Skip to content

Commit f2006ad

Browse files
onekiloparsecclaude
andcommitted
Local docs: the Linux docker group, and the "variable is not set" warnings
Two things a fresh Linux install runs into. Docker Engine only answers members of the docker group, which the "no admin account needed" tip glossed over since it was written for Docker Desktop. And CLI versions up to 3.17.1 could write a '$' into the signing keys in .env, which Compose interpolates away with one warning per key. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
1 parent e41aedf commit f2006ad

2 files changed

Lines changed: 38 additions & 1 deletion

File tree

‎docs/local/installation.md‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,15 @@ Two frequent worries, both unfounded:
4949
- **You do not need a Docker account** to run Arcsecond.local. Docker Desktop shows a sign-in screen on first
5050
launch — you can simply skip it. The only login involved is the one to the *Arcsecond* registry with your PAT,
5151
described below, which is unrelated to Docker Hub.
52+
53+
One exception, on **Linux with Docker Engine** (no Docker Desktop): the daemon only answers root and members of the
54+
`docker` group. If `docker compose up -d` ends with `permission denied while trying to connect to the docker API at
55+
unix:///var/run/docker.sock`, add your user to that group once, then log out and back in (or open a new shell with
56+
`newgrp docker`):
57+
58+
```bash
59+
sudo usermod -aG docker $USER
60+
```
5261
:::
5362

5463
## Installation

‎docs/local/troubleshooting.md‎

Lines changed: 29 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,4 +13,32 @@
1313
- Confirm the mount from inside a container (quick sanity check): Run a one-off container that writes a test file to
1414
/data and confirm the file appears on the host. If it can’t write, it’s almost always a sharing/permissions/path
1515
issue.
16-
16+
17+
18+
## Linux: "permission denied while trying to connect to the docker API"
19+
20+
The full line is `permission denied while trying to connect to the docker API at unix:///var/run/docker.sock`, and it
21+
shows up right after `docker compose up -d` on a Linux host running Docker Engine (not Docker Desktop). The daemon only
22+
answers root and members of the `docker` group, and a fresh install does not put your user there. `docker login`
23+
succeeds regardless, because it only writes a config file, which is why the failure looks sudden.
24+
25+
Add your user to the group once, then log out and back in (or `newgrp docker` in the current shell), and check with
26+
`docker ps` before running `docker compose up -d` again:
27+
28+
```bash
29+
sudo usermod -aG docker $USER
30+
```
31+
32+
## "The 'xyz' variable is not set. Defaulting to a blank string."
33+
34+
Repeated `WARN[0000] The "..." variable is not set` lines on `docker compose up`, with names that look like random
35+
fragments, come from a `$` inside one of the secret keys that `arcsecond setup` wrote to `.env`. Compose interpolates
36+
`$name` in that file, so the `$` and the characters after it are dropped. Versions of the CLI up to 3.17.1 could
37+
generate such keys; later versions do not.
38+
39+
The containers all see the same shortened value, so an installation that runs with these warnings is fine as it is.
40+
On a **brand new** installation that has not started yet, the cleaner move is to open `.env` and remove every `$` from
41+
`SECRET_KEY`, `AUTH_JWT_SIGNING_KEY` and `AGENT_JWT_SIGNING_KEY` (or delete `.env` and rerun `arcsecond setup` with an
42+
up-to-date CLI). Do not touch these three keys on an installation that already has users: they sign every session
43+
token, and changing them logs everyone out.
44+

0 commit comments

Comments
 (0)