Skip to content

Bits of .NET

Daily micro-tips for C#, SQL, performance, and scalable backend engineering.

  • Asp.Net Core
  • C#
  • SQL
  • JavaScript
  • CSS
  • About
  • ErcanOPAK.com
  • No Access
  • Privacy Policy
Docker

Docker: Run Containers as Non-Root User for Better Security

- 05.06.26 - ErcanOPAK
🔒 Root in Container = Root on Host (Almost)

Docker defaults to root user. Container escape = full host compromise. Run as non-root for defense in depth.

📝 Dockerfile Best Practice
FROM node:18-alpine

# Create non-root user
RUN addgroup -g 1001 -S nodejs && \
    adduser -S nodejs -u 1001

# Set ownership of app directory
WORKDIR /app
COPY --chown=nodejs:nodejs . .

# Switch to non-root user
USER nodejs

# Run as non-root
CMD ["node", "app.js"]

# Verify inside container
# docker run myapp whoami
# Output: nodejs (not root!)

🎯 Run-time User Override
# Override user at run time
docker run --user 1001:1001 myapp

# Run as non-root with specific group
docker run --user nodejs:nodejs myapp

# In docker-compose
services:
  app:
    image: myapp
    user: "1001:1001"

# Read-only root filesystem
docker run --read-only myapp

# Drop all capabilities
docker run --cap-drop=ALL --cap-add=NET_ADMIN myapp

✅ Security Checklist
  • Use specific user ID (not generic ‘node’)
  • Never run as root (except base images that need root for installs)
  • Switch user at the END (so installs run as root, app runs as user)
  • Use –cap-drop=ALL, add only needed capabilities
  • Set read-only root filesystem when possible

“Security audit found all our containers running as root. Added USER nodejs to Dockerfiles. Now container compromise ≠ host compromise. Simple change, big security win.”

— Security Engineer

Related posts:

Docker: Volumes vs Bind Mounts for Persistent Data Storage

Docker Multi-Stage Builds: From 1.2GB to 50MB - A Production Story

Docker: Optimizing Layer Cache for Lightning Fast CI/CD Builds

Post Views: 3

Post navigation

Kubernetes: Use Kustomize to Manage Multiple Environments Without Templates
AI Prompt: Generate Performance Review Comments from Metrics

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

June 2026
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
2930  
« May    

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (805)
  • Add Constraint to SQL Table to ensure email contains @ (580)
  • How to enable, disable and check if Service Broker is enabled on a database in SQL Server (579)
  • Average of all values in a column that are not zero in SQL (538)
  • How to use Map Mode for Vertical Scroll Mode in Visual Studio (505)
  • Find numbers with more than two decimal places in SQL (454)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files
  • Ajax: Add Custom Headers to Fetch Requests
  • JavaScript: Use console.table to Display Arrays as Tables
  • HTML: Use Spellcheck Attribute to Enable Browser Spell Check
  • CSS: Use user-select to Prevent Text Selection
  • Windows 11: Use Snipping Tool for Instant Screenshots

Most Viewed Posts

  • Get the User Name and Domain Name from an Email Address in SQL (953)
  • How to add default value for Entity Framework migrations for DateTime and Bool (882)
  • Get the First and Last Word from a String or Sentence in SQL (838)
  • How to select distinct rows in a datatable in C# (808)
  • How to make theater mode the default for Youtube (805)

Recent Posts

  • C#: Use String Interpolation Instead of Concatenation
  • C#: Use Tuples to Return Multiple Values from Methods
  • SQL: Use ISNULL and NULLIF for Smart NULL Handling
  • .NET Core: Use Data Annotations for Model Validation
  • Git: Use Git Clean to Remove Untracked Files

Social

  • ErcanOPAK.com
  • GoodReads
  • LetterBoxD
  • Linkedin
  • The Blog
  • Twitter
© 2026 Bits of .NET | Built with Xblog Plus free WordPress theme by wpthemespace.com