From 42b6916c02bc7b744316ce119a092135c239d131 Mon Sep 17 00:00:00 2001 From: clawbot <35+clawbot@noreply.example.org> Date: Tue, 29 Sep 2026 10:26:31 +0000 Subject: [PATCH] README: name everything that runs as root in the container The security-features bullet said only the entrypoint script runs as root. With no USER in the image, the health check and docker exec also run as root; the bullet now names all three. Model: opus-5-5 --- README.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/README.md b/README.md index e646274..d2330dd 100644 --- a/README.md +++ b/README.md @@ -3032,9 +3032,11 @@ check, see [The login endpoint](#the-login-endpoint). - Prometheus metrics behind basic auth - Static assets embedded in binary (no filesystem access needed at runtime) -- The app runs as a non-root user (UID 1000) in the container; only - the `ENTRYPOINT` script that sets the data directory's owner runs as - root, before the app starts +- The app runs as the non-root `webhooker` user (UID 1000) in the + container. The image sets no `USER`, so these run as root: the + `ENTRYPOINT` script, which sets the data directory's owner and mode + before the app starts; the image's health check; and `docker exec`, + unless given `--user` - GORM soft deletes on every entity that carries `BaseModel`, which is all of them but `Setting` (data preserved for audit)