Migrate Dockerfile.widgetms to unprivileged user 22/104922/1
authorPawel Wieczorek <p.wieczorek2@samsung.com>
Mon, 30 Mar 2020 09:50:46 +0000 (11:50 +0200)
committerSunder Tattavarada <statta@research.att.com>
Fri, 3 Apr 2020 16:48:02 +0000 (16:48 +0000)
Issue-ID: PORTAL-849
Change-Id: Ia6e96c72a0a7f4a7d7693688365c683227bef6d3
Signed-off-by: Pawel Wieczorek <p.wieczorek2@samsung.com>
(cherry picked from commit edebaff8d9225b23adac727b983e2c3890cd7ee1)

deliveries/Dockerfile.widgetms

index 82a2e4c..8f4b107 100644 (file)
@@ -14,7 +14,9 @@ RUN sh -c 'touch /app.jar'
 # Launch script
 COPY start-wms.sh /
 
+# Switch to unprivileged user
 RUN addgroup -g 1000 -S portal && adduser -u 1000 -S portal -G portal && mkdir logs / && chown -R portal:portal /start-wms.sh /tmp /etc/ssl/certs/java /logs && chmod -R 755 /start-wms.sh /etc/ssl/certs/java /logs /tmp
+USER portal
 
 # Define default command
 CMD /start-wms.sh