Skip to content

Commit fd8a98e

Browse files
authored
change Docker image to run as nonroot for k8s clusters restricting to runAsNonRoot (#1029)
Refs: elastic/elastic-otel-node#1398
1 parent 9a61ce4 commit fd8a98e

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

docker/Dockerfile

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,8 @@
11
FROM docker.elastic.co/wolfi/chainguard-base:latest@sha256:b2134dbfbcfb987eec9c249fc81111963de596ff76098775c2444a2869401d9c
22
ARG JAR_FILE
33
ARG EXTENSION_JAR_FILE
4-
COPY ${JAR_FILE} /javaagent.jar
5-
COPY ${EXTENSION_JAR_FILE} /extensions/elastic-otel-agentextension.jar
4+
COPY --chown=65532:65532 ${JAR_FILE} /javaagent.jar
5+
COPY --chown=65532:65532 ${EXTENSION_JAR_FILE} /extensions/elastic-otel-agentextension.jar
6+
# Use wolfi's "nonroot" user/group to satisfy k8s runAsNonRoot security policies.
7+
USER 65532:65532
68
RUN chmod go+r /javaagent.jar /extensions

0 commit comments

Comments
 (0)