From 9c44946927fa0e14e54230679315816c8dd72e4d Mon Sep 17 00:00:00 2001 From: Ishaan Jaff Date: Tue, 7 Jan 2025 19:30:41 -0800 Subject: [PATCH] fix security of base images --- docker/Dockerfile.database | 20 +++++++++++++------- 1 file changed, 13 insertions(+), 7 deletions(-) diff --git a/docker/Dockerfile.database b/docker/Dockerfile.database index 5e660618a90..02eb2861802 100644 --- a/docker/Dockerfile.database +++ b/docker/Dockerfile.database @@ -1,18 +1,20 @@ # Base image for building -ARG LITELLM_BUILD_IMAGE=python:3.13.1-slim +ARG LITELLM_BUILD_IMAGE=cgr.dev/chainguard/python:latest-dev # Runtime image -ARG LITELLM_RUNTIME_IMAGE=python:3.13.1-slim +ARG LITELLM_RUNTIME_IMAGE=cgr.dev/chainguard/python:latest-dev # Builder stage FROM $LITELLM_BUILD_IMAGE AS builder # Set the working directory to /app WORKDIR /app +USER root + # Install build dependencies -RUN apt-get clean && apt-get update && \ - apt-get install -y gcc python3-dev && \ - rm -rf /var/lib/apt/lists/* +RUN apk update && \ + apk add --no-cache gcc python3-dev openssl openssl-dev + RUN pip install --upgrade pip && \ pip install build @@ -38,8 +40,12 @@ RUN pip wheel --no-cache-dir --wheel-dir=/wheels/ -r requirements.txt # Runtime stage FROM $LITELLM_RUNTIME_IMAGE AS runtime -# Update dependencies and clean up - handles debian security issue -RUN apt-get update && apt-get upgrade -y && rm -rf /var/lib/apt/lists/* +# Ensure runtime stage runs as root +USER root + +# Install runtime dependencies +RUN apk update && \ + apk add --no-cache openssl WORKDIR /app # Copy the current directory contents into the container at /app