OpenHands / OpenHands/software-agent-sdk

Dockerfile best practice: specify non-root USER in custom tool example Dockerfile

Open Beginner friendly
#5,048 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

docker enhancement security
Dominant language
Python
Stars
1.1k
Forks
539
Avg merge
1d 19h
Merged PRs (30d)
137

Description

Context

The Dockerfile at examples/02_remote_agent_server/06_custom_tool/Dockerfile does not currently specify a USER directive, so the container runs as root by default.

Best practice

It is a Docker best practice to run containers as a non-root user. Adding a USER directive with a non-root user avoids unnecessary privilege and follows community conventions for well-formed Dockerfiles.

Suggested change

Add a non-root user to the Dockerfile, e.g.:

RUN useradd -m appuser
USER appuser

Or use an existing non-root user if one is already created in the base image.

Acceptance criteria

  • Dockerfile includes a USER directive with a non-root user
  • Container still builds and runs correctly

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with examples/02_remote_agent_server/06_custom_tool/Dockerfile and inspect the base image for any existing non-root user. Add a non-root USER directive, then build and run the container to confirm it works and the acceptance criteria are met.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker
Domain
devops, security
Issue type
Refactor
Difficulty
1/5
Estimated time
Under an hour
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
90/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.