Problem
In Dockerfile:
FROM alpine:latest
WORKDIR /app
COPY --from=builder /app/app .
COPY filters/ ./filters/
ENTRYPOINT ["./app"]
The runtime container runs as the root user (uid 0). Running as root in containers violates the principle of least privilege and introduces security risks in container orchestration environments (e.g. ECS, Kubernetes, or containerized runners) if a container escape vulnerability exists.
Proposed Solution
Add an unprivileged system user and group in Alpine and switch to it using the USER directive:
FROM alpine:latest
RUN addgroup -S appgroup && adduser -S appuser -G appgroup
WORKDIR /app
COPY --from=builder --chown=appuser:appgroup /app/app .
COPY --chown=appuser:appgroup filters/ ./filters/
USER appuser
ENTRYPOINT ["./app"]
Acceptance Criteria
Problem
In Dockerfile:
The runtime container runs as the
rootuser (uid 0). Running as root in containers violates the principle of least privilege and introduces security risks in container orchestration environments (e.g. ECS, Kubernetes, or containerized runners) if a container escape vulnerability exists.Proposed Solution
Add an unprivileged system user and group in Alpine and switch to it using the
USERdirective:Acceptance Criteria
appuser/ non-zero UID)/appare restricted to the non-root usermake docker-build