Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Security] Run Cloudbeaver as non-root by default (to be less vulnerable) #2290

Open
luarx opened this issue Jan 10, 2024 · 4 comments
Open
Labels
deployment feature request Let's add something new

Comments

@luarx
Copy link

luarx commented Jan 10, 2024

Is your feature request related to a problem? Please describe.
It would be a good point to run Cloudbeaver with a non-root user to follow best security practises
Reference of why this is important: https://docs.bitnami.com/tutorials/why-non-root-containers-are-important-for-security

Describe the solution you'd like
To do that, it should define a USER in the Dockerfile

I see that someone mentioned already this and suggested a solution, but it was not added to the repo as default

@luarx luarx added feature request Let's add something new wait for review labels Jan 10, 2024
@EvgeniaBzzz
Copy link
Contributor

Hi @luarx!
Thank you for your request!
You are right, for now we do not have default option for that.
How to start a server with a non-root user - look here.

@luarx
Copy link
Author

luarx commented Jan 12, 2024

Thanks for your suggestion! Happy to know that it is possible to run as non-root and that it is documented 🙌

On the other hand, I think that it should be the default option because of the security reasons that I shared unless there are some reasons to not do that...

@luarx
Copy link
Author

luarx commented Jan 24, 2024

Wdyt @EvgeniaBzzz ? 😄

@EvgeniaBzzz
Copy link
Contributor

@luarx we will implement it in one of the future releases

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
deployment feature request Let's add something new
Projects
None yet
Development

No branches or pull requests

2 participants