Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add Non-root User #20

Open
hutson opened this issue Jul 22, 2017 · 5 comments
Open

Add Non-root User #20

hutson opened this issue Jul 22, 2017 · 5 comments

Comments

@hutson
Copy link
Contributor

hutson commented Jul 22, 2017

Docker's Security guide has a Conclusions section that recommends, for added security, configuring a non-root user.

For example, all node images have a node user that can be accessed by passing --user node to docker run.

Some background on Docker security best practices - https://groups.google.com/forum/#!msg/docker-user/e9RkC4y-21E/JOZF8H-PfYsJ

@jojomi
Copy link
Owner

jojomi commented Dec 5, 2017

That is a good idea! Would you be able to create a little PR implementing this @hbetts ?

@bitorius
Copy link

bitorius commented Dec 21, 2017

@jojomi I've made some modifications and added non-root user as well. I've got the changes on GitLab, what's the best method to get these to you? Should I fork it here on GH and then request a pull?

@hutson
Copy link
Contributor Author

hutson commented Dec 21, 2017

@avinashmx would you mind submitting a pull request to bring in your changes?

Sorry I didn't get a chance to submit a pull request with a non-root user. Got tied up with other things.

I'd like to see what additional changes you came up with @avinashmx, as I'm trying to learn best practices around Docker image configurations.

@bitorius
Copy link

@hbetts Sure, let me fork it on GH, and then merge in changes and submit the pull request. Unfortunately, it's a little muddied as I made a change to allow creation of a new installation as well.

@jojomi
Copy link
Owner

jojomi commented Dec 23, 2017

I'll gladly have a look :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants