NoNewPrivileges on most containers. drop all caps on a few others
This commit is contained in:
parent
fb2dd2c723
commit
b3e4af5aca
36 changed files with 80 additions and 1 deletions
|
|
@ -9,6 +9,8 @@ PublishPort=127.0.0.1:40653:6555
|
|||
Volume=/var/containers/spindle/logs:/var/log/spindle:Z
|
||||
Volume=/var/containers/spindle/data:/app:Z
|
||||
Volume=/var/run/dind/docker.sock:/var/run/docker.sock:z
|
||||
# Security
|
||||
NoNewPrivileges=true
|
||||
|
||||
[Service]
|
||||
Restart=always
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue