mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
eade10ae0e
All published OPA images now run with a non-root uid/gid. The uid:gid is set to 1000:1000 for all images. As a result there is no longer a need for the --rootless image variant hence it will not be published as part of future releases. This change is in line with container security best practices. OPA can still be run with root privileges by explicitly setting the user, either with the --user argument for docker run, or by specifying the securityContext in the Kubernetes Pod specification. Fixes: #4295 Signed-off-by: Ashutosh Narkar <anarkar4387@gmail.com>
29 lines
920 B
Docker
29 lines
920 B
Docker
# Copyright 2019 The OPA Authors. All rights reserved.
|
|
# Use of this source code is governed by an Apache2
|
|
# license that can be found in the LICENSE file.
|
|
|
|
ARG BASE
|
|
|
|
FROM ${BASE}
|
|
|
|
LABEL org.opencontainers.image.authors="Torin Sandall <torinsandall@gmail.com>"
|
|
LABEL org.opencontainers.image.source="https://github.com/open-policy-agent/opa"
|
|
|
|
# Any non-zero number will do, and unfortunately a named user will not, as k8s
|
|
# pod securityContext runAsNonRoot can't resolve the user ID:
|
|
# https://github.com/kubernetes/kubernetes/issues/40958.
|
|
ARG USER=1000:1000
|
|
USER ${USER}
|
|
|
|
# TARGETOS and TARGETARCH are automatic platform args injected by BuildKit
|
|
# https://docs.docker.com/engine/reference/builder/#automatic-platform-args-in-the-global-scope
|
|
ARG TARGETOS
|
|
ARG TARGETARCH
|
|
ARG BIN_DIR=.
|
|
ARG BIN_SUFFIX=
|
|
COPY ${BIN_DIR}/opa_${TARGETOS}_${TARGETARCH}${BIN_SUFFIX} /opa
|
|
ENV PATH=${PATH}:/
|
|
|
|
ENTRYPOINT ["/opa"]
|
|
CMD ["run"]
|