Sign inSign up

creemama/openresty-non-root

By creemama

•Updated 8 days ago

Image
1

721

creemama/openresty-non-root repository overview

⁠Running nginx/openresty as a non-root user

Compared to the official nginx⁠ or openresty⁠ images, containers created from this image run as the nginx user instead of root.

The page for the official nginx images⁠ made the following recommendations in running nginx as a non-root user, which this image implements.

Redefine the following directives in /etc/nginx/nginx.conf⁠:

pid        /tmp/nginx.pid;
...
http {
    client_body_temp_path /tmp/client_temp;
    proxy_temp_path       /tmp/proxy_temp_path;
    fastcgi_temp_path     /tmp/fastcgi_temp;
    uwsgi_temp_path       /tmp/uwsgi_temp;
    scgi_temp_path        /tmp/scgi_temp;
...
}

The image modifies /etc/nginx/conf.d/default.conf⁠ to run with port 8080 since non-root users cannot bind processes to port 80 without additional configuration.

As a security best practice, this image does not advertise nginx or its version in headers using the following directives.

# https://github.com/openresty/headers-more-nginx-module#readme
server_tokens off;
more_clear_headers Server;

As recommended by the Docker Bench for Security⁠, this image includes a health check.

To disable this health check, do the following:

In docker run⁠, use --no-healthcheck.

In docker-compose⁠, use:

healthcheck:
  disable: true

⁠Trying out openresty-non-root

Use the following Docker command to try out this image:

docker run -p 8080:8080 --rm creemama/openresty-non-root:alpine

Afterwards, visit http://localhost:8080⁠ in a browser.

If you check out this container, you can use docker-compose:

docker-compose up

The configuration in docker-compose.yml⁠ is a more secure way of running this image.

⁠Nginx/OpenResty with HTTPS and CAC authentication

For an example server that redirects all traffic to HTTPS, see the ssl-example folder⁠. To run this SSL example, use the following command within the folder:

docker-compose up

Afterwards, visit https://localhost:8443⁠ in a browser.

The configuration for OCSP stapling and DoD certificates are commented out in default.conf⁠.

Uncomment the OCSP-stapling section if your certs support it.

Uncomment the Common Access Card (CAC) section if you would like to use CAC authentication with your website. This is useful for securing Department of Defense (DoD) web applications.

We created self-signed.crt⁠ and self-signed.key⁠ using the following command:

./self-signed-cert-generate.sh "localhost" "DNS:localhost"

Tag summary

Content type

Image

Digest

sha256:28e304ed9…

Size

60.7 MB

Last updated

8 days ago

docker pull creemama/openresty-non-root:alpine