hardening: run production container as non-root user #19
1 changed files with 6 additions and 0 deletions
|
|
@ -52,6 +52,12 @@ COPY --from=build /app/src/emails/ ./dist/emails/
|
|||
# Create data directory for SQLite
|
||||
RUN mkdir -p /data
|
||||
|
||||
# Create non-root user for security hardening
|
||||
RUN addgroup -S app && adduser -S -G app app
|
||||
RUN chown -R app:app /data
|
||||
|
||||
USER app
|
||||
|
||||
EXPOSE 4738
|
||||
|
||||
ENV NODE_ENV=production
|
||||
|
|
|
|||
Loading…
Reference in a new issue