Describe the feature you'd like
version: "3.8"
services:
web:
image: ghcr.io/karakeep-app/karakeep:${KARAKEEP_VERSION:-release}
restart: unless-stopped
container_name: Hoarder
volumes:
# By default, the data is stored in a docker volume called "data".
# If you want to mount a custom directory, change the volume mapping to:
# - /path/to/your/directory:/data
- ./data:/data
ports:
- 3000:3000
env_file:
- .env
environment:
MEILI_ADDR: http://meilisearch:7700
BROWSER_WEB_URL: http://chrome:9222
# OPENAI_API_KEY: ...
# You almost never want to change the value of the DATA_DIR variable.
# If you want to mount a custom directory, change the volume mapping above instead.
DATA_DIR: /data # DON'T CHANGE THIS
chrome:
image: gcr.io/zenika-hub/alpine-chrome:124
restart: unless-stopped
container_name: hoarder_1
security_opt:
- seccomp:./chrome.json
command:
- --disable-gpu
- --disable-dev-shm-usage
- --remote-debugging-address=0.0.0.0
- --remote-debugging-port=9222
- --hide-scrollbars
meilisearch:
image: getmeili/meilisearch:v1.11.1
restart: unless-stopped
container_name: hoarder_2
env_file:
- .env
environment:
MEILI_NO_ANALYTICS: "true"
volumes:
- ./meilisearch:/meili_data
(Enable sandbox and apply security policies)
Upgrade chromium to 124, use security_opt as recommended in Alpine Chromium repo
Use chrome.json from here:
chrome.json
Describe the benefits this would bring to existing Hoarder users
Sandboxing
Can the goal of this request already be achieved via other means?
Idk
Have you searched for an existing open/closed issue?
Additional context
No response
Describe the feature you'd like
(Enable sandbox and apply security policies)
Upgrade chromium to 124, use security_opt as recommended in Alpine Chromium repo
Use chrome.json from here:
chrome.json
Describe the benefits this would bring to existing Hoarder users
Sandboxing
Can the goal of this request already be achieved via other means?
Idk
Have you searched for an existing open/closed issue?
Additional context
No response