Skip to content

chore(docker): pin base images by digest and run as non-root - #396

Open
neo-jesse wants to merge 1 commit into
mainfrom
fix/docker-nonroot-digest-pins
Open

neo-jesse wants to merge 1 commit into
mainfrom
fix/docker-nonroot-digest-pins

Conversation

@neo-jesse

@neo-jesse neo-jesse commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Pin python:3.12-bookworm and ghcr.io/astral-sh/uv:0.12.1 by digest so rebuilds do not pick moved tags.
  • Keep the build user non-root: refuse host_uid/host_gid of 0, and set final USER to ${host_uid}:${host_gid}.
  • Own /volumes/* and start.sh as that uid/gid (via chown / COPY --chown) instead of a post-copy sudo chown.

Test plan

  • docker build with local uid/gid succeeds
  • docker image inspect shows User=<uid>:<gid> (not root); docker run --entrypoint id matches
  • CI image build path still matches host runner uid/gid for bind mounts

Lock python and uv image tags to digests, refuse root host uid/gid, and
set USER to the numeric build-arg identity so the final image is clearly
non-root for bind-mounted Yocto builds.

Co-authored-by: Cursor <cursoragent@cursor.com>
@neo-jesse
neo-jesse marked this pull request as ready for review September 30, 2026 00:13
@neo-jesse
neo-jesse requested a review from sfoster1 September 30, 2026 00:13

@sfoster1 sfoster1 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

good with it if builds pass, probably wait until 10.1 goes out though

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants