# Home directory not found, can't use shell session

**URL:** <https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277>\
**Category:** Get Help\
**Tags:** question\
**Created:** [January 19, 2021, 10:45pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277 "2021-01-19T22:45:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![SkoUtes](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/skoutes/32/787_2.png) [@SkoUtes](https://discourse.openondemand.org/u/SkoUtes)\
**Post date:** [January 19, 2021, 10:45pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/1 "2021-01-19T22:45:12Z")

</div>

Hi, I’m trying to set up a Kubernetes deployment of Open OnDemand using Keycloak for authentication, and I’m running into the same issue as the one at

> [@Launching OnDemand when home directory does not exist](https://discourse.openondemand.org/t/launching-ondemand-when-home-directory-does-not-exist/53/3):
>
> That experiment failed. However, there appears to be another solution. A modification to nginx\_stage/lib/nginx\_stage/views/pun\_config\_view.rb and nginx\_stage/templates/pun.conf.erb to show a warning page if the home directory was not found. Along with this diabeling the check for the existence of the home directory in nginx\_stage/lib/nginx\_stage/generator\_helpers.rb. The result is this workflow. When launching OnDemand with an account that does not have a home directory created, you would see t…

We would rather not allow users to SSH into the OnDemand container as is the typical solution for this problem. Though it can be done, we’d like to avoid it for security reasons. Is there any way to get around this “missing home directory” page? Can you disable this error page and allow users to log in regardless of missing homedirs?

If there is no way around it we can try setting up SSH to work but restricting the /etc/hosts.allow file. Still, we would like to avoid SSH if at all possible.

Thanks!

---

<div class="post-metadata">

**Author:** ![jeff.ohrstrom](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/jeff.ohrstrom/32/136_2.png) [@jeff.ohrstrom](https://discourse.openondemand.org/u/jeff.ohrstrom)\
**Post date:** [January 20, 2021, 2:28pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/2 "2021-01-20T14:28:05Z")

</div>

> [@SkoUtes](#):
>
> an you disable this error page and allow users to log in regardless of missing homedirs?

I don’t think so, we rely pretty heavily on the assumption it exists and write to it.

If you want to avoid ssh then I’d ask “what other mechanism can create a user’s home directory?”

---

<div class="post-metadata">

**Author:** ![efranz](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/efranz/32/27_2.png) [@efranz](https://discourse.openondemand.org/u/efranz)\
**Post date:** [January 20, 2021, 3:19pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/3 "2021-01-20T15:19:02Z")

</div>

Is there no way to ensure a home directory is present in the container while still preventing users from SSH-ing into the container?

The versions of rubygems included in the versions of Ruby we use currently do `File.expand_path "~"` to find the home directory (which in turn uses `getpwnam` to get the password struct for the user which has the home directory path. In other places in the code, we use `Dir.home` which respects just `$HOME` environment variable. In the container, the processes would need both env var and the password struct returned by `getpwnam` to point to a directory that exists.

If the home directory is not present, a crash occurs on startup of the Rails apps. I actually thought this was a bug not in OnDemand but in Ruby standard library itself, though it was a while ago when I debugged this issue so my memory is fuzzy.

---

<div class="post-metadata">

**Author:** ![SkoUtes](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/skoutes/32/787_2.png) [@SkoUtes](https://discourse.openondemand.org/u/SkoUtes)\
**Post date:** [January 20, 2021, 11:02pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/4 "2021-01-20T23:02:15Z")

</div>

Well, we can look into setting up SSSD and pam\_mkhomedir in the container. We also might be able to mount a filesystem using Autofs. It really depends on what will work and can meet our various needs.

Thanks for explaining that, though. I know it’s a bit of a fringe case.

---

<div class="post-metadata">

**Author:** ![SkoUtes](https://sea1.discourse-cdn.com/flex015/user_avatar/discourse.openondemand.org/skoutes/32/787_2.png) [@SkoUtes](https://discourse.openondemand.org/u/SkoUtes)\
**Post date:** [January 22, 2021, 11:50pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/5 "2021-01-22T23:50:24Z")

</div>

Okay looks like I got it working. I set up an incrontab to run a script whenever /var/log/httpd24/access.log is edited. The script looks for new PUN directories in /var/log/ondemand-nginx and then makes a home directory for those users

```
#!/bin/bash
mkdir -p $(ls -1 -d /var/log/ondemand-nginx/*/ | tr -d '/' | sed 's/\(varlogondemand-nginx\)//g' | xargs -L 1 echo /home/ | tr -d ' ')
```

---

<div class="post-metadata">

**Author:** ![westburg.2](https://avatars.discourse-cdn.com/v4/letter/w/0ea827/32.png) [@westburg.2](https://discourse.openondemand.org/u/westburg.2)\
**Post date:** [May 26, 2022, 3:43pm UTC](https://discourse.openondemand.org/t/home-directory-not-found-cant-use-shell-session/1277/6 "2022-05-26T15:43:02Z")

</div>


