nodejs / nodejs/docker-node

Add --no-log-init to the node user that gets created to avoid massive image sizes

Aperta Adatta ai principianti
#1,779 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Lingua principale
Dockerfile
Stelle
8.6k
Fork
2k
Merge medio
10h 19m
PR unite (30g)
16

Descrizione

Problem

Currently the node user is created with useradd --uid 1000 --gid node --shell /bin/bash --create-home node.

When customizing the UID / GID using build args with groupmod -g "${GID}" node && usermod -u "${UID}" -g "${GID}" node, some folks are reporting they are running out of disk space and can't build the image when they have a non-1000 UID on systems that create a lot of users.

Here's a comment going into more detail: https://github.com/nickjj/docker-flask-example/pull/7#issuecomment-1266698181

Also not using --no-log-init will cause Hadolint to throw this warning: -:44 DL3046 warning: useradd without flag -l and high UID will result in excessively large Image.

The usermod command doesn't support being able to set that option so it means our only option is to delete the node user and create a new one in which case life could be simplified by setting that flag here. You could make a case this is a bug report and not feature request due to the implications of not setting this flag when you create users in a Docker image.

Solution

Add --no-log-init to all of the useradd commands that create the node user.

Guida per i contributori

Apri la guida per i contributori

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Direzione di ricerca

Cerca nelle definizioni di build delle immagini Docker ogni comando useradd che crea l’utente node, iniziando dal comando mostrato nell’issue. Aggiungi l’opzione richiesta a ogni comando applicabile, quindi esegui la build delle immagini interessate e verifica che l’avviso di Hadolint segnalato sia stato risolto.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
docker, dockerfile
Ambito
build-system, devops
Tipo di issue
Bug
Difficoltà
2/5
Tempo stimato
1-3 ore
Stato di attività
Tranquilla
Chiarezza
Specificata chiaramente
Idoneità per principianti
68/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.