From 0c4c91b1ba9273d08d08b9b0f390045f2365d888 Mon Sep 17 00:00:00 2001 From: Alexander Tarasov Date: Tue, 29 Sep 2026 10:21:35 +0200 Subject: [PATCH 1/2] build(self-hosted): Run sentry image as non-root and drop gosu Set USER 999:999 in the image and remove gosu along with the entrypoint's root branch that chowned /data and stepped down to the sentry user. /data is now created and owned by sentry at build time, so fresh named volumes come up with the right ownership. This mirrors getsentry/snuba#2777. Production already runs getsentry as uid 999 via runAsUser. Removes a root-only code path and the gosu binary ahead of moving the image to a distroless base. --- self-hosted/Dockerfile | 8 +++++++- self-hosted/docker-entrypoint.sh | 8 -------- 2 files changed, 7 insertions(+), 9 deletions(-) diff --git a/self-hosted/Dockerfile b/self-hosted/Dockerfile index b4f52f40d5d6..a2d9d92c0213 100644 --- a/self-hosted/Dockerfile +++ b/self-hosted/Dockerfile @@ -29,7 +29,6 @@ RUN groupadd -r sentry --gid 999 && useradd -r -m -g sentry --uid 999 sentry RUN : \ && apt-get update \ && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-install-recommends \ - gosu \ libexpat1 \ tini \ && apt-get clean \ @@ -91,6 +90,13 @@ RUN : double-check some built files are available \ && test -f /usr/src/sentry/src/sentry/static/sentry/dist/entrypoints/app.js \ && sentry help +# Pre-create /data owned by sentry so fresh named volumes are initialized +# with the right ownership. This must happen before the VOLUME instruction. +RUN mkdir -p /data/files && chown -R sentry:sentry /data + +# Numeric so that Kubernetes' runAsNonRoot can verify it. +USER 999:999 + EXPOSE 9000 VOLUME /data diff --git a/self-hosted/docker-entrypoint.sh b/self-hosted/docker-entrypoint.sh index 2f0eb6c7d819..e3610fb68ca3 100755 --- a/self-hosted/docker-entrypoint.sh +++ b/self-hosted/docker-entrypoint.sh @@ -14,14 +14,6 @@ fi if [ "$1" = 'sentry' ]; then set -- tini -- "$@" - if [ "$(id -u)" = '0' ]; then - mkdir -p /data/files - sentry_uid=$(id -u sentry) - if [ "$(stat -c %u /data)" != "$sentry_uid" ] || [ "$(stat -c %u /data/files)" != "$sentry_uid" ]; then - find /data ! -user sentry -exec chown sentry {} \; - fi - set -- gosu sentry "$@" - fi fi exec "$@" From cccdd1c9271914b623e610e3da424e050563a363 Mon Sep 17 00:00:00 2001 From: Alexander Tarasov Date: Tue, 29 Sep 2026 10:30:33 +0200 Subject: [PATCH 2/2] build(self-hosted): Use named sentry user in USER instruction --- self-hosted/Dockerfile | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/self-hosted/Dockerfile b/self-hosted/Dockerfile index a2d9d92c0213..abac1f6319fa 100644 --- a/self-hosted/Dockerfile +++ b/self-hosted/Dockerfile @@ -94,8 +94,7 @@ RUN : double-check some built files are available \ # with the right ownership. This must happen before the VOLUME instruction. RUN mkdir -p /data/files && chown -R sentry:sentry /data -# Numeric so that Kubernetes' runAsNonRoot can verify it. -USER 999:999 +USER sentry EXPOSE 9000 VOLUME /data