From 57c98dc0be7e949012b8537ef5481747502d0497 Mon Sep 17 00:00:00 2001 From: "scott.eppler" <scott.eppler@coda.global> Date: Tue, 8 Oct 2019 14:17:17 -0500 Subject: [PATCH] Update MarkdownRender sample-function to run as non-root user Signed-off-by: scott.eppler <scott.eppler@coda.global> --- sample-functions/MarkdownRender/Dockerfile | 3 +++ 1 file changed, 3 insertions(+) diff --git a/sample-functions/MarkdownRender/Dockerfile b/sample-functions/MarkdownRender/Dockerfile index 02524af1..9d417dc2 100644 --- a/sample-functions/MarkdownRender/Dockerfile +++ b/sample-functions/MarkdownRender/Dockerfile @@ -21,4 +21,7 @@ RUN chmod +x /usr/bin/fwatchdog COPY --from=builder /go/bin/MarkdownRender /usr/bin/MarkdownRender ENV fprocess "/usr/bin/MarkdownRender" +RUN addgroup -g 1000 -S app && adduser -u 1000 -S app -G app +USER 1000 + CMD ["/usr/bin/fwatchdog"] -- GitLab