[Feature] Harden rootless Docker Compose more with read-only filesystem, dropped all capabilities and network isolation #31702
Im-hsh
started this conversation in
Community Guides
Replies: 2 comments 4 replies
|
I have problems with dropping ALL permissions for the postgres and valkey containers. Postgres is the exact same image as yours (by hash). I see one difference I'm using the default uid=999 gid=999 rather than your |
3 replies
|
Btw. you don't need to prefix your networks with |
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
The official
rootlessCompose configuration already runs the Immich containers as1000:1000, enablesno-new-privilegesand dropsNET_RAW.I have been running the rootless configuration with additional hardening successfully:
read_only: truefor all containerscap_drop: ALLHardened writable /tmp
tmpfswhere required for read-only operationWritable PostgreSQL runtime/config paths required for read-only operation
Separate frontend and internal backend networks to isolate Redis, PostgreSQL and machine-learning services from the frontend webui off immich
I've included a sample Compose configuration showing these changes and have been running it successfully for months now.
Would these additional hardening measures be suitable for inclusion in the official rootless Compose example?
All reactions