-
-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Run as non root user #67
Comments
@timlinux part of it is already done, https://github.com/gem/oq-qgis-server/blob/master/start-xvfb-nginx.sh#L55 |
@daniviga what do you think? |
You can run the FCGI process as different user, but not the entire container (e.g. passing
However, does it worth the effort when the container runs perfectly fine in rootless mode? (Podman is your friend!) @vot4anto may have opinions here |
If someone (@timlinux?) wants to test it: https://github.com/daniviga/oq-qgis-server/tree/usermode Please note that nginx is now exposed on
|
Rootless is also available from docker: https://docs.docker.com/engine/security/rootless/ |
is this issue still relevant? |
It would be nice if the container ran as e.g. apache or other non-priveledged user....
The text was updated successfully, but these errors were encountered: