# Running Logstash in a Docker container: data directory permissions

**URL:** <https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028>\
**Category:** Logstash\
**Created:** [June 7, 2018, 4:02pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028 "2018-06-07T16:02:13Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 7, 2018, 4:02pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/1 "2018-06-07T16:02:13Z")

</div>

Hello, I'm trying to run a Docker container with this setup:

```
docker run --name logstash6 -d -v /srv/logstash6/pipeline/:/usr/share/logstash/pipeline/ -v /srv/logstash6/data/:/usr/share/logstash/data/ docker.elastic.co/logstash/logstash-oss:6.2.4

```

My problem is that Logstash is exiting with the following error:

```
[FATAL][logstash.runner] An unexpected error occurred! {:error=>#<ArgumentError: Path "/usr/share/logstash/data" must be a writable directory. It is not writable.>

```

I have already set 644/755 permissions on /srv/logstash6/data directory

What am I doing wrong?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 10, 2018, 8:21pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/2 "2018-06-10T20:21:38Z")

</div>

Who's the owner of /srv/logstash6/data? What user is Logstash running as inside the container?

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 11, 2018, 5:29am UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/3 "2018-06-11T05:29:34Z")

</div>

Hi @magnusbaeck,

usually for Elasticsearch Docker container, i set a data directory to achieve persistency and the owner is root with file/folder permissions set to 755/644, and the thing works. Somehow Docker manages to automatically change the ownership of the folder.  
For Logstash, I set 755/644 as well, but the container seems to be unable to write in the folder. The ownership remains for root.

I managed to make the whole thing work using a folder inside the home of the user who launches the docker run command (e.g. `~/logstash/data/`), but I'm still confused how the whole thing works.

For the moment, _my_ best practice seems to be to put all ELK containers folders inside ~/  
But I would like to understand how you need to set file/folder ownership and permissions for another system folder, like /srv/\* in order to make the think working _always_

Thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2018, 5:53am UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/4 "2018-06-11T05:53:13Z")

</div>

I repeat: What user is Logstash running as inside the container?

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 11, 2018, 6:27am UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/5 "2018-06-11T06:27:42Z")

</div>

The user Logstash is running inside the container is `logstash`  
Currently, the container is able to write files to the host folder `/home/user/logstash/data/` which has the following permissions:

```
drwxr-xr-x 5 user user 4096 Jun 8 11:34 data/

```

But the container would not work with a host folder owned by `root`, e.g. `/srv/logstash/data/`

```
drwxr-xr-x 2 root root 4096 Jun 7 14:01 data/

```

Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 11, 2018, 7:01am UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/6 "2018-06-11T07:01:39Z")

</div>

What's the uid of "user"? What's the uid of "logstash" in the Logstash container?

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 11, 2018, 8:05pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/7 "2018-06-11T20:05:21Z")

</div>

Both logstash and user have the same uid, 1000.  
I would like to understand how to set file and folder permissions when user has a uid different than logstash.  
Thank you 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2018, 6:04am UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/8 "2018-06-12T06:04:52Z")

</div>

> Both logstash and user have the same uid, 1000.

As I suspected. That's why it happens to work when you mount directories from your home directory.

> I would like to understand how to set file and folder permissions when user has a uid different than logstash.

The directory you mount needs to be writable to the logstash user with uid 1000. So, a chown operation on /srv/logstash/data/ or whatever directory you want to use should solve the problem.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 12, 2018, 12:25pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/9 "2018-06-12T12:25:00Z")

</div>

Do you think another option would be changing uid of the logstash user inside the container with the `docker run --user 1001` option?

Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 12, 2018, 12:58pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/10 "2018-06-12T12:58:37Z")

</div>

Yeah, that probably works.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 12, 2018, 1:56pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/11 "2018-06-12T13:56:18Z")

</div>

Thank you for your time, this discussion has been really helpful to me (and I hope for others as well).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2018, 1:56pm UTC](https://discuss.elastic.co/t/running-logstash-in-a-docker-container-data-directory-permissions/135028/12 "2018-07-10T13:56:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
