You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为自定义Docker镜像添加身份验证,需凭证才可进入?

Add Authentication to Your Custom Ubuntu Docker Image

Got it, let's solve this problem where you want to lock down your ubuntu-myapp image—so only folks with valid credentials can get inside to modify or copy code. Below are two practical, easy-to-implement approaches:

1. Quick & Simple: Use a Custom Entrypoint Script for Password Check

This is the fastest way to add basic auth without messing with system-level configs. Here's how to do it:

  • First, create an entrypoint script (name it auth-entrypoint.sh) with the following content:

    #!/bin/bash
    
    # Define your secret password (use build args/secrets instead of hardcoding for production!)
    EXPECTED_PASSWORD="your-secure-password-here"
    
    # Prompt user for password (hides input while typing)
    read -s -p "Enter authentication password: " INPUT_PASSWORD
    echo ""
    
    # Validate credentials
    if [ "$INPUT_PASSWORD" != "$EXPECTED_PASSWORD" ]; then
        echo "Error: docker image run authentication required - invalid credentials"
        exit 1
    fi
    
    # If valid, start the shell or your app
    exec "$@"
    
  • Next, update your Dockerfile to include this script and set it as the entrypoint:

    FROM ubuntu-myapp
    
    # Copy the auth script into the container
    COPY auth-entrypoint.sh /usr/local/bin/
    
    # Make it executable
    RUN chmod +x /usr/local/bin/auth-entrypoint.sh
    
    # Set our auth script as the entrypoint
    ENTRYPOINT ["auth-entrypoint.sh"]
    # Default to starting bash if no command is provided
    CMD ["bash"]
    
  • Build the updated image:

    docker build -t ubuntu-myapp-auth .
    

Now, when someone runs docker run -it ubuntu-myapp-auth, they'll be prompted for a password. Wrong credentials will kick them out with the exact "docker image run authentication required" message you wanted.

Pro tip: For better security, avoid hardcoding the password in the script. Pass it as a build argument or use Docker Secrets (if using Swarm) to keep credentials out of your Dockerfile and version control.

2. More Robust: System-Level Authentication with PAM

If you want a native, Linux-like login experience (requiring both username and password), set up system user accounts and enforce login prompts:

  • Update your Dockerfile to create a dedicated user, set a hashed password, and configure the container to require login:

    FROM ubuntu-myapp
    
    # Install login tools if missing
    RUN apt-get update && apt-get install -y --no-install-recommends login
    
    # Create a dedicated user (replace 'myappuser' with your preferred username)
    RUN useradd -m myappuser
    # Set a hashed password for the user (use openssl to generate the hash)
    RUN echo "myappuser:$(openssl passwd -1 your-secure-password)" | chpasswd
    
    # Configure container to start a login prompt instead of direct bash
    CMD ["login", "-f", "myappuser"]
    
  • Build the image:

    docker build -t ubuntu-myapp-pam-auth .
    

When you run docker run -it ubuntu-myapp-pam-auth, you'll get a standard Linux login prompt. Only users with the correct username and password can access the shell. To block users from overriding the login prompt (e.g., by passing a custom CMD), add an entrypoint script that validates the command being run.

Important Notes

  • These methods prevent unauthorized shell access, but remember: if someone has access to the Docker daemon (can run docker commands on the host), they can still inspect image layers or extract files without entering the container. Combine this with Docker registry authentication to restrict who can pull the image in the first place.
  • Never commit sensitive passwords to version control. Use build args, secrets, or encrypted environment variables to manage credentials safely.

内容的提问来源于stack exchange,提问作者Sandeep

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:57:53