# Keycloak 17 on container fails to extract theme from jar

**URL:** <https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425>\
**Category:** Extending the server\
**Created:** [March 18, 2022, 6:09pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425 "2022-03-18T18:09:13Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 18, 2022, 6:09pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/1 "2022-03-18T18:09:13Z")

</div>

Hi,

I’m using Keycloak 17 in a podman rootless container where I add my jar file with our theme. Sometimes it works, but after a while it starts failing with the error:

2022-03-18 18:59:37,260 WARN [org.keycloak.services] (executor-thread-1) KC-SERVICES0075: Failed to get theme request: java.lang.RuntimeException: Temporary directory /opt/keycloak/bin/…/data/tmp does not exist and it was not possible to create it.  
at org.keycloak.quarkus.runtime.integration.QuarkusPlatform.getTmpDirectory(QuarkusPlatform.java:153)  
at org.keycloak.encoding.GzipResourceEncodingProviderFactory.initCacheDir(GzipResourceEncodingProviderFactory.java:55)  
at org.keycloak.encoding.GzipResourceEncodingProviderFactory.create(GzipResourceEncodingProviderFactory.java:26)  
at org.keycloak.encoding.GzipResourceEncodingProviderFactory.create(GzipResourceEncodingProviderFactory.java:15)  
at org.keycloak.services.DefaultKeycloakSession.getProvider(DefaultKeycloakSession.java:333)  
at jdk.internal.reflect.GeneratedMethodAccessor28.invoke(Unknown Source)

Seems like it can’t unzip the theme from the jar file to serve the resources (CSS files and such).  
As anyone else experienced this behavior or is it only me / my container environment?  
Any idea on how to fix it?

Thanks for any help!

Regards  
João

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 18, 2022, 6:21pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/2 "2022-03-18T18:21:15Z")

</div>

most probably my bad…  
was setting the container user to Keycloak which is then not able to write on the /opt/keycloak since its owned by root.  
now running the container with root user inside the container it already works fine apparently

(doesn’t quiet explains why sometimes it actually worked)

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 18, 2022, 6:32pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/3 "2022-03-18T18:32:39Z")

</div>

After some further investigation from the base keycloak 17 container I believe we might have a problem here…  
all the /opt/keycloak folder it owned by root, and the default user is keycloak.  
Therefor it is not possible to create the data folder which is expected for the theme

I presume the temp directory at /opt/keycloak/data/tmp should be possible to write by the default user.

 ![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/1/153372337a186c05dcd8b39f80c70c863cfe486a.png)

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 21, 2022, 11:35am UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/4 "2022-03-21T11:35:17Z")

</div>

going a bit further…  
Keycloak belongs to the root group and therefor it can write inside most of /opt/keycloak.  
What it can’t do is create folders under /opt/keycloak (to create the data directory) since the group root doesn’t have write permissions on the /opt/keycloak itself:

![image](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/d/d9736d224e2bfb7ae2d899382b22f9c514342abc.png)

---

<div class="post-metadata">

**Author:** ![bpedersen2](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/bpedersen2/32/3934_2.png) [@bpedersen2](https://forum.keycloak.org/u/bpedersen2)\
**Post date:** [March 21, 2022, 11:48am UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/5 "2022-03-21T11:48:46Z")

</div>

Typically, you should build a custom container with the theme instead of relying on the container doing the initial build on the fly. Then you won’t have a problem as the build is done as root.

Like:

```auto
FROM keycloak:17
WORKDIR /opt/keycloak
COPY *.jar providers/
ENV <set envs for kec build here>

RUN /opt/keycloak/bin/kc.sh build 

```

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 21, 2022, 12:03pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/6 "2022-03-21T12:03:41Z")

</div>

Hi,

Our Dockerfile does what you suggest, and what I believe is suggested from documentation.

FROM [Quay](http://quay.io/keycloak/keycloak:17.0.0) as builder

COPY ourTheme.jar /opt/keycloak/providers/ourTheme.jar  
COPY ourPlugin\*.jar /opt/keycloak/providers/ourPlugins.jar

ENV KC\_DB=postgres  
ENV …  
RUN /opt/keycloak/bin/kc.sh build

FROM [Quay](http://quay.io/keycloak/keycloak:17.0.0)

ENV …

COPY --from=builder /opt/keycloak/lib/quarkus/ /opt/keycloak/lib/quarkus/  
COPY --from=builder /opt/keycloak/providers/ /opt/keycloak/providers/  
WORKDIR /opt/keycloak

ENTRYPOINT ["/opt/keycloak/bin/kc.sh", “start”]

now the problem is that base image has /opt/keycloak not writable by keycloak user, and once the theme tries to unzip some resources to the temporary folder the user can’t create the folder.  
Therefor we need to provide some additional permissions to the user on the folder itself.

Also find weird since original Dockerfile seems to create the folder with the right group permissions if I understand it correctly ([keycloak/Dockerfile at main · keycloak/keycloak · GitHub](https://github.com/keycloak/keycloak/blob/main/quarkus/container/Dockerfile))

---

<div class="post-metadata">

**Author:** ![bpedersen2](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/bpedersen2/32/3934_2.png) [@bpedersen2](https://forum.keycloak.org/u/bpedersen2)\
**Post date:** [March 21, 2022, 12:22pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/7 "2022-03-21T12:22:01Z")

</div>

Yes, so you have to switch to user 0 in your build image and swizch back (maybe even update the permission again)

An alternative is to just use the upstream docker file and adopt it to your needs (so copying the jar files and run build in the builder image.)

---

<div class="post-metadata">

**Author:** ![joao-rebelo](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/joao-rebelo/32/3487_2.png) [@joao-rebelo](https://forum.keycloak.org/u/joao-rebelo)\
**Post date:** [March 24, 2022, 1:24pm UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/8 "2022-03-24T13:24:04Z")

</div>

with release 17.0.1 this is now solved as /opt/keycloak is owned by keycloak user not root.

---

<div class="post-metadata">

**Author:** ![TBG-FR](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/tbg-fr/32/8389_2.png) [@TBG-FR](https://forum.keycloak.org/u/TBG-FR)\
**Post date:** [June 12, 2023, 11:41am UTC](https://forum.keycloak.org/t/keycloak-17-on-container-fails-to-extract-theme-from-jar/14425/9 "2023-06-12T11:41:45Z")

</div>

Reproduced that issue with `quay.io/keycloak/keycloak:20.0.3`

Turns out the issue was coming from the misdownloaded/built `.jar` and not Keycloak 🙃
