Description
When automatic confirmation is not configured for yum install in a Dockerfile, installation may request confirmation. An automated build without a user to respond can stop or fail.
Potential impact
- Image builds can stop or fail during package installation.
- Urgent deployment or recovery work can be delayed.
Remediation
- Use -y or --assumeyes with yum install and retain package signature verification.
- Keep installation and yum clean all in the same RUN and verify that the automated build completes. Confirmation options alone do not fix package, repository or network errors.
Examples
The historical CentOS 7 examples are preserved. Use a supported image and repositories for actual builds, including a repository that provides nginx.
Before
dockerfile
FROM centos:7
RUN yum install nginx
After
dockerfile
FROM centos:7
RUN yum install -y nginx \
&& yum clean all
Explanation:
- Before: yum may require installation confirmation.
- After: The -y option answers confirmation, then cleans caches after successful installation.