Security hardening
The container settings the installation package applies, and why to keep them.
The Compose file already applies these settings; keep them when you adapt it:
- the app runs as a non-root user with a read-only root filesystem,
/tmpbeing the only writable path; - the runner has no published ports and is not on the database network;
- the app drops all Linux capabilities and cannot gain new privileges; the runner keeps only the three it needs to run each job as its own user and to ping.