haystack icon indicating copy to clipboard operation
haystack copied to clipboard

Run Internet facing commands inside docker container as a non root user

Open vblagoje opened this issue 2 years ago • 0 comments

Is your feature request related to a problem? Please describe. We currently run gunicorn as a root user, exposing not only the contents of the docker image to potential attackers but also leaving a backdoor open for an attacker to gain access to the host machine.

Describe the solution you'd like Run all internet-facing commands as non-root user thus limiting potential security issues for the Haystack deployments.

Describe alternatives you've considered N/A

For more context and a brief introduction refer to this excellent article

vblagoje avatar Sep 21 '22 09:09 vblagoje