permission denied (volume) 🐳 Docker

Permission denied writing to a mounted volume inside a Docker container

The process inside the container runs as a user (UID) that doesn’t own the bind-mounted host folder, so reads/writes fail with EACCES.

Seen on: Docker

Meaning

Files keep numeric UIDs across the mount. If the image runs as node (1000), www-data (33) or postgres (999) but the host folder belongs to UID 501 or root, the container user has no permission. SELinux on Fedora/RHEL adds another layer (fix with :z).

Common causes

  • Container user UID differs from the host folder owner
  • Folder created by root (Docker auto-creates missing -v paths as root)
  • SELinux labels block access
  • Read-only mount (:ro)

⚡ Quick fix

  1. Run as your UID: --user "$(id -u):$(id -g)"
  2. chown the host folder to the container UID
  3. On SELinux hosts add :z to the volume

Detailed fix by platform

Docker

  1. bash
    docker run --user "$(id -u):$(id -g)" -v "$(pwd)":/app -w /app node:20 npm ci
    sudo chown -R 999:999 ./pgdata   # postgres image UID

Docker Compose

  1. bash
    volumes:
      - ./data:/var/lib/data:z   # SELinux relabel

How to diagnose

  1. Owner — ls -ln on the host folder
  2. User — docker exec c id
  3. SELinux — getenforce

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.