Skip to content

security: run container as non-root - #29

Merged
darkoatanasovski merged 1 commit into
masterfrom
security/run-as-non-root
Sep 3, 2026
Merged

darkoatanasovski merged 1 commit into
masterfrom
security/run-as-non-root

Conversation

@peter-matkovski

Copy link
Copy Markdown
Contributor

Summary

  • create a dedicated unprivileged UID/GID in the final Alpine image
  • assign the server binary and static frontend assets to that user
  • run the service as the non-root app user

Security impact

This addresses code scanning alert #44 by removing root privileges from the runtime container.

The service listens on unprivileged port 8081 and the runtime code only reads the server binary and bundled static files; no runtime filesystem writes were found.

Validation

  • reviewed the final image permissions and runtime file access
  • confirmed the server binds to port 8081
  • container build not run locally because no Docker-compatible runtime is available

Create a dedicated UID/GID for the runtime and assign ownership of the server and static assets.
@darkoatanasovski
darkoatanasovski merged commit 59c3ed1 into master Sep 3, 2026
6 checks passed
@darkoatanasovski
darkoatanasovski deleted the security/run-as-non-root branch September 3, 2026 08:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants