Dockerfile has no USER instruction

Check the final image’s default user and run the application with only the privileges it needs.

Description

Without a USER instruction, a Dockerfile inherits the base image’s user configuration. If the base image has no user configured either, the default is root. An omitted USER therefore does not always mean root, but the final image’s effective user needs verification.

Creating an account does not switch the runtime user. In a multistage build, check the base image and user configuration of the final stage.

Potential impact

  • If the effective user is root, an application compromise can provide broader access to files and processes inside the container.
  • Base-image or deployment changes can alter the intended runtime privileges.

Remediation

  • Prepare the required non-root account in the final runtime stage and explicitly select it with USER <non-root-user>.
  • Restrict ownership and permissions of application files and writable directories to the runtime account’s needs.
  • Review image configuration and runtime user overrides together, then test startup and file access.

Examples

The example requires the actual app/app.py and application code compatible with the selected versions. Maintain tested dependency versions and update them regularly.

Before

dockerfile
FROM python:3.13-slim
RUN pip install Flask==3.1.2
RUN useradd -ms /bin/bash appuser
COPY --chown=appuser:appuser app /app
WORKDIR /app
CMD ["python", "app.py"]

This base image defaults to root. Creating appuser and assigning file ownership do not switch the runtime account.

After

dockerfile
FROM python:3.13-slim
RUN pip install Flask==3.1.2
RUN useradd -ms /bin/bash appuser
COPY --chown=appuser:appuser app /app
WORKDIR /app
USER appuser
CMD ["python", "app.py"]

USER appuser selects the default application user. File ownership in this example also matches that account.

References