We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent aabc69f commit b4fbc39Copy full SHA for b4fbc39
1 file changed
IMAGES/helm-job-runner/Dockerfile-nix
@@ -15,9 +15,8 @@ mkdir -p /tmp/nix-store-closure
15
cp -R $(nix-store -qR /tmp/output/result) /tmp/nix-store-closure
16
EOF
17
18
-FROM scratch
19
-WORKDIR /app
+FROM gcr.io/distroless/static
20
COPY --from=builder /tmp/nix-store-closure /nix/store
21
-COPY --from=builder /tmp/output/ /app/
22
-USER 1001
+USER nonroot:nonroot
+COPY --from=builder --chown=nonroot:nonroot /tmp/output/ /app/
23
ENV PATH=/app/result/bin
0 commit comments