hardening: run production container as non-root user
All checks were successful
CI / checks (pull_request) Successful in 38s
All checks were successful
CI / checks (pull_request) Successful in 38s
Add a dedicated 'app' user/group in the production image stage so the application runs without root privileges. The build stage retains root for apk add of build-time dependencies. Changes: - Create 'app' user and group via addgroup/adduser - Change ownership of /data to app:app - Set USER app before EXPOSE and CMD Closes mailship-c3s
This commit is contained in:
parent
8235513822
commit
dfdc6d489c
1 changed files with 6 additions and 0 deletions
|
|
@ -52,6 +52,12 @@ COPY --from=build /app/src/emails/ ./dist/emails/
|
|||
# Create data directory for SQLite
|
||||
RUN mkdir -p /data
|
||||
|
||||
# Create non-root user for security hardening
|
||||
RUN addgroup -S app && adduser -S -G app app
|
||||
RUN chown -R app:app /data
|
||||
|
||||
USER app
|
||||
|
||||
EXPOSE 4738
|
||||
|
||||
ENV NODE_ENV=production
|
||||
|
|
|
|||
Loading…
Reference in a new issue