Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[FR] Support running Docker image as non-root user

Abierto
#6,484 4 comentarios 1 reacción 1 asignado Ver en GitHub

Los mantenedores suelen responder en 1 día

@dermetfan ya está trabajando en esto.

Desde el 10/6/2026.

  • #6599 de @dermetfan — fusionado

Evaluación

Este issue todavía no se ha evaluado.

Descripción

docker Stale

Internal/External
External otherwise. (Midnight)

Area
Other Any other topic (Delegation, Ranking, ...).

Summary
The run-node script unconditionally writes to /usr/local/bin/env, a root-owned path inside the container filesystem, making it impossible to run the container as a non-root user. Additionally, when using the config merge feature, the entrypoint script writes to /opt/cardano/config//, which also fails as non-root.

Steps to reproduce

  1. Run ghcr.io/intersectmbo/cardano-node:10.5.2 with a non-root security context:
    securityContext:
    runAsNonRoot: true
    runAsUser: 1001
    runAsGroup: 1001
  2. Container crashes with:
    /usr/local/bin/run-node: line 91: /usr/local/bin/env: Permission denied
  3. If CARDANO_CONFIG_JSON_MERGE is also set, the entrypoint additionally fails with:
    /usr/local/bin/entrypoint: line 31: /opt/cardano/config/preview/config-merged.json: Permission denied

Expected behavior
The container should support running as a non-root user. Generated files should be written to a user-writable location (e.g. /tmp) instead of root-owned paths:

  • run-node writeRootEnv() (line 91): write to /tmp/env instead of /usr/local/bin/env
  • entrypoint (line 31): write config-merged.json / topology-merged.json to /tmp instead of /opt/cardano/config//

System info (please complete the following information):

  • OS Name: Linux (Kubernetes)
  • OS Version: Kernel 5.10
  • Node version: cardano-node 10.5.2 (ghcr.io/intersectmbo/cardano-node:10.5.2)
  • CLI version: N/A
Lenguaje dominante
Haskell
Estrellas
3.2k
Forks
760
Merge medio
2 d 7 h
PR fusionados (30 d)
21

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de IntersectMBO/cardano-node

Todos los issues de IntersectMBO/cardano-node

Issues similares

Más issues de Haskell

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.