an environment variable.

Environment

  • OS: Arch Linux
  • Version: n/a (Arch is a rolling distro)
  • IDE: PyCharm

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions