Skip to content

chore: container hardening — read-only root FS + tmpfs /tmp + Python env#68

Merged
constk merged 1 commit into
developfrom
chore/docker-hardening
Apr 29, 2026
Merged

chore: container hardening — read-only root FS + tmpfs /tmp + Python env#68
constk merged 1 commit into
developfrom
chore/docker-hardening

Conversation

@constk
Copy link
Copy Markdown
Owner

@constk constk commented Apr 29, 2026

Brings #119, #120, #170 from Teller v1.10.3 — adds RO-FS + tmpfs /tmp on the docker-compose app service, PYTHONDONTWRITEBYTECODE/UNBUFFERED in Dockerfile runtime stage, distroless decision recorded in docs/SECURITY.md.

@constk constk merged commit 1d3ef1a into develop Apr 29, 2026
15 checks passed
@constk constk deleted the chore/docker-hardening branch April 29, 2026 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant