GoogleContainerTools / GoogleContainerTools/jib
extraDirectories should use container user:group or have a parameter to set the user:group instead of using root
- Dominant language
- Java
- Stars
- 14.5k
- Forks
- 1.5k
- PR merge metrics
- No merged PRs in 30d
Description
**Environment**:
- *Jib version:*
- *Build tool:* gradle 7.5.1
- *OS:* ubuntu
**Description of the issue**:
_I'm writing this as a bug, because I couldn't find it on documentation or internet search or in the issue list, if there is already something feel free to send me the related documentation or example._
If a user is set on `container` section, it should be use by extraDirectories or extraDirectories should be able to accept a user:group as parameter, today extraDirectories is forcing ownership to 'root'.
I have an application that is run with a dedicated user:group (not root) and I am adding files with extraDirectories.
Using "myuser:mygroup" as example.
With a configuration such as (I have anonymized enterprise data):
```
jib {
from {
image = //an custom docker image
}
container {
user = "myuser:mygroup"
ports = ["8080"]
}
extraDirectories {
paths {
path {
from = file("build")
into = "/opt/myuser/app"
}
}
}
pluginExtensions {
pluginExtension {
implementation = "com.google.cloud.tools.jib.gradle.extension.ownership.JibOwnershipExtension"
configuration {
rules {
rule {
glob = "/opt/myuser/**"
ownership = "myuser:mygroup"
}
}
}
}
}
}
```
**Expected behavior**:
Being able to have files created on runtime as "myuser" inside `/opt/myuser/app`.
But I have permissions errors **because user on the 'app' folder is 'root' instead of the expected 'myuser'**, such as:
```
[myuser@6213a8c424b3 app]$ pwd
/opt/myuser/app
[myuser@6213a8c424b3 app]$ touch myfile.txt
touch: cannot touch 'myfile.txt': Permission denied
[myuser@6213a8c424b3 app]$ ls -lart
-rw-r--r-- 1 myuser myuser 93 Jan 1 1970 version.txt
drwxr-xr-x 3 myuser myuser 4096 Jan 1 1970 bin
drwxr-xr-x 1 root root 4096 Jan 1 1970 ..
drwxr-xr-x 1 root root 4096 Jan 1 1970 .
```
Additional information is that `/opt/myuser/app` already exists in the base docker image, if I remove the `extraDirectories` block then the user is myuser on `/opt/myuser/app` (so it's forced changed ownership to root by JibOwnershipExtension).
**Steps to reproduce**:
1. Build a docker image with gradle jib, having a user:group different from root
2. Copy some file in a folder '/opt/app' with JibOwnershipExtension
3. Run docker image as user different from root, try to "touch myfile.txt" inside '/opt/app'
**Additional Information**:
As I read limitations on https://github.com/GoogleContainerTools/jib-extensions/blob/6b81680d0882cfd5c3bd38c8a1c7034d53854107/first-party/jib-ownership-extension-gradle/README.md?plain=1#L60-L64
The workaround is to have the app folder inside the build folder of gradle, and have this =>
```
extraDirectories {
paths {
path {
from = file("build/") //this one has build/app/bin
into = "/opt/myuser"
}
}
}
```
But if a user is set on `container` section, it should be use by extraDirectories or extraDirectories should be able to accept a user:group as parameter, I don't see any security reason to force having 'root' user, since it's more a good practice to NOT run applications as root in docker.
Contributor guide
Assessment
This issue has not been assessed yet.