From b18c62177929fa74a8837884ea39ceb0ce0f8cf0 Mon Sep 17 00:00:00 2001 From: Arnaud Rebts Date: Sat, 14 Nov 2020 13:56:02 +0100 Subject: [PATCH] Don't run as root --- Dockerfile | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/Dockerfile b/Dockerfile index c971a28..779585d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -15,5 +15,9 @@ RUN set -ex; \ COPY --from=build /usr/local/cargo/bin/shiny-robots /usr/local/bin +RUN useradd -ms /bin/bash -u 1001 deps +WORKDIR /home/deps +USER deps + EXPOSE 8080 CMD /usr/local/bin/shiny-robots