Lewis John McGibbney created NUTCH-3213:
-------------------------------------------
Summary: Harden Docker image: non-root USER and Dockerfile lint
(SonarCloud)
Key: NUTCH-3213
URL: https://issues.apache.org/jira/browse/NUTCH-3213
Project: Nutch
Issue Type: Improvement
Components: docker
Affects Versions: 1.23
Reporter: Lewis John McGibbney
Assignee: Lewis John McGibbney
Fix For: 1.24
SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues (visible
on PR analysis after docker was added to sonar.sources). They are independent
of NUTCH-3130.
*Security*
* docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The
image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md
already recommends a dedicated low-privilege user.
*Maintainability*
* docker:S6595: RUN apk update is a separate layer (stale/index bloat).
* docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
* docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).
*Proposed fix*
* Single RUN: apk --no-cache add (no standalone apk update), create nutch
user/group, clone+ant runtime, symlinks, chown.
* Quote all shell variable expansions.
* USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so
NUTCH_HOME is owned by the runtime user. Document the path change in
docker/README.md (breaking for anyone mounting /root/nutch_source).
* Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted
/etc/profile.d snippet during the same RUN.
See:
https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967
--
This message was sent by Atlassian Jira
(v8.20.10#820010)