fix: run simulator image as non-root user (Trivy DS-0002)

Add swarm uid 10001 in both build stages so Trivy config scan passes
and containers do not run as root. Mounted /data volumes should be
world-writable or owned by uid 10001 (var/t1 from Ansible is 0777).
This commit is contained in:
2026-07-08 20:20:19 +01:00
parent de1c7c9558
commit 1585c8f12f
+9
View File
@@ -7,6 +7,10 @@ COPY virtual_drone ./virtual_drone
COPY monitoring ./monitoring COPY monitoring ./monitoring
COPY explorer ./explorer COPY explorer ./explorer
COPY tests ./tests COPY tests ./tests
RUN groupadd --gid 10001 swarm \
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
&& chown -R swarm:swarm /app
USER swarm
RUN pytest tests/ -q RUN pytest tests/ -q
FROM python:3.12-slim FROM python:3.12-slim
@@ -19,6 +23,11 @@ COPY virtual_drone ./virtual_drone
# them without bind mounts (Compose overrides these with live mounts) # them without bind mounts (Compose overrides these with live mounts)
COPY monitoring ./monitoring COPY monitoring ./monitoring
COPY explorer ./explorer COPY explorer ./explorer
RUN groupadd --gid 10001 swarm \
&& useradd --uid 10001 --gid swarm --home-dir /app --shell /usr/sbin/nologin swarm \
&& mkdir -p /data \
&& chown -R swarm:swarm /app /data
ENV DATA_DIR=/data ENV DATA_DIR=/data
USER swarm
CMD ["python", "-m", "virtual_drone.main"] CMD ["python", "-m", "virtual_drone.main"]