From a6cb200a81887315763b08d2e5f129f5b3951244 Mon Sep 17 00:00:00 2001 From: Pierluigi Lenoci Date: Tue, 14 Apr 2020 12:44:50 +0200 Subject: [PATCH 1/2] Added uid 1000 for kube-slack to be able to run this container in k8s with Pod Security Policy activated. --- .gitignore | 1 + Dockerfile | 4 ++-- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/.gitignore b/.gitignore index c177b4f..e19b34a 100644 --- a/.gitignore +++ b/.gitignore @@ -4,3 +4,4 @@ yarn.lock config/local*.yaml .vscode build/ +.idea diff --git a/Dockerfile b/Dockerfile index 9245a0f..8904891 100644 --- a/Dockerfile +++ b/Dockerfile @@ -10,7 +10,7 @@ RUN npm run build FROM node:10-alpine # Don't run as root user ENV user kube-slack -RUN addgroup -S $user && adduser -S -g $user $user +RUN addgroup -S $user && adduser -S -g $user $user --uid 1000 WORKDIR /app COPY package.json /app @@ -20,6 +20,6 @@ COPY --from=build /app/build/ /app COPY config/ /app/config/ RUN chown -R $user:$user /app -USER $user +USER 1000 CMD ["node", "."] From 2f8690662296d6ad5209f5983d11d759b16443e0 Mon Sep 17 00:00:00 2001 From: Pierluigi Lenoci Date: Tue, 14 Apr 2020 13:31:34 +0200 Subject: [PATCH 2/2] fix uid --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index 8904891..1fdef82 100644 --- a/Dockerfile +++ b/Dockerfile @@ -10,7 +10,7 @@ RUN npm run build FROM node:10-alpine # Don't run as root user ENV user kube-slack -RUN addgroup -S $user && adduser -S -g $user $user --uid 1000 +RUN addgroup -S $user && adduser -S -g $user $user --uid 2000 WORKDIR /app COPY package.json /app @@ -20,6 +20,6 @@ COPY --from=build /app/build/ /app COPY config/ /app/config/ RUN chown -R $user:$user /app -USER 1000 +USER 2000 CMD ["node", "."]