Skip to content

fix(dockerfile): ignore hadolint DL3066 on USER instruction - #222

Merged
colisee merged 1 commit into
masterfrom
jlvillal/hadolint_fix
Oct 10, 2026
Merged

colisee merged 1 commit into
masterfrom
jlvillal/hadolint_fix

Conversation

@JohnVillalovos

@JohnVillalovos JohnVillalovos commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

hadolint 2.15.x adds rule DL3066, which flags a non-numeric user in
the USER instruction because the name may not be resolvable by the
host system. The rule is info severity, but hadolint-action's default
failure-threshold is info, so it fails the "Lint Dockerfile" job. This
blocks the Dependabot bump of hadolint/hadolint-action from 3.3.0 to
3.5.0 (#220).

Keep USER www-data:root and suppress the rule with an inline
# hadolint ignore=DL3066 pragma. The www-data user and root group
always exist in the Debian-based php:*-apache base image, and the
names are more readable than their numeric IDs.

Assisted-by: Claude Opus 5.5 noreply@anthropic.com

@JohnVillalovos
JohnVillalovos requested a review from colisee October 9, 2026 17:13
@colisee

colisee commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator

In theory, hadolint rule 3066 makes sense, but probably not in our case. User www-data is known by the image since the apache server is installed (which means that the www-data profile is created inside the image).

We would need the advice from someone who is using librebooking with Kubernetes.

@colisee colisee self-assigned this Oct 10, 2026
@colisee colisee added the bug Something isn't working label Oct 10, 2026
@colisee

colisee commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator

@ikke-t , what would be your opinion on this matter?

hadolint 2.15.x adds rule DL3066, which flags a non-numeric user in
the USER instruction because the name may not be resolvable by the
host system. The rule is info severity, but hadolint-action's default
failure-threshold is info, so it fails the "Lint Dockerfile" job. This
blocks the Dependabot bump of hadolint/hadolint-action from 3.3.0 to
3.5.0 (#220).

Keep `USER www-data:root` and suppress the rule with an inline
`# hadolint ignore=DL3066` pragma. The www-data user and root group
always exist in the Debian-based php:*-apache base image, and the
names are more readable than their numeric IDs.

Assisted-by: Claude Opus 5.5 <noreply@anthropic.com>
@JohnVillalovos

Copy link
Copy Markdown
Collaborator Author

@colisee I changed the PR to just ignore this info level notice. As it is only info level I think it is fine to ignore it.

@ikke-t

ikke-t commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

The user depends on kube deployment. In OpenShift kube it gets random uid in each run, and gid root. That's why www-data:root and 0775 chmod earlier. It guarantees whichever uid is, the write permissions will match duenroot group can write to workdirs.

@colisee

colisee commented Oct 10, 2026

Copy link
Copy Markdown
Collaborator

Thank you so much @ikke-t

@colisee
colisee merged commit 14b17f1 into master Oct 10, 2026
3 checks passed
@colisee
colisee deleted the jlvillal/hadolint_fix branch October 10, 2026 16:55
@JohnVillalovos JohnVillalovos changed the title fix(dockerfile): use numeric UID:GID in USER instruction fix(dockerfile): ignore hadolint DL3066 on USER instruction Oct 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants