Skip to content

security: run claude-apps-gateway container as non-root; harden .gitignore - #18

Merged
DustyStudy merged 1 commit into
mainfrom
security/hardening-2026-09
Sep 21, 2026
Merged

DustyStudy merged 1 commit into
mainfrom
security/hardening-2026-09

Conversation

@DustyStudy

@DustyStudy DustyStudy commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner
  • Both claude-apps-gateway Dockerfiles ran the container as root; they now create and run as an unprivileged user (uid 10001). Port 8080 needs no privileges. Please test a build before merging.
  • Extends .gitignore to cover .env, tfvars, keys and .terraform.

Found in a security scan of all repos.

…gnore

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@DustyStudy
DustyStudy merged commit 085f323 into main Sep 21, 2026
3 checks passed
@DustyStudy
DustyStudy deleted the security/hardening-2026-09 branch September 21, 2026 13:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant