Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -34,3 +34,13 @@ Thumbs.db

# Examples and docs
docs

# Secrets and local env - must never land in an image layer (audit HI-12).
# Applies to every build using the repo root as context (web + api/v2).
.env
.env.*
*.pem
*.key
*.p12
*.pfx
.husky
9 changes: 8 additions & 1 deletion Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -101,14 +101,21 @@ WORKDIR /calcom

RUN apt-get update && apt-get install -y --no-install-recommends netcat-openbsd wget && rm -rf /var/lib/apt/lists/*

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

While COPY --chown=node:node correctly sets the ownership of the copied files, the /calcom directory itself was created by WORKDIR /calcom while running as root. This leaves the /calcom directory owned by root:root with 0755 permissions, which prevents the non-root node user from creating any new files or directories directly under /calcom at runtime (e.g., lockfiles, temporary files, or local cache directories).

To prevent potential Permission denied errors, change the ownership of the /calcom directory to node:node during the setup phase.

RUN apt-get update && apt-get install -y --no-install-recommends netcat-openbsd wget && rm -rf /var/lib/apt/lists/* && chown node:node /calcom


COPY --from=builder-two /calcom ./
# Why --chown: the container runs as the non-root node user (USER below); owning
# the tree lets the runtime write its caches (Next ISR, prisma engines) without
# adding a duplicate copy-up layer that a separate chown -R would create.
COPY --from=builder-two --chown=node:node /calcom ./
ARG NEXT_PUBLIC_WEBAPP_URL=https://cal.crove.com
ENV NEXT_PUBLIC_WEBAPP_URL=$NEXT_PUBLIC_WEBAPP_URL \
BUILT_NEXT_PUBLIC_WEBAPP_URL=$NEXT_PUBLIC_WEBAPP_URL

ENV NODE_ENV=production
EXPOSE 3000

# HI-12: run as the unprivileged node user (uid 1000) shipped with the base
# image instead of root; apt above already ran as root.
USER node

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-medium medium

Using a non-numeric user name like USER node can cause issues with strict container security scanners, Kubernetes admission controllers (such as Kyverno or OPA Gatekeeper), and certain container runtimes that require or prefer numeric UIDs to verify non-root execution without inspecting the image's /etc/passwd file.

Since the node user in the official Node.js base image is guaranteed to have UID 1000, it is a best practice to use the numeric UID instead.

USER 1000


HEALTHCHECK --interval=30s --timeout=30s --retries=5 \
CMD wget --spider http://localhost:3000 || exit 1
Comment on lines 119 to 120

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

By default, wget attempts to write a .wget-hsts file to the user's home directory (/home/node). If the container is run with a read-only root filesystem (a common security best practice), this write operation will fail and may cause the healthcheck to fail or log warnings.

Adding the --no-hsts flag to wget disables HSTS tracking and prevents it from attempting to write to the filesystem, making the healthcheck more robust in read-only environments.

HEALTHCHECK --interval=30s --timeout=30s --retries=5 \
  CMD wget --no-hsts --spider http://localhost:3000 || exit 1


Expand Down
Loading