Non-Root User

Running as a Non-Root User by Default

Without USER, a container runs as root. Namespaces weaken that root, but it can still rewrite the image's files, bind privileged ports and, after an escape or through a careless bind mount, act as root on the host (Container Security). The Node.js 2,131 images ship an unprivileged user, node (UID 1000), and BookNest switches to it after installing dependencies:

The API runs as node and cannot modify its own codeShell
docker start l3-api >/dev/null
docker exec l3-api id
docker exec l3-api ls -ld /app /app/server.js
docker exec l3-api touch /app/server.js
Output
uid=1000(node) gid=1000(node) groups=1000(node)
drwxr-xr-x 1 root root 4096 Sep 25 09:09 /app
-rwxr-xr-x 1 root root  712 Sep 25 05:57 /app/server.js
touch: cannot touch '/app/server.js': Permission denied

The files were copied before USER, so they belong to root: the server can read but not change them, and code injected through a vulnerability cannot rewrite the application. An application that must write gets one directory handed over with RUN mkdir /app/data && chown node /app/data, or better a volume (Volumes, Bind Mounts and tmpfs). The user is given by number, USER 1000:1000, because Kubernetes 5,150 can enforce runAsNonRoot only for a numeric UID, and Hadolint 12,433 's rule DL3066 flags names.