Skip to content

Run as user

Emanuele Aina requested to merge wip/em/run-as-user into master

The current containers are run with some unfortunate defaults:

  • the posgres one switches to user 999:999
  • the apertis-qa-report runs as root:root (the real one, as userns are not used by Docker)

This raises important security concerns and is cumbersome to manage.

To avoid that, explicitly set the numeric uid:gid when instantiating both containers, so they get run by non-root and file permissions are consistent both inside and outside of the container.

Edited by Emanuele Aina

Merge request reports