Description
Writing CMD and ENTRYPOINT without JSON arrays can invoke a shell and change argument interpretation. Signal forwarding and process control may then behave differently from what is intended.
Containers need a main process that starts and stops reliably. Use JSON arrays to specify the executable and arguments directly. If shell features are needed, invoke them deliberately and verify that signals reach the final process.
Potential impact
- Termination signals may not reach the intended process.
- Different argument interpretation can change execution results.
- Container shutdown or restart can cause operational problems.
Remediation
- Use a JSON array such as
CMD ["python", "/app/app.py"]. - Use the same form for
ENTRYPOINTto reduce implicit shell dependencies. - Review existing string-form commands and their intended behavior.
Examples
These excerpts assume a Linux image supporting top -b. Exec-form CMD supplies default arguments appended to ENTRYPOINT.
Before
dockerfile
CMD [-b]
ENTRYPOINT [top]
After
dockerfile
CMD ["-b"]
ENTRYPOINT ["top"]
Explanation:
- Before: An array without quoted strings is not valid JSON and does not select the intended exec form.
- After: The JSON arrays run
top -bdirectly. Test signal handling and graceful termination in the actual application as well.