mirror of
https://github.com/R0m1k3/podcastic.git
synced 2026-10-11 17:26:20 +02:00
security: run Docker container as non-root node user
Defense in depth — drop root in the production image. The official node:alpine image ships a "node" user (uid 1000); chown /app and switch with USER node so a compromise can't write outside the app directory. Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
f620ec614c
commit
f8f4f96169
1 file changed
+4
@@ -40,6 +40,10 @@ COPY --from=backend-builder /app/dist ./dist
|
||||
# Copy frontend build into public/ (backend will serve it as static files)
|
||||
COPY --from=frontend-builder /frontend/dist ./public
|
||||
|
||||
# Run as non-root for defense in depth — node:alpine ships a "node" user (uid 1000)
|
||||
RUN chown -R node:node /app
|
||||
USER node
|
||||
|
||||
EXPOSE 3579
|
||||
|
||||
ENV NODE_ENV=production
|
||||
|
||||
Reference in new issue
Block a user