hardening: run production container as non-root user
All checks were successful
CI / checks (pull_request) Successful in 38s

Add a dedicated 'app' user/group in the production image stage so the
application runs without root privileges. The build stage retains root
for apk add of build-time dependencies.

Changes:
- Create 'app' user and group via addgroup/adduser
- Change ownership of /data to app:app
- Set USER app before EXPOSE and CMD

Closes mailship-c3s
This commit is contained in:
Agent 2026-09-18 10:30:52 -04:00
parent 8235513822
commit dfdc6d489c

View file

@ -52,6 +52,12 @@ COPY --from=build /app/src/emails/ ./dist/emails/
# Create data directory for SQLite
RUN mkdir -p /data
# Create non-root user for security hardening
RUN addgroup -S app && adduser -S -G app app
RUN chown -R app:app /data
USER app
EXPOSE 4738
ENV NODE_ENV=production