add nonroot-user
Some checks failed
ci/woodpecker/push/lint Pipeline failed
ci/woodpecker/push/build unknown status

This commit is contained in:
Michael Grote 2024-07-30 10:32:02 +02:00
parent 5b05afe684
commit f0f3d3ec23

View file

@ -2,11 +2,25 @@ FROM python:3.12.4-bookworm
ENV DEBIAN_FRONTEND=noninteractive
WORKDIR /
COPY requirements.txt .
COPY requirements.yaml .
COPY start_tmux.sh .
COPY version.sh .
# Update the package list, install sudo, create a non-root user, and grant password-less sudo permissions
# https://dev.to/izackv/running-a-docker-container-with-a-custom-non-root-user-syncing-host-and-container-permissions-26mb
RUN apt update && \
apt install -y sudo && \
addgroup --gid 2000 nonroot && \
adduser --uid 2000 --gid 2000 --disabled-password --gecos "" ansible-user && \
echo 'ansible-user ALL=(ALL) NOPASSWD: ALL' >> /etc/sudoers \
&& rm -rf /var/lib/apt/lists/* /var/tmp/* /tmp/* \
&& apt-get clean
# Set the non-root user as the default user
USER ansible-user
WORKDIR /home/ansible-user/
COPY --chown=ansible-user:ansible-user requirements.txt .
COPY --chown=ansible-user:ansible-user requirements.yaml .
COPY --chown=ansible-user:ansible-user start_tmux.sh .
COPY --chown=ansible-user:ansible-user version.sh .
# hadolint ignore=DL3013
RUN python3 -m pip install --no-cache-dir --upgrade pip \