Change to no-root user in docker image by default #18516

Closed
opened 2026-02-21 19:48:40 -05:00 by yindo · 0 comments
Owner

Originally created by @41tair on GitHub (Sep 29, 2025).

Originally assigned to: @41tair on GitHub.

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • Please do not modify this template :) and fill in all the required fields.

1. Is this request related to a challenge you're experiencing? Tell me about your story.

The current Docker image defaults to running as the root user. This poses a security risk and contradicts the principle of least privilege.

In many production and CI/CD environments, running containers as root is prohibited by security policies. For instance, Kubernetes clusters often enforce Pod Security Standards (like baseline or restricted profiles) that prevent containers from running as UID 0.

When we attempt to deploy this image in such an environment, the deployment is blocked by our security admission controllers. The current workaround is to manually override the security context for every deployment, which is cumbersome and not a scalable solution.

2. Additional context or comments

No response

3. Can you help us with this feature?

  • I am interested in contributing to this feature.
Originally created by @41tair on GitHub (Sep 29, 2025). Originally assigned to: @41tair on GitHub. ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] Please do not modify this template :) and fill in all the required fields. ### 1. Is this request related to a challenge you're experiencing? Tell me about your story. The current Docker image defaults to running as the root user. This poses a security risk and contradicts the principle of least privilege. In many production and CI/CD environments, running containers as root is prohibited by security policies. For instance, Kubernetes clusters often enforce Pod Security Standards (like baseline or restricted profiles) that prevent containers from running as UID 0. When we attempt to deploy this image in such an environment, the deployment is blocked by our security admission controllers. The current workaround is to manually override the security context for every deployment, which is cumbersome and not a scalable solution. ### 2. Additional context or comments _No response_ ### 3. Can you help us with this feature? - [x] I am interested in contributing to this feature.
yindo added the 💪 enhancement label 2026-02-21 19:48:40 -05:00
yindo closed this issue 2026-02-21 19:48:40 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#18516