瀏覽代碼

docker-compose: read-only container root fs

Fabian Peter Hammerle 3 年之前
父節點
當前提交
d013120275
共有 1 個文件被更改,包括 3 次插入0 次删除
  1. 3 0
      docker-compose.yml

+ 3 - 0
docker-compose.yml

@@ -33,6 +33,9 @@ services:
     volumes:
     - host_keys:/etc/ssh/host_keys:rw
     - authorized_keys:/home/dump/.ssh:ro
+    tmpfs:
+    - /tmp:nosuid,nodev,exec,size=4k # /tmp/mysqldump.sh
+    read_only: true
     ports:
     - 127.0.0.1:2222:2222
     security_opt: ['no-new-privileges']