Agent skill

Gorse Runasnonroot Failure

by divinevideo in divinevideo/divine-mobile

Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error.

MPL-2.0Auto-check passedDevOps & Cloud

Install Gorse Runasnonroot Failure

skills CLI
$ npx skills add divinevideo/divine-mobile --skill gorse-runasnonroot-failure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install divinevideo/divine-mobile gorse-runasnonroot-failure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/divinevideo/divine-mobile.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/gorse-runasnonroot-failure .claude/skills/gorse-runasnonroot-failure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gorse-runasnonroot-failure
GitHub stars
266
Token cost
~707 tokens
SKILL.md length
248 words
Files
1
Skills in repo
103
Repo updated
First seen
Licence
MPL-2.0

At a glance

Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error.

  • Works in 4 steps: Delete existing crashing pods: kubectl… → Wait for new pods to start → Check logs: kubectl logs -l… → …
  • Gorse master/server/worker pods show CrashLoopBackOff
  • SKILL.md covers Problem, Context / Trigger Conditions, Root Cause and Solution, plus 3 more sections
  • Calls kubectl

What it does

Gorse Runasnonroot Failure is an agent skill from divinevideo/divine-mobile. Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error. Use when: (1) Gorse master/server/worker pods show CrashLoopBackOff or Error status, (2) Logs show "failed to get user directory" with unknown userid, (3) Running gorse containers with runAsNonRoot security context and custom UID. The gorse images call os.UserHomeDir() at startup which requires the UID to exist in /etc/passwd.

Its SKILL.md is about 710 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Kubernetes. The licence is MPL-2.0.

When your agent uses it

  • Gorse master/server/worker pods show CrashLoopBackOff
  • Logs show failed to get user directory with unknown userid
  • Running gorse containers with runAsNonRoot security context and custom UID

Example prompts

  • “user: unknown userid 65532”
  • “failed to get user directory”
  • “/gorse-runasnonroot-failure”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Delete existing crashing pods: kubectl delete pods -l app.kubernetes.io/name=gorse -n gorse
  2. Wait for new pods to start
  3. Check logs: kubectl logs -l app=gorse-master -n gorse
  4. Verify master shows connection to data store and cache store

What it can do on your machine

Read from SKILL.md and the folder at commit 6487b05. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gorse Runasnonroot Failure loads about 707 tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 248 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~707

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from divinevideo/divine-mobile at commit 6487b05, republished under its MPL-2.0 licence (© divinevideo). 248 words, ~707 tokens.

Download SKILL.mdSave it as .claude/skills/gorse-runasnonroot-failure/SKILL.md (or your agent's skills folder).
name
gorse-runasnonroot-failure
description
Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error. Use when: (1) Gorse master/server/worker pods show CrashLoopBackOff or Error status, (2) Logs show "failed to get user directory" with unknown userid, (3) Running gorse containers with runAsNonRoot security context and custom UID. The gorse images call os.UserHomeDir() at startup which requires the UID to exist in /etc/passwd.
author
Claude Code
version
1.0.0
date
2026-01-29

Gorse runAsNonRoot Container Failure

Problem

Gorse recommendation engine containers (master, server, worker) crash immediately on startup when running with Kubernetes runAsNonRoot: true and a custom UID like 65532.

Context / Trigger Conditions

  • Gorse pods show CrashLoopBackOff or Error status
  • Pod logs show:
    {"level":"fatal","ts":...,"caller":"model/built_in.go:95","msg":"failed to get user directory","error":"user: unknown userid 65532"}
  • Deployment has securityContext.runAsNonRoot: true and runAsUser: 65532
  • Using official gorse images (zhenghaoz/gorse-master, zhenghaoz/gorse-server, zhenghaoz/gorse-worker)

Root Cause

The gorse codebase calls Go's os.UserHomeDir() during initialization in model/built_in.go. This function requires the running UID to have an entry in /etc/passwd. When running as a non-root user that doesn't exist in the container's passwd file, the lookup fails.

Solution

Remove the runAsNonRoot and runAsUser constraints from the pod security context:

yaml
# Before (broken)
spec:
  template:
    spec:
      securityContext:
        runAsNonRoot: true
        runAsUser: 65532
        fsGroup: 65532

# After (working)
spec:
  template:
    spec:
      securityContext:
        fsGroup: 1000

Apply to all gorse deployments:

  • deployment-master.yaml
  • deployment-server.yaml
  • deployment-worker.yaml
  • init-db-job.yaml (if using init job)

Verification

After updating the security context:

  1. Delete existing crashing pods: kubectl delete pods -l app.kubernetes.io/name=gorse -n gorse
  2. Wait for new pods to start
  3. Check logs: kubectl logs -l app=gorse-master -n gorse
  4. Verify master shows connection to data store and cache store

Notes

  • This is a limitation of the official gorse images, not a Kubernetes issue
  • The gorse project may fix this in future versions by not requiring home directory
  • If security policy requires non-root, you would need to build custom gorse images with proper /etc/passwd entries for the desired UID
  • Redis Stack images used for gorse cache have the same issue with UID 65532
  • Gorse GitHub: The images don't document this requirement
  • Similar issues affect other Go applications that use os.UserHomeDir()

© divinevideo, MPL-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/gorse-runasnonroot-failure of divinevideo/divine-mobile.

Open the folder on GitHubat commit 6487b05

Compare with similar skills

Gorse Runasnonroot Failure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gorse Runasnonroot Failure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gorse Runasnonroot Failure this skilldivinevideo/divine-mobile266—~707Automated safety check: PassMPL-2.0
Kubeshark Installerkubeshark/kubeshark12k—~3.6kAutomated safety check: NotesApache-2.0
KubeSphere Multi-Tenant Managementkubesphere/kubesphere17k—~3.1kAutomated safety check: PassCustom licence
Sim Helmsimstudioai/sim30k—~2.2kAutomated safety check: PassApache-2.0
Helm Chart ScaffoldingCybereason-Public/owLSM28013 repos~381Automated safety check: PassGPL-2.0
Kubeshark KFL2 Filter Referencekubeshark/kubeshark12k—~3.6kAutomated safety check: PassApache-2.0

Similar skills

  • Kubeshark Installer

    kubeshark/kubeshark

    Installs and configures Kubeshark on a Kubernetes cluster, choosing between the quick CLI path and a Helm install with custom values.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything.

    17k GitHub stars~3.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Sim Helm

    simstudioai/sim

    Install, upgrade, and operate the Sim Helm chart on Kubernetes.

    30k GitHub stars~2.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Helm Chart Scaffolding

    Cybereason-Public/owLSM

    Comprehensive guidance for creating, organizing, and managing Helm charts for packaging and deploying Kubernetes applications.

    280 GitHub starsUsed in 13 repos~381 tokens
    DevOps & CloudAuto-check passed
  • Syntax reference for KFL2, the CEL-based display filter language used to search Kubernetes network traffic captured by Kubeshark, loaded before any filter is written.

    12k GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere ServiceMesh Manager

    kubesphere/kubesphere

    Installs, checks and troubleshoots the KubeSphere ServiceMesh extension (Istio, Kiali, Jaeger), including grayscale release, sidecar injection, topology and tracing issues.

    17k GitHub stars~2.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed

More from divinevideo/divine-mobile

All 103 skills in this repo
  • Fix ArgoCD ExternalSecret deployment failing with "namespace X is not permitted in project Y".

    266 GitHub stars~931 tokensUpdated today
    Auto-check passed
  • Art Direct

    divinevideo/divine-mobile

    Art direction for any content — reads text, PDF, Word, HTML, PPT, then proposes 2-3 creative directions with photography style, mood, and visual language.

    266 GitHub stars~4.8k tokensUpdated today
    Auto-check passed
  • Async Await Null Race Condition

    divinevideo/divine-mobile

    Fix "Null check operator used on a null value" errors when an object is set to null during an async await.

    266 GitHub stars~881 tokensUpdated today
    Auto-check passed
  • AWS V4 Signing Custom Headers Gcs

    divinevideo/divine-mobile

    Add custom metadata headers (x-amz-meta-) to AWS v4 signed requests for GCS S3-compatible API.

    266 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Bash Herestring Newline Secrets

    divinevideo/divine-mobile

    Fix password/secret authentication failures caused by trailing newlines when creating Google Cloud secrets (or similar) with bash here-strings.

    266 GitHub stars~791 tokensUpdated today
    Auto-check passed
  • Fix silent video/media processing failures caused by URL extraction code that filters on file extensions (.mp4, .webm, .webp).

    266 GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Gorse Runasnonroot Failure

What does Gorse Runasnonroot Failure do?

Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error. Gorse Runasnonroot Failure is an agent skill from divinevideo/divine-mobile. Fix Gorse recommendation engine pods crashing with "user: unknown userid 65532" error.

When should I use Gorse Runasnonroot Failure?

Gorse Runasnonroot Failure fits situations like: gorse master/server/worker pods show CrashLoopBackOff; logs show failed to get user directory with unknown userid; running gorse containers with runAsNonRoot security context and custom UID.

How do I install Gorse Runasnonroot Failure in Claude Code?

Run `npx skills add divinevideo/divine-mobile --skill gorse-runasnonroot-failure -a claude-code`. Or copy the skill folder (.agents/skills/gorse-runasnonroot-failure in divinevideo/divine-mobile) into .claude/skills/gorse-runasnonroot-failure in your project. Claude Code loads it when a task matches its description.

How do I install Gorse Runasnonroot Failure in Codex?

Run `npx skills add divinevideo/divine-mobile --skill gorse-runasnonroot-failure -a codex`. Or copy the skill folder (.agents/skills/gorse-runasnonroot-failure in divinevideo/divine-mobile) into .agents/skills/gorse-runasnonroot-failure in your project. Codex loads it when a task matches its description.

Can I use Gorse Runasnonroot Failure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add divinevideo/divine-mobile --skill gorse-runasnonroot-failure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gorse-runasnonroot-failure, .gemini/skills/gorse-runasnonroot-failure, .github/skills/gorse-runasnonroot-failure and .opencode/skills/gorse-runasnonroot-failure in your project.

What does Gorse Runasnonroot Failure need to run?

Going by SKILL.md and its folder, Gorse Runasnonroot Failure needs the command-line tools its instructions call (kubectl).

Does Gorse Runasnonroot Failure access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Gorse Runasnonroot Failure safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gorse Runasnonroot Failure use?

Gorse Runasnonroot Failure is published under the MPL-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gorse Runasnonroot Failure use?

About 707 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gorse Runasnonroot Failure?

Skills that share tags, products or a category with Gorse Runasnonroot Failure: Kubeshark Installer (kubeshark/kubeshark, 12k stars), KubeSphere Multi-Tenant Management (kubesphere/kubesphere, 17k stars), Sim Helm (simstudioai/sim, 30k stars) and Helm Chart Scaffolding (Cybereason-Public/owLSM, 280 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gorse Runasnonroot Failure?

divinevideo (a GitHub organization) maintains it in divinevideo/divine-mobile, which has 266 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 9, 2026.

Source: divinevideo/divine-mobile on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.