Description
Use SHELL to select the default shell for subsequent shell-form instructions rather than changing it indirectly with RUN. RUN executes individual commands and does not express that intent clearly.
Changing a shell executable’s link can affect other scripts that use it and make later command behavior confusing. Explicit Dockerfile instructions are easier to maintain and review.
Potential impact
- Unclear intent makes the Dockerfile harder to maintain.
- Shell behavior may differ between build steps and cause errors.
- Build reviews can miss unintended behavior.
Remediation
- Use
SHELL ["..."]when a different default shell is needed. - Avoid changing the shell through commands such as
RUN ln -sf .... - Change the shell only when required and declare it explicitly.
Examples
These excerpts assume a Linux image with Bash installed at /bin/bash. SHELL applies to subsequent shell-form RUN, CMD and ENTRYPOINT instructions; it does not change a user’s login shell.
Before
dockerfile
RUN ln -sfv /bin/bash /bin/sh
After
dockerfile
SHELL ["/bin/bash", "-c"]
Explanation:
- Before: A
RUNcommand changes the shell link, hiding the intended shell choice and complicating maintenance. - After:
SHELLexplicitly selects the shell used by later shell-form instructions.