Skip to content

Commit 6d50147

Browse files
authored
Docker non-root access for cloud image (#215)
1 parent f492dc9 commit 6d50147

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

cloud.Dockerfile

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,14 @@ RUN make install-utils install-ui build-cloud
2222
FROM ${BASE_SERVER_IMAGE} AS ui-server
2323
WORKDIR /home/ui-server
2424

25+
RUN addgroup -g 5000 temporal
26+
RUN adduser -u 5000 -G temporal -D temporal
27+
2528
COPY --from=ui-builder /home/ui-builder/ui-server ./
2629
COPY docker/start-ui-server.sh ./start-ui-server.sh
2730
COPY docker/config_template.yaml ./config/config_template.yaml
2831

32+
RUN chown temporal:temporal /home/ui-server -R
33+
2934
EXPOSE 8080
3035
ENTRYPOINT ["./start-ui-server.sh"]

0 commit comments

Comments
 (0)