Support readonly filesystem without errors
It is a best practice to run kubernetes workloads as readOnlyRootFilesystem. See https://kubernetes.io/docs/tasks/configure-pod-container/security-context/.
When running with such a security context, Mattermost will throw an error : Failed to update assets subpath from config.
This is the case even if the deployment is not served as a subpath.
My proposal is to add support for a readonly filesystem, by either :
- Detecting when the SITE_URL is not affecting the subpath, thereby not raising an error and not trying to update the subpath
OR
- Writing the updated files to a different directory that can be mounted as a read-writable volume instead of trying to updated assets in the root filesystem.
Code location https://github.com/mattermost/mattermost-server/blob/c4b4e1bc38eb7ff9fcc77af93873c1386392089e/utils/subpath.go#L149
![](https://secure.gravatar.com/avatar/a93a42a8c05e0d610c3fb6725156d2d0?size=40&default=https%3A%2F%2Fassets.uvcdn.com%2Fpkg%2Fadmin%2Ficons%2Fuser_70-6bcf9e08938533adb9bac95c3e487cb2a6d4a32f890ca6fdc82e3072e0ea0368.png)