Repository navigation
[Enhancement]: Support running LibreChat with a read-only container filesystem #16522
peeeteeer
started this conversation in
Feature Requests & Suggestions
Replies: 1 comment 1 reply
|
@peeeteeer misread your post, I think these are reasonable asks, will add to our roadmap. |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What features would you like to see added?
Problem
LibreChat still writes to the local container filesystem in several runtime paths. This makes it difficult or impossible to run the application with a read-only root filesystem, which is a common hardening requirement for Kubernetes/OpenShift/containerized production deployments.
Operators can configure external storage such as S3 for uploaded files, but some code paths still create local files or directories for logs, uploads, avatars, or generated assets.
Desired behavior
LibreChat should be able to run with the application container filesystem mounted read-only, provided that persistent file storage is configured through an external backend.
Why this matters
Read-only containers reduce the blast radius of application compromise and are required by many enterprise/container security baselines. Supporting this mode would make LibreChat easier to run in hardened Kubernetes and OpenShift environments without downstream patches.
More details
Known write paths / areas to address
Log file transports
Uploads
multer.diskStorage.multer.memoryStoragefor large uploads unless there is no streaming-compatible alternative.Avatars
LLM-generated files
Which components are impacted by your request?
No response
Pictures
No response
Code of Conduct
All reactions