# container-image Specification ## Purpose Define the security posture of the shipped application container image, starting with running the application process as a dedicated non-root user. ## Requirements ### Requirement: Runtime container executes as non-root The application container image SHALL run the application process as a dedicated non-root user. #### Scenario: Container process has a non-zero UID - **WHEN** the image is built and a container is started from it with no user override - **THEN** the application process SHALL run with a non-zero UID #### Scenario: Application serves normally as non-root - **WHEN** the container runs as the non-root user - **THEN** the application SHALL bind port 8080 and serve requests - **AND** no operation SHALL fail with a filesystem or port permission error