fix: run simulator image as non-root user (Trivy DS-0002)
Add swarm uid 10001 in both build stages so Trivy config scan passes and containers do not run as root. Mounted /data volumes should be world-writable or owned by uid 10001 (var/t1 from Ansible is 0777).
This commit is contained in:
@@ -7,6 +7,10 @@ COPY virtual_drone ./virtual_drone
|
||||
COPY monitoring ./monitoring
|
||||
COPY explorer ./explorer
|
||||
COPY tests ./tests
|
||||
RUN groupadd --gid 10001 swarm \
|
||||
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
|
||||
&& chown -R swarm:swarm /app
|
||||
USER swarm
|
||||
RUN pytest tests/ -q
|
||||
|
||||
FROM python:3.12-slim
|
||||
@@ -19,6 +23,11 @@ COPY virtual_drone ./virtual_drone
|
||||
# them without bind mounts (Compose overrides these with live mounts)
|
||||
COPY monitoring ./monitoring
|
||||
COPY explorer ./explorer
|
||||
RUN groupadd --gid 10001 swarm \
|
||||
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
|
||||
&& mkdir -p /data \
|
||||
&& chown -R swarm:swarm /app /data
|
||||
|
||||
ENV DATA_DIR=/data
|
||||
USER swarm
|
||||
CMD ["python", "-m", "virtual_drone.main"]
|
||||
|
||||
Reference in New Issue
Block a user