Update internal repo to support non-root user scenario
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
调研方向
首先将内部 Dockerfile 和 release pipeline YAML 与公开 PR #3520 中的更改进行比较。完成的标准是:同时构建、签名并纳入 SBOM/manifest 和 registry pushes 的 root 与 non-root 标签,scan gate 针对 non-root 镜像,并且 release notes 或 image README 说明两种变体及其注意事项。
由索引模型根据 Issue 内容生成。
描述
Related to: https://github.com/Azure/data-api-builder/issues/3514
Background
Public PR Azure/data-api-builder#3520 restructured the sample Dockerfile into a multi-target build with two runtime variants:
runtime(default / last stage) — runs as root, backwards-compatible with today's published image.runtime-nonroot(opt-in via--target runtime-nonroot) — runs asUSER $APP_UID(UID 1654), satisfies scanners (e.g. Checkmarx One) that require a non-rootConfig.User.
The public Dockerfile is only a customer sample. The image we actually publish is built from the internal repo, which has its own Dockerfile + release pipeline YAML — both need updating to publish the second tag.
Tasks
- Update the internal
Dockerfileto match #3520 (multi-stageruntime-base→runtime/runtime-nonroot,USER $APP_UID, non-recursivechown $APP_UID:$APP_UID /App/logs). - Update the pipeline to build + push both images: root (
:<version>,:latest) and non-root (--target runtime-nonroot→:<version>-nonroot,:latest-nonroot). - Run signing, SBOM/manifest, and registry push for both tags.
- Point the container scan gate at the
-nonrootimage. - Update release notes / image README with the two variants and non-root consumer caveats.
- 主要语言
- C#
- 星标
- 1.5k
- 派生
- 371
- 平均合并
- 9 天 2 小时
- 30 天内合并 PR
- 10
环境准备
在浏览器里用你自己的 GitHub 账号启动这个项目的开发容器。
- 提供 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
Azure/data-api-builder 的其他 Issue
-
pgsql
难度 2/5 1-3 小时 新手友好度 68/100
Azure/data-api-builder#3598 ·
维护者通常 1 天内回复
-
2.x cli mcp-server
难度 2/5 1-3 小时 新手友好度 68/100
Azure/data-api-builder#3576 ·
维护者通常 1 天内回复
-
2.x health-endpoint
难度 2/5 1-3 小时 新手友好度 68/100
Azure/data-api-builder#3570 ·
维护者通常 1 天内回复
-
2.x telemetry
难度 2/5 1-3 小时 新手友好度 68/100
Azure/data-api-builder#3564 ·
维护者通常 1 天内回复
-
2.x telemetry
难度 2/5 1-3 小时 新手友好度 70/100
Azure/data-api-builder#3562 ·
维护者通常 1 天内回复
查看 Azure/data-api-builder 的全部 Issue
相似的 Issue
-
bug
难度 2/5 1-3 小时 新手友好度 75/100
AvaloniaUI/Avalonia#22323 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
microsoft/onnxruntime-genai#2633 ·
维护者通常 1 天内回复
-
Not reproducible
难度 2/5 1-3 小时 新手友好度 82/100
microsoft/fluentui-blazor#5350 · 4 条评论 ·
维护者通常 1 天内回复
-
python triage
难度 2/5 1-3 小时 新手友好度 85/100
microsoft/semantic-kernel#14491 ·
维护者通常 2 天内回复
-
area:jobads-cv FE mvp P3
难度 2/5 1-3 小时 新手友好度 88/100
klasolsson81/jobbliggaren#1878 ·
维护者通常 1 天内回复