Lewis John McGibbney created NUTCH-3213:
-------------------------------------------

             Summary: Harden Docker image: non-root USER and Dockerfile lint 
(SonarCloud)
                 Key: NUTCH-3213
                 URL: https://issues.apache.org/jira/browse/NUTCH-3213
             Project: Nutch
          Issue Type: Improvement
          Components: docker
    Affects Versions: 1.23
            Reporter: Lewis John McGibbney
            Assignee: Lewis John McGibbney
             Fix For: 1.24


SonarCloud Docker analysis of docker/Dockerfile reports 8 OPEN issues (visible 
on PR analysis after docker was added to sonar.sources). They are independent 
of NUTCH-3130.

*Security*
 * docker:S6471: alpine defaults to root; no USER instruction. CWE-250. The 
image CMD is /bin/bash and nutch/crawl are on PATH as root. docker/README.md 
already recommends a dedicated low-privilege user.

*Maintainability*
 * docker:S6595: RUN apk update is a separate layer (stale/index bloat).
 * docker:S7031: consecutive RUN instructions (apk, rc files, clone, ln).
 * docker:S6570: unquoted $HOME and $NUTCH_HOME (word-splitting/globbing).

*Proposed fix*
 * Single RUN: apk --no-cache add (no standalone apk update), create nutch 
user/group, clone+ant runtime, symlinks, chown.
 * Quote all shell variable expansions.
 * USER nutch before CMD. Move install prefix off /root (e.g. /opt/nutch) so 
NUTCH_HOME is owned by the runtime user. Document the path change in 
docker/README.md (breaking for anyone mounting /root/nutch_source).
 * Keep ENV JAVA_HOME; drop redundant .bashrc/.ashrc writes or write a quoted 
/etc/profile.d snippet during the same RUN.

See:
https://sonarcloud.io/project/issues?id=apache_nutch&pullRequest=967



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to