如何为自定义Docker镜像添加身份验证,需凭证才可进入?
Got it, let's solve this problem where you want to lock down your ubuntu-myapp image—so only folks with valid credentials can get inside to modify or copy code. Below are two practical, easy-to-implement approaches:
1. Quick & Simple: Use a Custom Entrypoint Script for Password Check
This is the fastest way to add basic auth without messing with system-level configs. Here's how to do it:
First, create an entrypoint script (name it
auth-entrypoint.sh) with the following content:#!/bin/bash # Define your secret password (use build args/secrets instead of hardcoding for production!) EXPECTED_PASSWORD="your-secure-password-here" # Prompt user for password (hides input while typing) read -s -p "Enter authentication password: " INPUT_PASSWORD echo "" # Validate credentials if [ "$INPUT_PASSWORD" != "$EXPECTED_PASSWORD" ]; then echo "Error: docker image run authentication required - invalid credentials" exit 1 fi # If valid, start the shell or your app exec "$@"Next, update your Dockerfile to include this script and set it as the entrypoint:
FROM ubuntu-myapp # Copy the auth script into the container COPY auth-entrypoint.sh /usr/local/bin/ # Make it executable RUN chmod +x /usr/local/bin/auth-entrypoint.sh # Set our auth script as the entrypoint ENTRYPOINT ["auth-entrypoint.sh"] # Default to starting bash if no command is provided CMD ["bash"]Build the updated image:
docker build -t ubuntu-myapp-auth .
Now, when someone runs docker run -it ubuntu-myapp-auth, they'll be prompted for a password. Wrong credentials will kick them out with the exact "docker image run authentication required" message you wanted.
Pro tip: For better security, avoid hardcoding the password in the script. Pass it as a build argument or use Docker Secrets (if using Swarm) to keep credentials out of your Dockerfile and version control.
2. More Robust: System-Level Authentication with PAM
If you want a native, Linux-like login experience (requiring both username and password), set up system user accounts and enforce login prompts:
Update your Dockerfile to create a dedicated user, set a hashed password, and configure the container to require login:
FROM ubuntu-myapp # Install login tools if missing RUN apt-get update && apt-get install -y --no-install-recommends login # Create a dedicated user (replace 'myappuser' with your preferred username) RUN useradd -m myappuser # Set a hashed password for the user (use openssl to generate the hash) RUN echo "myappuser:$(openssl passwd -1 your-secure-password)" | chpasswd # Configure container to start a login prompt instead of direct bash CMD ["login", "-f", "myappuser"]Build the image:
docker build -t ubuntu-myapp-pam-auth .
When you run docker run -it ubuntu-myapp-pam-auth, you'll get a standard Linux login prompt. Only users with the correct username and password can access the shell. To block users from overriding the login prompt (e.g., by passing a custom CMD), add an entrypoint script that validates the command being run.
Important Notes
- These methods prevent unauthorized shell access, but remember: if someone has access to the Docker daemon (can run
dockercommands on the host), they can still inspect image layers or extract files without entering the container. Combine this with Docker registry authentication to restrict who can pull the image in the first place. - Never commit sensitive passwords to version control. Use build args, secrets, or encrypted environment variables to manage credentials safely.
内容的提问来源于stack exchange,提问作者Sandeep

