Review COPY file ownership and write permissions

Grant the runtime account only necessary data-write permissions and protect application code.

Description

Giving the application account ownership through COPY --chown can allow it to modify code, depending on file permissions. A compromised application can cause greater damage if that account can also alter executables or configuration.

--chown is not inherently unsafe. It can support non-root execution and necessary data writes. Review the files’ purpose and effective file, directory and mount permissions together.

Potential impact

  • If the runtime account can modify code, an attacker can change application behavior or leave malicious code after a compromise.
  • Removing write access from required data directories can break the application.

Remediation

  • Separate application code from writable data and grant the runtime account write access only to necessary paths.
  • Configure code ownership and modes together. Verify that the non-root account can read and execute the code without modifying it; root ownership alone does not guarantee this.

Examples

The examples compare ownership of copied files. Also check source file modes and the application’s actual write paths.

Before

dockerfile
FROM python:3.12-slim

RUN useradd -ms /bin/bash appuser
COPY --chown=appuser:appuser app /app
WORKDIR /app
USER appuser
CMD ["python", "app.py"]

After

dockerfile
FROM python:3.12-slim

RUN useradd -ms /bin/bash appuser
COPY app /app
WORKDIR /app
USER appuser
CMD ["python", "app.py"]

Explanation:

  • Before: appuser owns the copied files. Effective write access depends on file and directory permissions.
  • After: Files are copied with default root ownership and the application runs as appuser. Required read/execute access and restrictions on code writes still need verification.

References