BobSong-dev opened a new pull request, #7152:
URL: https://github.com/apache/shenyu/pull/7152

   ## Background
   
   The Dockerfiles under shenyu-examples and shenyu-integrated-test run as root 
and do not provide OCI image metadata or container liveness checks. This makes 
the example and integration-test images harder to operate safely and 
consistently.
   
   Fixes #6819
   
   ## Changes
   
   - Add OCI image title, source, and license labels to all 39 target 
Dockerfiles.
   - Create a dedicated shenyu system user and run each image as that non-root 
user.
   - Add a portable process-level liveness HEALTHCHECK without introducing 
extra runtime packages.
   - Keep the upload-plugin custom artifact image buildable by checking the 
packaged plugin artifact instead of treating it as an application service.
   
   ## Verification
   
   - git diff --check
   - Static validation confirmed all 39 target Dockerfiles contain LABEL, USER 
shenyu, and HEALTHCHECK, with no build-stage RUN instructions after the user 
switch.
   - Dockerfile BuildKit checks were attempted for representative CentOS, 
Alpine, and custom-plugin images, but Docker Desktop's Linux daemon was 
unavailable in the local environment.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to