Pipeline without pipefail

Configure the shell to detect failures earlier in a pipeline.

Description

With pipefail disabled, a shell generally takes a pipeline’s exit status from its last command. A RUN step can therefore succeed when an earlier command fails but the last command succeeds.

Potential impact

An unnoticed download or preprocessing failure can leave incomplete artifacts in the image.

Remediation

Enable pipefail in a shell installed in the image that supports it. Otherwise, explicitly choose a supporting shell or check each command’s failure separately.

Examples

The examples configure Bash to propagate pipeline failures. pipefail does not verify the downloaded script’s trustworthiness; check its source and integrity before execution.

Before

dockerfile
FROM node:22

RUN curl -fsSL https://example.com/install.sh | bash

After

dockerfile
FROM node:22

SHELL ["/bin/bash", "-o", "pipefail", "-c"]
RUN curl -fsSL https://example.com/install.sh | bash

References