# Docker NR & ttyUSB0 Permission denied

**URL:** <https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803>\
**Category:** General\
**Created:** [27 April 2021 12:48 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803 "2021-04-27T12:48:41Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 12:48 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/1 "2021-04-27T12:48:41Z")

</div>

Hello, since a few days I test NR Docker.  
I use [Portainer.io](http://Portainer.io) to manage my containers. It's quite simple.  
Now I want to be able to use the serialport node to read what is on the USB port (RFlink card) of my OrangePi.  
So I found the place where to bring up the ttyUSB0 port in the container, but there is still a problem of access rights. I don't know how and where to add the node-red user to the diaolout group or maybe launch the container as root?

Would you have any suggestions, solutions to help me.

**Thanks to all !**

Inside the NR container:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/8/b847b31f31ddb9c710c9ac63131b13a2e571cf86.png)

Inside [Portainer.io](http://Portainer.io)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/4/d4304000385b2a1bca87974de1f31e8c5182b48f.png)

On the editor

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/8/886cc75dc77d10554208cd14da8208d8d05c17a2.png)

The whole stack

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/c/1c4dd7e5d5ddd22c3b4c41e177ce88cd7172b8b4.png)

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [27 April 2021 13:16 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/2 "2021-04-27T13:16:38Z")

</div>

You can add node-red to the dialout group by adding the following commands in your node-red dockerfile

```auto
USER root
RUN addgroup node-red dialout
USER node-red

```

maybe you also need to check if your dialout group exists in your docker container an is having the same group ID as your host machine.

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 13:17 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/3 "2021-04-27T13:17:08Z")

</div>

I read in the [documentation](https://nodered.org/docs/getting-started/docker) that you have to launch the container with the addition of the user to the dialout group,  
but I can't find the way to make it work under [portainer.io](http://portainer.io)  
Syntax error ?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/6/a6f60f7710215999af4e5902a1cb58f53b44cbce.png)

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 13:20 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/4 "2021-04-27T13:20:17Z")

</div>

this is what i see under the Pi for USB0

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/0/f0c64067a2be0cd94c974a9e0de01452125f49b3.png)

With portainer GUI, we don't use dockerfile 🙃  
i tried to translate this specific command with no luck actually

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [27 April 2021 13:28 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/5 "2021-04-27T13:28:06Z")

</div>

What is your actual command to run the container ?

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 13:39 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/6 "2021-04-27T13:39:24Z")

</div>

Sorry, I don't know, because everything is hidden by the [portainer.io](http://portainer.io) GUI.  
Here is the container log, it seems that the additional command is taken into account, at least I have the impression.  
I tried to change the User by root, so I lost my flow but still the access problem.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/2/f250a41183d6232685e2597b64c6b53f52516329.png)

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [27 April 2021 14:07 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/7 "2021-04-27T14:07:22Z")

</div>

The `--group-add` option is a docker run option and not a node.js option.

You should be able to specify it somehow when creating a new container.

---

<div class="post-metadata">

**Author:** ![dceejay](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dceejay/32/38_2.png) [@dceejay](https://discourse.nodered.org/u/dceejay)\
**Post date:** [27 April 2021 14:09 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/8 "2021-04-27T14:09:02Z")

</div>

you can always start (run) the container from outside portainer - and then manage it from there (and then maybe see where is sets/saves that extra option)

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 14:40 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/9 "2021-04-27T14:40:54Z")

</div>

yes indeed, I will try to understand the dockerfile commands and run it by hand.  
I may ask the question in the portainer forum.  
I looked in the directory used by portainer, it seems that it uses its DB to store its configuration, no traces of a readable file 😔

Did you use this tool or do you pass the commands by hand?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/a/daceb4260b013608c7044a65420e85102c1b7190.png)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [27 April 2021 14:57 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/10 "2021-04-27T14:57:23Z")

</div>

How do you add node red in portainer? Do you specify a docker image?

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 15:26 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/11 "2021-04-27T15:26:46Z")

</div>

The image is: nodered/node-red (it takes the latest)

The process is:

1. create the volume:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/b/3b817a9f15f0b9262d86d8388604ae948826ed68.png)

Add Network if needed:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/7/8/7855a3aa341afa8d7962beee3f784625e4e172e5.png)

1. Add container:  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/d/2/d232a8661ddc825899fe2c6343476afb823a9c5e.png)

and fill the yellow fields

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/6/163d824570bf1e193a415036c4b9de385085b8b0.png)

Under Volume:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/0/000207d89a2d4a9a5f581653167d0f42586584f8.png)

Under Network :  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/0/a/0a3444963c941fbe048a235ed151b6d4cc0281fe.png)

Under Runtime

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/c/1/c109e8007f6ec5ee24fb0968ccb3251923e7dddc.png)

And press Deploy and that's it  
 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/b/6bd36223384cc351a54c354ee3aa4efa9255c031.png)

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/4/8453a41cef675b4769ac758c1e56a6022fb5b2b8.png)

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [27 April 2021 15:58 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/12 "2021-04-27T15:58:03Z")

</div>

So one solution would be to build your own image with the appropriate modifications.

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 16:12 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/13 "2021-04-27T16:12:48Z")

</div>

I'll do some digging, I have a feeling it's just a syntax problem in the Command field.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/d/8d60130f51aaccea249509f4abdd42ea531d2851.png)

I can see in the container log that the order is placed but it is malformed compared to what I circled in red

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/1/2/12063dc9ffdb2f14aa26745273073a211b0d3a54.png)

build my container, probably the next step 🤔  
For now I want to stay with the standard

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [27 April 2021 17:20 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/14 "2021-04-27T17:20:36Z")

</div>

> [@Jean-Luc](#):
>
> I'll do some digging, I have a feeling it's just a syntax problem in the Command field.

I don't think that is your problem.

The command field allows you to specify the docker [CMD](https://docs.docker.com/engine/reference/builder/#cmd) for your container.

What you need is a way to specify docker run options (more particularly the [--group-add](https://docs.docker.com/engine/reference/run/#additional-groups) option).  
I understand that you have created your container by adding the container via portainer.  
I did have a quick look and I don't think it is possible to specify docker run options via portainer.

You can of course create an image from a simple container that is adding the dialout group for node-red user (see my earlier post) and select this image in portainer when adding a new container.

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 18:35 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/15 "2021-04-27T18:35:16Z")

</div>

> [@janvda](#):
>
> I understand that you have created your container by adding the container via portainer.

Yes, i did.

I just asked the question in the [portainer.io](http://portainer.io) forum.  
If I get a positive answer, I'll come back to put it on my post

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [27 April 2021 18:48 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/16 "2021-04-27T18:48:23Z")

</div>

I just found this possibility into [Portainer.io](http://Portainer.io).  
This could be the place to write the orders used when creating a container

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/1/310f6e5a694628ff26dd3933c119f9baba944e7f.png)

---

<div class="post-metadata">

**Author:** ![janvda](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/janvda/32/234_2.png) [@janvda](https://discourse.nodered.org/u/janvda)\
**Post date:** [28 April 2021 08:19 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/17 "2021-04-28T08:19:42Z")

</div>

What you mention there is the possibility to use a docker-compose file, but I don't think you can add a group to node-red via a docker-compose file.

You need to create a simple image that sets the permission.  
So you need to create a Dockerfile with following contents on the host machine where portainer is running.

```auto
FROM nodered/node-red

USER root
RUN addgroup node-red dialout
USER node-red

```

You can a build an docker image based on the above Dockerfile using below command (should be run in the same folder where you have created the above Dockerfile)

```auto
[root@nuc-jan test]# docker build -t node-red-with-dialout-permissions .
Sending build context to Docker daemon 2.048kB
Step 1/4 : FROM nodered/node-red:1.2.9-12
 ---> 9772fc53c59f
Step 2/4 : USER root
 ---> Using cache
 ---> f51e7cd902b0
Step 3/4 : RUN addgroup node-red dialout
 ---> Running in 15b6a066db67
Removing intermediate container 15b6a066db67
 ---> dfcc57c65d21
Step 4/4 : USER node-red
 ---> Running in 407d4e0100a9
Removing intermediate container 407d4e0100a9
 ---> 0e44d20e1653
Successfully built 0e44d20e1653
Successfully tagged node-red-with-dialout-permissions:latest
[root@nuc-jan test]# 

```

Now you can deploy a container using image `node-red-with-dialout-permissions:latest` in portainer as you used to do.

I have tested this and it works for me as you can see in screenshot below:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/a/a/aa74c67d2ed242d37c4a9211e49f6e4f6590cbfa.png)

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [28 April 2021 16:25 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/19 "2021-04-28T16:25:11Z")

</div>

> [@janvda](#):
>
> `node-red-with-dialout-permissions:latest`

It does indeed work. Great 😃  
You have to do things on the command line. as often  
I'm going to get an arduino to connect to the USB and see if there is a real dialog that goes back to NR.  
I'll give you a feedback as soon as I've done the manipulation.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/8/3/83b19ccc5cd0f5ce03f08719fe576b222c1c6b99.png)

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [28 April 2021 16:46 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/20 "2021-04-28T16:46:13Z")

</div>

Yes, it works.  
Except that the name USB0 has become ACM0.  
Changed this in the container and the flow, Et voilà !

I really appreciate your help in moving forward on the docker path.

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/b/1/b129f1b507fbca3f68c82136e8deec1ab6950a8a.png)

---

<div class="post-metadata">

**Author:** ![Jean-Luc](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jean-luc/32/89996_2.png) [@Jean-Luc](https://discourse.nodered.org/u/Jean-Luc)\
**Post date:** [29 April 2021 14:23 UTC](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803/21 "2021-04-29T14:23:55Z")

</div>

So, if I understand correctly, I can create an image with the nodes I need in my flows in the same way.  
One question, what about the configuration-flows-credentials files.  
Will they be included in the image or will they be left separately ?  
The ones in my case /data that physically point to /var/lib/docker/volumes/node\_red\_user\_data/\_data ?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/f/1/f1411d08dedaeab7e886d7548d926ee56b719c11.png)

[Next page](https://discourse.nodered.org/t/docker-nr-ttyusb0-permission-denied/44803.md?page=2)
