Skip to content

Commit 3494605

Browse files
eatwithforksrpardini
authored andcommitted
run as non privileged user for security
1 parent e3f1eee commit 3494605

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

Dockerfile

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -53,6 +53,12 @@ ADD entrypoint.sh /entrypoint.sh
5353
ADD create_ca_cert.sh /create_ca_cert.sh
5454
RUN chmod +x /create_ca_cert.sh /entrypoint.sh
5555

56+
# Allow running nginx with unprivileged user
57+
RUN chown 1000:1000 /etc/nginx && \
58+
mkdir /certs && chown 1000:1000 /certs
59+
60+
USER 1000:1000
61+
5662
# Clients should only use 3128, not anything else.
5763
EXPOSE 3128
5864

0 commit comments

Comments
 (0)