Explorar o código

Dockerfile: use non-privileged user account (#16052)

Federico Gimenez %!s(int64=7) %!d(string=hai) anos
pai
achega
50dbe8e244
Modificáronse 2 ficheiros con 12 adicións e 0 borrados
  1. 6 0
      Dockerfile
  2. 6 0
      Dockerfile.alltools

+ 6 - 0
Dockerfile

@@ -12,5 +12,11 @@ FROM alpine:latest
 RUN apk add --no-cache ca-certificates
 COPY --from=builder /go-ethereum/build/bin/geth /usr/local/bin/
 
+RUN addgroup -g 1000 geth && \
+    adduser -h /root -D -u 1000 -G geth geth && \
+    chown geth:geth /root
+
+USER geth
+
 EXPOSE 8545 8546 30303 30303/udp 30304/udp
 ENTRYPOINT ["geth"]

+ 6 - 0
Dockerfile.alltools

@@ -12,4 +12,10 @@ FROM alpine:latest
 RUN apk add --no-cache ca-certificates
 COPY --from=builder /go-ethereum/build/bin/* /usr/local/bin/
 
+RUN addgroup -g 1000 geth && \
+    adduser -h /root -D -u 1000 -G geth geth \
+    chown geth:geth /root
+
+USER geth
+
 EXPOSE 8545 8546 30303 30303/udp 30304/udp