From 3b4117c7a322e4cb61b3c14336bee5b4bc93535c Mon Sep 17 00:00:00 2001 From: Marc Wickenden Date: Wed, 17 Jan 2024 08:31:26 +0000 Subject: [PATCH] run as kubeshot user --- build/Dockerfile | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/build/Dockerfile b/build/Dockerfile index 4c4126c..a96ae6f 100644 --- a/build/Dockerfile +++ b/build/Dockerfile @@ -33,8 +33,14 @@ RUN \ # headful mode support, for example: $ xvfb-run chromium-browser --remote-debugging-port=9222 xvfb \ # cleanup - && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* + && apt-get clean && rm -rf /var/lib/apt/lists/* /tmp/* /var/tmp/* + +RUN useradd -u 1001 -m -s /bin/bash kubeshot COPY --from=build /go/bin/kubeshot /usr/local/bin/kubeshot WORKDIR /data + +RUN chown kubeshot:kubeshot /data + +USER kubeshot