[ https://issues.apache.org/jira/browse/GUACAMOLE-890?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17025925#comment-17025925 ]
Nick Couchman commented on GUACAMOLE-890: ----------------------------------------- {quote} Unfortunately, this does not work for the guacamole container... We then have one of the 2 components running as root, which is not really a good thing... {quote} Why not? {quote} Would be nice to have this fixed for the 1.1.0 release. {quote} This will not be fixed or changed in the 1.1.0 release - the release is almost completed and is in final RC stages, now. *If* any changes need to be made they will be in a future release. > Guacamole/Guacd Docker Process Privilege Drop > --------------------------------------------- > > Key: GUACAMOLE-890 > URL: https://issues.apache.org/jira/browse/GUACAMOLE-890 > Project: Guacamole > Issue Type: Improvement > Components: guacamole-docker > Reporter: Anthony Boccia > Priority: Minor > Labels: docker, security > > Hello, > I noticed after deploying Guacamole in docker that the processes all run as > the root user. Are there any plans to add support for specifying a user for > the processes to drop privs to and run as instead of root? I am currently > doing this rebuilding the containers for guacamole and guacd adding in my own > user and using docker compose to exec all processes triggered within the > container as that user. I feel like the option to specify this should be done > upstream. > Thank You -- This message was sent by Atlassian Jira (v8.3.4#803005)