NoNewPrivileges on most containers. drop all caps on a few others

This commit is contained in:
zenfyr 2026-01-11 14:11:56 +07:00
commit b3e4af5aca
Signed by: melontini
SSH key fingerprint: SHA256:TtcIcnTnoAB5mqHofsaOxIgiMzfVBxej1AXT7DQdrTE
36 changed files with 80 additions and 1 deletions

View file

@ -3,7 +3,6 @@ Description=Caddy reverse proxy
[Container]
ContainerName=caddy
AddCapability=NET_ADMIN
Image=ghcr.io/zenfyrdev/caddy:latest
Network=host
Volume=/etc/caddy:/etc/caddy:z
@ -11,6 +10,10 @@ Volume=/var/containers/caddy/config:/config:z
Volume=/var/containers/caddy/data:/data:z
Volume=/var/log/caddy:/var/log/caddy:z
Volume=/var/www:/var/www:z
# Security
NoNewPrivileges=true
DropCapability=ALL
AddCapability=NET_ADMIN NET_BIND_SERVICE
[Service]
Restart=always