← All recipes
Open source

Add USER instruction

Recipe IDorg.openrewrite.docker.AddUserInstructionArtifactorg.openrewrite:rewrite-docker

Adds a USER instruction to run the container as a non-root user (CIS Docker Benchmark 4.1). By default, adds to the final stage only and skips if a USER instruction already exists.

Single recipeApache 2.0

Add to your build

Get a download tokenSign in with GitHub or Google, and your token replaces YOUR_DOWNLOAD_TOKEN below. Free for open source recipes like this one.

~/.gradle/gradle.properties

codeGenomeUsername=you@example.com
codeGenomeToken=YOUR_DOWNLOAD_TOKEN

build.gradle.kts

plugins {
    id("org.openrewrite.rewrite") version("latest.release")
}

rewrite {
    activeRecipe("org.openrewrite.docker.AddUserInstruction")
}

repositories {
    mavenCentral()
    maven {
        url = uri("https://artifacts.codegenomeproject.org/maven")
        credentials {
            username = providers.gradleProperty("codeGenomeUsername").get()
            password = providers.gradleProperty("codeGenomeToken").get()
        }
    }
}

dependencies {
    rewrite("org.openrewrite:rewrite-docker:8.92.8")
}

Then run

./gradlew rewriteRun

This recipe has required options, which a build sets in a rewrite.yml recipe that you activate instead.

Usage

You’ll need the Moderne CLI configured before running the command below.

mod run . --recipe org.openrewrite.docker.AddUserInstruction --recipe-option "userName=appuser"

If the recipe isn’t available locally, install it with:

mod config recipes jar install org.openrewrite:rewrite-docker:RELEASE

Options

NameTypeDescription
userNamerequiredStringThe username to run as.
e.g. appuser
groupNameStringThe group name. If specified, the USER instruction will be USER user:group.
e.g. appgroup
stageNameStringOnly add the USER instruction to this build stage. If null, adds to the final stage only.
e.g. final
skipIfUserExistsBooleanIf true (default), skip adding USER if the stage already has a USER instruction. If false, always add the USER instruction at the end of the stage.

Data tables

Structured output this recipe can produce.

  • Source files that had resultsSource files that were modified by the recipe run.org.openrewrite.table.SourcesFileResults
  • Source files that had search resultsSearch results that were found during the recipe run.org.openrewrite.table.SearchResults
  • Source files that errored on a recipeThe details of all errors produced by a recipe run.org.openrewrite.table.SourcesFileErrors
  • Recipe performanceStatistics used in analyzing the performance of recipes.org.openrewrite.table.RecipeRunStats