Permission denied writing to a mounted volume inside a Docker container
The process inside the container runs as a user (UID) that doesn’t own the bind-mounted host folder, so reads/writes fail with EACCES.
Seen on:
Docker
Meaning
Files keep numeric UIDs across the mount. If the image runs as node (1000), www-data (33) or postgres (999) but the host folder belongs to UID 501 or root, the container user has no permission. SELinux on Fedora/RHEL adds another layer (fix with :z).
Common causes
- Container user UID differs from the host folder owner
- Folder created by root (Docker auto-creates missing -v paths as root)
- SELinux labels block access
- Read-only mount (:ro)
⚡ Quick fix
- Run as your UID: --user "$(id -u):$(id -g)"
- chown the host folder to the container UID
- On SELinux hosts add :z to the volume
Detailed fix by platform
Docker
- bash
docker run --user "$(id -u):$(id -g)" -v "$(pwd)":/app -w /app node:20 npm ci sudo chown -R 999:999 ./pgdata # postgres image UID
Docker Compose
- bash
volumes: - ./data:/var/lib/data:z # SELinux relabel
How to diagnose
- Owner — ls -ln on the host folder
- User — docker exec c id
- SELinux — getenforce
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Docker
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026