Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Feature] Run the PD, Store and Server images as a non-root user

Open
#3,211 1 comment 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
docker, helm, java, kubernetes

Research direction

Locate the Dockerfiles and entrypoints for the PD, Store and Server images, then inspect how their data, log and temporary directories are created and used. Build each image and verify the Java process runs as the fixed user without permission errors; document the PVC upgrade note and ensure the Helm chart's security contexts can adopt the new defaults.

Written by the indexing model from the issue text.

Description

Feature Description (功能描述)

The published hugegraph/pd, hugegraph/store and hugegraph/server images all run their Java process as root: none of the three declares a USER, checked against the current latest image configs on Docker Hub (registry config blob, .config.User empty on all three, 2026-09-17).

Why it matters on Kubernetes:

  1. A namespace under the restricted Pod Security Standard rejects these pods outright (runAsNonRoot != true).
  2. The Helm chart in #3132 cannot set runAsNonRoot: true or readOnlyRootFilesystem: true as defaults; it documents this in its Limitations and ships the remaining hardening it can (allowPrivilegeEscalation: false, capabilities.drop: [ALL], seccompProfile: RuntimeDefault).
  3. Security scanners (kube-score, polaris, kubescape) flag every workload for it, which any adopter evaluating the chart sees on day one; the 2026-09-10 chart test campaign recorded it as a failing kubescape NSA control on both branches.

Proposal:

  • Create a fixed-UID user in each Dockerfile (the toolchain's Hubble image can follow the same pattern later) and chown the data and log directories to it.
  • Declare USER in the image and keep the entrypoints from writing outside the data, log and temp directories, so readOnlyRootFilesystem becomes possible as a follow-up.
  • Ship it in a minor release with an upgrade note: existing PVC data written as root needs a one-time chown, or an initContainer / fsGroup note in the chart.

The chart side is ready to adopt this the release it lands: podSecurityContext and securityContext are fully configurable per component today, so only the defaults would change.

Dominant language
Java
Stars
3.2k
Forks
640
Avg merge
4d 10h
Merged PRs (30d)
19

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from apache/hugegraph

All issues in apache/hugegraph

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.