security: run Docker container as non-root node user

Defense in depth — drop root in the production image. The official
node:alpine image ships a "node" user (uid 1000); chown /app and
switch with USER node so a compromise can't write outside the app
directory.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
MichaelandClaude Haiku 4.5 committed 2026-04-18 07:25:42 +02:00
1 parent f620ec614c
commit f8f4f96169
1 file changed
+4
+4
View File
@@ -40,6 +40,10 @@ COPY --from=backend-builder /app/dist ./dist
# Copy frontend build into public/ (backend will serve it as static files)
COPY --from=frontend-builder /frontend/dist ./public
# Run as non-root for defense in depth — node:alpine ships a "node" user (uid 1000)
RUN chown -R node:node /app
USER node
EXPOSE 3579
ENV NODE_ENV=production