FROM docker.io/library/alpine:3 RUN apk add --no-cache openssh-client tini COPY --chmod=0755 entrypoint.sh /usr/local/bin/sish-client # nobody: ssh needs a uid that exists in /etc/passwd, so keep runAsUser at 65534 USER 65534:65534 # tini reaps zombies and forwards SIGTERM to the whole process group (-g), incl. ssh ENTRYPOINT ["/sbin/tini", "-g", "--", "/usr/local/bin/sish-client"]