Bench user as sudoer

Anyone concerned about the bench user being member of sudoers ?

I understand some bench commands requires sudo, but I am more concerned about frappe services running as sudo user.

Any comments ?

In dockerized setup all the processes run as non root user.

only nginx container that reverse proxy and serves static assets run as root. Build unprivileged frappe-nginx and erpnext-nginx · Issue #493 · frappe/frappe_docker · GitHub

