FROM alpine:3.22
# a service account with fixed numeric IDs, and the one directory it may write
RUN addgroup -S -g 10001 app \
 && adduser -S -D -H -u 10001 -G app app \
 && mkdir /data \
 && chown 10001:10001 /data
# the code stays owned by root: the app can run it but not change it
COPY --chmod=0755 app.sh /app/app.sh
USER 10001:10001
CMD ["/app/app.sh"]
