Review diagnostic commands in RUN

Run commands needed by the build and perform interactive diagnostics separately.

Description

RUN executes while an image is being built. Commands such as top that expect interactive operation can stall or fail a build, and ps output describes the build-time state rather than the running service.

Diagnostic tools are not inherently prohibited. Necessary noninteractive build diagnostics can be used, and executing a tool is distinct from installing it.

Potential impact

  • Unnecessary diagnostics can lengthen or interrupt automated builds.
  • Build-time process output can be mistaken for the state of the running service.

Remediation

  • Remove diagnostic commands that the build does not need, and configure necessary diagnostics to finish without interaction.
  • Inspect running services at runtime. Removing a RUN instruction does not remove tools already installed in the base image.

Examples

The existing Go 1.22 examples compare build commands. Use a supported compatible image and supply the required source and module files for actual builds.

Before

dockerfile
FROM golang:1.22

WORKDIR /app
COPY . .
RUN top
RUN ps -ef
CMD ["go", "run", "main.go"]

After

dockerfile
FROM golang:1.22

WORKDIR /app
COPY . .
RUN go build -o app .
CMD ["./app"]

Explanation:

  • Before: top and ps run during the build. top may be unsuitable for a noninteractive build.
  • After: The application is built and the resulting executable is started. This change alone does not remove the Go tools from the image.

References