EXPOSE 8080
-USER root
+USER root
+RUN addgroup -g 1000 sdc && adduser -S -u 1000 -G sdc -s /bin/sh sdc
ARG ARTIFACT
-ADD ${ARTIFACT} /app.jar
+ADD --chown=sdc:sdc ${ARTIFACT} /app.jar
-COPY org.onap.sdc.p12 /keystore
-COPY org.onap.sdc.trust.jks /truststore
+COPY --chown=sdc:sdc org.onap.sdc.p12 /keystore
+COPY --chown=sdc:sdc org.onap.sdc.trust.jks /truststore
-COPY startup.sh .
+COPY --chown=sdc:sdc startup.sh .
RUN chmod 744 startup.sh
+
+RUN mkdir /var/log/ONAP/
+RUN chown sdc:sdc /var/log/ONAP/
-ENTRYPOINT [ "./startup.sh" ]
\ No newline at end of file
+USER sdc
+ENTRYPOINT [ "./startup.sh" ]