harden: run unprivileged, read-only rootfs, no capabilities
The app is the only process on this box accepting unauthenticated input from the internet and it was running as root in a writable container. Now uid 10001, read_only with a tmpfs /tmp, cap_drop ALL and no-new-privileges. Host-side /srv/scout-website/data and the service account key are chowned to 10001. Verified on a throwaway container: every route, the admin API, spam rejection, and a real submission writing to both the jsonl and SQLite.
This commit is contained in:
@@ -17,6 +17,13 @@ services:
|
||||
build:
|
||||
context: ./app
|
||||
container_name: scout-website
|
||||
read_only: true
|
||||
tmpfs:
|
||||
- /tmp
|
||||
cap_drop:
|
||||
- ALL
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
restart: unless-stopped
|
||||
logging:
|
||||
driver: json-file
|
||||
|
||||
Reference in New Issue
Block a user