如何以用户“nobody”的身份在暂存容器中运行我的 Go 应用程序?

som*_*ude 9 go docker linux-containers

我不想以 root 身份在 docker 容器中运行任何内容。我想要简约的图像。

我可以毫无问题地在暂存映像中运行我编译的 Go 应用程序。但是当我不希望它以 root 身份运行(我假设它以 root 身份运行)并在 dockerfile 中定义 USER nobody 时,我得到

014/10/25 06:07:10 Error response from daemon: Cannot start container 
4822f34e54e20bb580f8cd1d38d7be3c828f28595c2bebad6d827a17b4c2fe21: 
finalize namespace setup user get supplementary groups Unable to find user nobody
Run Code Online (Sandbox Code Playgroud)

这是我的 dockerfile

FROM scratch
ADD lichtpunkt_go_linux_amd64 /lichtpunkt_go_linux_amd64
ADD web /web
USER nobody
CMD ["./lichtpunkt_go_linux_amd64"]
EXPOSE 3001
Run Code Online (Sandbox Code Playgroud)

编辑 - - - - - -

事实证明,划痕是空的,非常空。

RUN useradd 会执行 /bin/sh -c useradd 但没有 /bin/sh 。RUN ["useradd"] 将直接执行。但没有 useradd。id 必须添加 rootfs.tar 并从零开始构建内容。

我将使用 debian,因为我不会在容器中以 root 身份运行任何东西,因为......

将容器内的根视为容器外的根

Ida*_*dan 12

解决方案是使用多阶段构建和复制/etc/passwd,正如Liz Rice 的这篇精彩博客文章中所解释的那样。


Кон*_*Ван 5

创建一个包含以下内容的文件,并将COPY其scratch作为/etc/passwd.

\n
nobody:*:65534:65534:nobody:/_nonexistent:/bin/false\n
Run Code Online (Sandbox Code Playgroud)\n

你COPY /bin/false也可以;或者您不\xe2\x80\x99t,在这种情况下,尝试登录 asnobody只会失败。

\n
su: failed to execute /bin/false: No such file or directory\n
Run Code Online (Sandbox Code Playgroud)\n


som*_*ude -1

事实证明,划痕是空的,非常空。

RUN useradd 会执行 /bin/sh -c useradd 但没有 /bin/sh 。RUN ["useradd"] 将直接执行。但没有 useradd。id 必须添加 rootfs.tar 并从零开始构建内容。

我将使用 debian,因为我不会在容器中以 root 身份运行任何东西,因为......

将容器内的根视为容器外的根

http://opensource.com/business/14/7/docker-security-selinux

  • **接受问题的答案,而不是你最终做了什么。** (3认同)