douwen5833 2017-02-14 21:56
浏览 35
已采纳

从头开始非特权执行

I'm building/deploying go/golang micro-services on images FROM scratch.

Is it possible to specify non-privileged execution on an image built this way -- there are only two files on the image–the go executable and a root certificate file–so there doesn't seem to be any concept of privilege within the container.

I also use read-only containers and --selinux-enabled=true --icc=false --iptables=true, but would feel more warm and fuzzy if I knew that the executable was running as a "common" non-privileged user.

  • 写回答

1条回答 默认 最新

  • duanpu1963 2017-02-14 22:08
    关注

    You don't seem to have any choice in the user (root) running the CMD inside a container launched from an image built "FROM scratch".

    But by definition of a container, that user can only influence its own (disk, memory, resources) space, not the host. So it should not matter.

    The only other alternative would be to define a container from scratch only for declaring a volume container, that you would use in a full-fledged image able to run with a non-root user.
    See "Running as a non-root inside a container"

    $ echo 'FROM scratch
    ADD data.tar /
    VOLUME ["/data"]' > Dockerfile
    
    $ docker build -t minimal .
    $ docker create --name minimal minimal :
    

    The container that mounts this minimal volume container needs to create the user with id 1000:

    $ docker run --rm --volumes-from minimal  -it debian:jessie /bin/bash -c 'useradd postgres && ls -l /data'
    

    That is not what you need (since the Go program does not need any dynamic libraries, and can run solely on system calls). But that illustrates how a non-root user can use a "FROM scratch" container (here as a volume)

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 关于#matlab#的问题:在模糊控制器中选出线路信息,在simulink中根据线路信息生成速度时间目标曲线(初速度为20m/s,15秒后减为0的速度时间图像)我想问线路信息是什么
  • ¥15 banner广告展示设置多少时间不怎么会消耗用户价值
  • ¥16 mybatis的代理对象无法通过@Autowired装填
  • ¥15 可见光定位matlab仿真
  • ¥15 arduino 四自由度机械臂
  • ¥15 wordpress 产品图片 GIF 没法显示
  • ¥15 求三国群英传pl国战时间的修改方法
  • ¥15 matlab代码代写,需写出详细代码,代价私
  • ¥15 ROS系统搭建请教(跨境电商用途)
  • ¥15 AIC3204的示例代码有吗,想用AIC3204测量血氧,找不到相关的代码。