[FR] Support running Docker image as non-root user
Los mantenedores suelen responder en 1 día
Evaluación
Este issue todavía no se ha evaluado.
Descripción
Internal/External
External otherwise. (Midnight)
Area
Other Any other topic (Delegation, Ranking, ...).
Summary
The run-node script unconditionally writes to /usr/local/bin/env, a root-owned path inside the container filesystem, making it impossible to run the container as a non-root user. Additionally, when using the config merge feature, the entrypoint script writes to /opt/cardano/config//, which also fails as non-root.
Steps to reproduce
- Run ghcr.io/intersectmbo/cardano-node:10.5.2 with a non-root security context:
securityContext:
runAsNonRoot: true
runAsUser: 1001
runAsGroup: 1001 - Container crashes with:
/usr/local/bin/run-node: line 91: /usr/local/bin/env: Permission denied - If CARDANO_CONFIG_JSON_MERGE is also set, the entrypoint additionally fails with:
/usr/local/bin/entrypoint: line 31: /opt/cardano/config/preview/config-merged.json: Permission denied
Expected behavior
The container should support running as a non-root user. Generated files should be written to a user-writable location (e.g. /tmp) instead of root-owned paths:
- run-node writeRootEnv() (line 91): write to /tmp/env instead of /usr/local/bin/env
- entrypoint (line 31): write config-merged.json / topology-merged.json to /tmp instead of /opt/cardano/config//
System info (please complete the following information):
- OS Name: Linux (Kubernetes)
- OS Version: Kernel 5.10
- Node version: cardano-node 10.5.2 (ghcr.io/intersectmbo/cardano-node:10.5.2)
- CLI version: N/A
- Lenguaje dominante
- Haskell
- Estrellas
- 3.2k
- Forks
- 760
- Merge medio
- 2 d 7 h
- PR fusionados (30 d)
- 21
Preparar el entorno
- Incluye un Dockerfile o un archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de IntersectMBO/cardano-node
-
Stale
Dificultad 1/5 1-3 horas Aptitud para principiantes 75/100
IntersectMBO/cardano-node#6597 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Stale
Dificultad 1/5 1-3 horas Aptitud para principiantes 72/100
IntersectMBO/cardano-node#6578 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
IntersectMBO/cardano-node#6522 · 2 comentarios ·
Los mantenedores suelen responder en 1 día
-
needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 30/100
IntersectMBO/cardano-node#6729 ·
Los mantenedores suelen responder en 1 día
-
increase in memory usageAbierto
Dificultad 4/5 3-5 días Aptitud para principiantes 28/100
IntersectMBO/cardano-node#6718 ·
Los mantenedores suelen responder en 1 día
Todos los issues de IntersectMBO/cardano-node
Issues similares
-
New-pipeline: update TracyAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
AccelerateHS/accelerate#583 · 2 comentarios ·
-
component: hls-refactor-plugin status: needs triage type: bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 60/100
haskell/haskell-language-server#5111 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
alunduil/network-arbitrary#193 ·
Los mantenedores suelen responder en 1 día
-
enhancement
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
alunduil/siren-json.hs#245 ·
Los mantenedores suelen responder en 1 día
-
infrastructure
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
alunduil/collection-json.hs#393 ·
Los mantenedores suelen responder en 1 día