diff --git a/Dockerfile b/Dockerfile index 24a2c71..e4224df 100644 --- a/Dockerfile +++ b/Dockerfile @@ -26,7 +26,11 @@ RUN GITCOMMIT=$(git rev-parse HEAD) \ -ldflags="-X 'github.com/uc-cdis/cohort-middleware/version.GitCommit=${GITCOMMIT}' -X 'github.com/uc-cdis/cohort-middleware/version.GitVersion=${GITVERSION}'" \ -o /cohort-middleware +RUN echo "nobody:x:65534:65534:Nobody:/:" > /etc_passwd + FROM scratch +COPY --from=builder /etc_passwd /etc/passwd COPY --from=builder /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem /etc/ssl/certs/ca-certificates.crt COPY --from=builder /cohort-middleware /cohort-middleware +USER nobody CMD ["/cohort-middleware"]