open /data/db.sqlite: permission denied (bind mount on SELinux host)
Fixes 'permission denied' writing to bind-mounted volumes on SELinux systems (RHEL, CentOS, Fedora). Use when the mount works but the container cannot read/write files. Not for missing directories or non-SELinux hosts.
TL;DR: Add the :z (shared) or :Z (private) flag to the bind mount: -v /host/data URIs/data URIsz. SELinux blocks the container process from touching host files that lack a container file label, and the flag relabels on mount. Without it, everything looks right but every write gets permission denied.
The error
open /data/db.sqlite: permission denied(inside the container, when the same operation works on a named volume or with --privileged)
Fix it
- Confirm SELinux is the cause:
ls -Z /host/data shows unconfined_u:object_r:user_home_t:s0 (no container label), and ausearch -m avc -ts recent | grep denied shows denials. Expected: AVC denials for the container process.
- Relabel with the shared flag (multiple containers need it) or private flag (single container):
docker run -v /host/data URIs/data URIsz [image] Expected: reads and writes work.
- For --mount syntax:
--mount type=bind,source=/host/data,target=/data,bind-propagation=rshared does NOT set the label; use the :z short syntax or chcon -Rt container_file_t /host/data on the host.
When this applies
- RHEL/CentOS/Fedora/Rocky hosts with SELinux enforcing
- Bind mounts failing with permission denied while named volumes work
When this does NOT apply
- SELinux disabled or permissive (
getenforcesays so) - UID/GID mismatch permission errors (fix with chown, not labels)
Versions
All Docker versions on SELinux-enforcing distros.
Why it happens
SELinux confines the container process to files labeled container_file_t. Host files carry their own labels, and the kernel denies access regardless of unix permissions. :z tells docker to relabel the content on mount.
Edge cases
:Z(capital) gives a private unshared label; a second container mounting the same path with :Z will break the first. Use:zwhen sharing.- Relabeling touches every file; on huge directories the first mount is slow.
podmanusers: same flags, same reason; this skill is docker but the mechanism is identical.- Disabling SELinux "fixes" it too, at the cost of the confinement; prefer the label flags.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.