Description
Dockerfile RUN instructions execute with the currently configured user’s permissions. Adding sudo can make the effective permissions harder to follow and introduce environment-dependent behavior.
A simple privilege flow makes builds easier to review and maintain. When a different user is needed, select it explicitly with USER and avoid sudo within RUN.
Potential impact
- Build-stage privileges become harder to understand and review.
- Differences in sudo configuration or availability can cause build failures.
- Unnecessary use of elevated privileges can become routine.
Remediation
- Run commands as the required user rather than using
sudoinsideRUN. - Declare user changes explicitly with
USER. - Reduce unnecessary administrative privileges during image builds.
Examples
These excerpts assume a root build step in an Alpine-based image with apk and repositories configured. Removing sudo does not reduce root privileges; configure the application’s runtime user separately.
Before
dockerfile
RUN sudo apk add --no-cache curl
After
dockerfile
RUN apk add --no-cache curl
Explanation:
- Before:
sudoadds unnecessary complexity to the build’s privilege flow. - After: The command runs directly with the current user’s permissions, making build behavior more predictable.