hardening: run production container as non-root user #19
1 changed files with 6 additions and 0 deletions
|
|
@ -52,6 +52,12 @@ COPY --from=build /app/src/emails/ ./dist/emails/
|
||||||
# Create data directory for SQLite
|
# Create data directory for SQLite
|
||||||
RUN mkdir -p /data
|
RUN mkdir -p /data
|
||||||
|
|
||||||
|
# Create non-root user for security hardening
|
||||||
|
RUN addgroup -S app && adduser -S -G app app
|
||||||
|
RUN chown -R app:app /data
|
||||||
|
|
||||||
|
USER app
|
||||||
|
|
||||||
EXPOSE 4738
|
EXPOSE 4738
|
||||||
|
|
||||||
ENV NODE_ENV=production
|
ENV NODE_ENV=production
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue