feat: run the app image as a non-root user (E00-S02-T05)

The runtime stage of apps/server/Dockerfile now drops root privileges with
'USER node' — the non-root user (uid/gid 1000) the official Node image ships
with — so the app container does not run with root privileges. The server
binds port 3000 (>= 1024) and only reads the root-owned files copied above,
so no extra user creation or ownership changes are required. compose.yaml
header updated: T05 is in scope; T06 (read-only rootfs) and T07 (multi-arch)
remain out of scope.
This commit is contained in:
implementer
2026-08-29 00:41:10 +00:00
parent a634168d9c
commit a4cf365098
2 changed files with 20 additions and 5 deletions
+8 -3
View File
@@ -1,4 +1,4 @@
# EPPP Docker Compose baseline — [E00-S02-T01/T02/T03/T04]
# EPPP Docker Compose baseline — [E00-S02-T01..T05]
#
# `docker compose up -d` starts both the database (PostgreSQL) and the
# application (@personal-blog/server). Rollback: `docker compose down`.
@@ -18,8 +18,13 @@
# `docker compose down` + `docker compose up -d` (recreate, which discards the
# container filesystem). Reset the data with `docker compose down -v`.
#
# Explicitly out of scope for T01..T04 (land in later E00-S02 tasks):
# - non-root execution (T05), read-only root filesystem (T06)
# Non-root execution (T05): the app image's runtime stage runs as the official
# Node image's non-root `node` user (see apps/server/Dockerfile — `USER node`),
# so the app container does not run with root privileges. No Compose-level
# `user:` override is needed: the image's USER is inherited by the container.
#
# Explicitly out of scope for T01..T05 (land in later E00-S02 tasks):
# - read-only root filesystem (T06), multi-arch build targets (T07)
#
# All values have defaults so `docker compose up -d` works from a clean clone
# without a .env file (a committed .env.example template lands in E00-S04).