Run tomcat as onap user
[vid.git] / deliveries / src / main / docker / docker-files / Dockerfile
index 81ebd17..9b46853 100755 (executable)
@@ -3,6 +3,8 @@ FROM tomcat:8.0-jre8-alpine
 # add vim and uncomment alias to speedup troubleshooting purpose
 RUN apk update && apk add openjdk8 vim net-tools
 
+RUN adduser --disabled-password onap onap
+RUN mkdir -p /opt/app
 COPY conf.d/ /etc/onap/vid/conf.d/
 
 # MariaDB variables
@@ -26,7 +28,7 @@ ENV CACHE_DIRECTORY="$ROOT_DIR/cache"
 # Keystore variables
 ENV VID_KEYSTORE_FILENAME="${ROOT_DIR}/etc/org.onap.vid.jks" \
   VID_TRUSTSTORE_FILENAME="${ROOT_DIR}/etc/org.onap.vid.trust.jks" \
-  VID_KEYSTORE_PASSWORD="ry1RLC(?M6?2fQ]1a2)2y{P:" \
+  VID_KEYSTORE_PASSWORD="ry1RLC\(\?M6\?2fQ\]1a2\)2y\{P:" \
   VID_TRUSTSTORE_PASSWORD="OBF:1dx01j0e1hs01t981mis1dws156s1ojc1qjc1zsx1pw31qob1qr71pyj1zst1qhy1ojq156i1dua1mm21tb61hvi1j0g1du2" \
   VID_TOMCAT_PATH="/usr/local/tomcat/conf/"
 
@@ -90,6 +92,7 @@ ADD maven/config/server.xml ${VID_TOMCAT_PATH}
 ADD maven/scripts/*.sh /tmp/vid/
 ADD maven/artifacts/vid.war /tmp/vid/stage/
 
+RUN chown onap:onap /tmp/vid /usr/local/tomcat /etc/onap/vid /opt/app -R
 RUN chmod +x /tmp/vid/localize.sh
-
-CMD ["/tmp/vid/localize.sh"]
\ No newline at end of file
+USER onap
+CMD ["/tmp/vid/localize.sh"]