From b2ef1a13e82c0db0900cef59e5734da59d745b26 Mon Sep 17 00:00:00 2001 From: Mehrdad Biukian <80095851+mehrdadbn9@users.noreply.github.com> Date: Thu, 6 Aug 2026 08:11:02 +0400 Subject: [PATCH] image: pin numeric uid/gid for the nonroot user (#8316) Kubernetes rejects a pod at admission when runAsNonRoot is set and the image declares its user by name: "container has runAsNonRoot and image has non-numeric user (nonroot), cannot verify user is non-root". The Dockerfile set `USER nonroot:nonroot`, so the built image's config user was the name rather than a uid, which the kubelet cannot verify. distroless "nonroot" is uid/gid 65532, so pin the numeric id. The image runs as the same user and the binary keeps cap_net_bind_service from the build stage, so it can still bind :53. Verified by building the image: config user is now `65532:65532`. Fixes #7542 Signed-off-by: mehrdadbn9 --- Dockerfile | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 140a30340..76f61ed87 100644 --- a/Dockerfile +++ b/Dockerfile @@ -10,7 +10,13 @@ RUN setcap cap_net_bind_service=+ep /coredns FROM ${BASE} COPY --from=build /coredns /coredns -USER nonroot:nonroot +# Use the numeric uid/gid (distroless "nonroot" is 65532) rather than the named +# user so Kubernetes can verify the image runs as non-root when runAsNonRoot is +# set. A named user is rejected at admission ("container has runAsNonRoot and +# image has non-numeric user, cannot verify user is non-root"). The binary keeps +# cap_net_bind_service (set in the build stage), so it can still bind :53. +# Refs #7542. +USER 65532:65532 # Reset the working directory inherited from the base image back to the expected default: # https://github.com/coredns/coredns/issues/7009#issuecomment-3124851608 WORKDIR /