Using sudo in RUN

Make the RUN user explicit and remove unnecessary sudo use.

Description

Dockerfile RUN instructions execute with the currently configured user’s permissions. Adding sudo can make the effective permissions harder to follow and introduce environment-dependent behavior.

A simple privilege flow makes builds easier to review and maintain. When a different user is needed, select it explicitly with USER and avoid sudo within RUN.

Potential impact

  • Build-stage privileges become harder to understand and review.
  • Differences in sudo configuration or availability can cause build failures.
  • Unnecessary use of elevated privileges can become routine.

Remediation

  • Run commands as the required user rather than using sudo inside RUN.
  • Declare user changes explicitly with USER.
  • Reduce unnecessary administrative privileges during image builds.

Examples

These excerpts assume a root build step in an Alpine-based image with apk and repositories configured. Removing sudo does not reduce root privileges; configure the application’s runtime user separately.

Before

dockerfile
RUN sudo apk add --no-cache curl

After

dockerfile
RUN apk add --no-cache curl

Explanation:

  • Before: sudo adds unnecessary complexity to the build’s privilege flow.
  • After: The command runs directly with the current user’s permissions, making build behavior more predictable.

References