mirror of
https://github.com/coredns/coredns.git
synced 2026-08-20 23:08:28 -04:00
image: pin numeric uid/gid for the nonroot user (#8316)
Kubernetes rejects a pod at admission when runAsNonRoot is set and the image declares its user by name: "container has runAsNonRoot and image has non-numeric user (nonroot), cannot verify user is non-root". The Dockerfile set `USER nonroot:nonroot`, so the built image's config user was the name rather than a uid, which the kubelet cannot verify. distroless "nonroot" is uid/gid 65532, so pin the numeric id. The image runs as the same user and the binary keeps cap_net_bind_service from the build stage, so it can still bind :53. Verified by building the image: config user is now `65532:65532`. Fixes #7542 Signed-off-by: mehrdadbn9 <mehrdadbiukian@gmail.com>
This commit is contained in:
@@ -10,7 +10,13 @@ RUN setcap cap_net_bind_service=+ep /coredns
|
|||||||
|
|
||||||
FROM ${BASE}
|
FROM ${BASE}
|
||||||
COPY --from=build /coredns /coredns
|
COPY --from=build /coredns /coredns
|
||||||
USER nonroot:nonroot
|
# Use the numeric uid/gid (distroless "nonroot" is 65532) rather than the named
|
||||||
|
# user so Kubernetes can verify the image runs as non-root when runAsNonRoot is
|
||||||
|
# set. A named user is rejected at admission ("container has runAsNonRoot and
|
||||||
|
# image has non-numeric user, cannot verify user is non-root"). The binary keeps
|
||||||
|
# cap_net_bind_service (set in the build stage), so it can still bind :53.
|
||||||
|
# Refs #7542.
|
||||||
|
USER 65532:65532
|
||||||
# Reset the working directory inherited from the base image back to the expected default:
|
# Reset the working directory inherited from the base image back to the expected default:
|
||||||
# https://github.com/coredns/coredns/issues/7009#issuecomment-3124851608
|
# https://github.com/coredns/coredns/issues/7009#issuecomment-3124851608
|
||||||
WORKDIR /
|
WORKDIR /
|
||||||
|
|||||||
Reference in New Issue
Block a user