Run tomcat as onap user 26/84526/2
authorWojciech Sliwka <wojciech.sliwka@nokia.com>
Mon, 8 Apr 2019 13:12:40 +0000 (15:12 +0200)
committerWojciech Sliwka <wojciech.sliwka@nokia.com>
Tue, 9 Apr 2019 06:28:07 +0000 (06:28 +0000)
Issue-ID: VID-423
Change-Id: I5ec25252e325216e0835c55ae9b8ddb47ce11161
Signed-off-by: Wojciech Sliwka <wojciech.sliwka@nokia.com>
deliveries/src/main/docker/docker-files/Dockerfile

index 3f9c1ad..9b46853 100755 (executable)
@@ -3,6 +3,8 @@ FROM tomcat:8.0-jre8-alpine
 # add vim and uncomment alias to speedup troubleshooting purpose
 RUN apk update && apk add openjdk8 vim net-tools
 
+RUN adduser --disabled-password onap onap
+RUN mkdir -p /opt/app
 COPY conf.d/ /etc/onap/vid/conf.d/
 
 # MariaDB variables
@@ -90,6 +92,7 @@ ADD maven/config/server.xml ${VID_TOMCAT_PATH}
 ADD maven/scripts/*.sh /tmp/vid/
 ADD maven/artifacts/vid.war /tmp/vid/stage/
 
+RUN chown onap:onap /tmp/vid /usr/local/tomcat /etc/onap/vid /opt/app -R
 RUN chmod +x /tmp/vid/localize.sh
-
-CMD ["/tmp/vid/localize.sh"]
\ No newline at end of file
+USER onap
+CMD ["/tmp/vid/localize.sh"]