docker: run minedmap as unpriviledged user

This commit is contained in:
Matthias Schiffer 2025-02-22 04:02:10 +01:00
parent 7bc15f97de
commit 282f62fc30
Signed by: neocturne
GPG key ID: 16EF3F64CB201D9C

View file

@ -9,7 +9,12 @@ RUN strip target/release/minedmap
FROM docker.io/library/alpine:latest
RUN addgroup -g 1000 -S minedmap \
&& adduser -S -D -H -u 1000 -h /output -s /sbin/nologin -G minedmap -g minedmap minedmap
RUN apk add --no-cache libgcc tini
COPY --from=builder /build/target/release/minedmap /bin/minedmap
ENTRYPOINT [ "/sbin/tini", "--", "/bin/minedmap" ]
USER minedmap:minedmap