Description
RUN executes while an image is being built. Commands such as top that expect interactive operation can stall or fail a build, and ps output describes the build-time state rather than the running service.
Diagnostic tools are not inherently prohibited. Necessary noninteractive build diagnostics can be used, and executing a tool is distinct from installing it.
Potential impact
- Unnecessary diagnostics can lengthen or interrupt automated builds.
- Build-time process output can be mistaken for the state of the running service.
Remediation
- Remove diagnostic commands that the build does not need, and configure necessary diagnostics to finish without interaction.
- Inspect running services at runtime. Removing a RUN instruction does not remove tools already installed in the base image.
Examples
The existing Go 1.22 examples compare build commands. Use a supported compatible image and supply the required source and module files for actual builds.
Before
dockerfile
FROM golang:1.22
WORKDIR /app
COPY . .
RUN top
RUN ps -ef
CMD ["go", "run", "main.go"]
After
dockerfile
FROM golang:1.22
WORKDIR /app
COPY . .
RUN go build -o app .
CMD ["./app"]
Explanation:
- Before: top and ps run during the build. top may be unsuitable for a noninteractive build.
- After: The application is built and the resulting executable is started. This change alone does not remove the Go tools from the image.