Fix shared upload permissions for capability-restricted LTX backend

This commit is contained in:
Mikei386 committed 2026-09-29 19:45:38 +02:00
1 parent 64573e01a3
commit 5b887dfb42
7 files changed
+41 -7

No files matched your search

+5 -2
View File
@@ -7,7 +7,8 @@ The additional `deploy/compose.athena.yaml` uses host networking **only for this
frontend**, binds its web server to `127.0.0.1:8118`, and connects to Deck at
`http://127.0.0.1:8120`. This avoids changing Deck's existing network or relying on
its current Docker IP. No Docker socket, GPU devices or inference packages are
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB.
mounted into the GUI. CPU and RAM limits: 2 CPUs / 1 GiB. GUI identity: UID 1000 / GID 0;
this supplies shared-file read access, not root UID or Linux capabilities.
Filtered Deck inventory labels:
@@ -17,7 +18,9 @@ Filtered Deck inventory labels:
Media mounts:
- `/data/video/ltx-desktop/LTXDesktop/remote-inputs/deskweb` → writable inputs.
A new isolated directory owned by UID/GID 1000; no recursive permission changes.
A new isolated directory owned by UID 1000 / GID 0, mode 2750; no changes to other LTX directories.
Files use mode 0640. The existing LTX backend runs with GID 0 and dropped
capabilities, so group-read/traverse permission is required even for its root UID.
- `/data/video/ltx-desktop/LTXDesktop/outputs` → read-only outputs.
Backend-visible input path: `/data/LTXDesktop/remote-inputs/deskweb`.