Orlok

Security hardening

The container settings the installation package applies, and why to keep them.

The Compose file already applies these settings; keep them when you adapt it:

  • the app runs as a non-root user with a read-only root filesystem, /tmp being the only writable path;
  • the runner has no published ports and is not on the database network;
  • the app drops all Linux capabilities and cannot gain new privileges; the runner keeps only the three it needs to run each job as its own user and to ping.