hardening: run production container as non-root user #19
Loading…
Reference in a new issue
No description provided.
Delete branch "mailship-c3s-docker-run-production-container-as-non-r-4e7"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
mailship-c3s
The production Docker stage currently runs as root. This change creates a dedicated non-root user (
app) and switches to it before runtime, reducing the impact of a container compromise.Changes:
addgroup -S app && adduser -S -G app appto create the non-root user and group in the production stagechown -R app:app /dataso the SQLite data directory is writable by the app userUSER appbeforeEXPOSEandCMDso the container runs as non-rootThe
buildstage is unaffected — it retains root forapk add python3 make g++ gitand other build-time needs.How to test:
docker build --target production .then verify the container starts and can write to/data(e.g.docker run --rm <image> touch /data/test.txt).