Docker creates /home/voicebox/.cache (parent of the huggingface-cache
volume mountpoint) owned by root on every container create, and a
fresh named volume is root-owned too. The app runs as the voicebox
user (uid 999), so anything that writes a cache outside the HF mount
(torch hub, spacy, ...) fails with Permission denied.
The entrypoint already runs as root before dropping privileges via
gosu — create/chown the cache dirs there (non-recursive, instant).
Co-Authored-By: Claude Fable 5 <[email protected]>