docker-compose.yml 907 B

123456789101112131415161718192021222324252627282930313233343536
  1. version: '2.3' # volumes long syntax
  2. # options to share host's x-server:
  3. # - Xephyr
  4. # - pass $XAUTHORITY (insecure, https://stackoverflow.com/a/25280523/5894777)
  5. # - xhost + (horribly insecure)
  6. volumes:
  7. home:
  8. services:
  9. browser:
  10. build: .
  11. image: docker.io/fphammerle/brave-browser
  12. container_name: brave_browser
  13. environment:
  14. - DISPLAY
  15. read_only: true
  16. volumes:
  17. - type: bind
  18. source: /tmp/.X11-unix
  19. target: /tmp/.X11-unix
  20. - type: volume
  21. source: home
  22. target: /home/browser
  23. - type: tmpfs
  24. # > ERROR:chrome_browser_main.cc(1254)] Failed to create a ProcessSingleton for your profile directory. [...]
  25. target: /tmp
  26. tmpfs:
  27. # nosuid,nodev,noexec added by default
  28. mode: '1777'
  29. size: 4k
  30. cap_drop: [ALL]
  31. security_opt: [no-new-privileges]
  32. # https://docs.docker.com/compose/compose-file/compose-file-v2/