We should use a tool like gosu or yasu to step down from root to a non-privileged user during container startup.
root