Giving Read Only rights to homepage container. Adding :RO to the docker.sock volume. When the container gets compromised the intruder will have root access basically. The container doesn't need the write privileges. This measure will stop inexperienced people from exposing their docker.socket to the public internet.pull/770/head
parent
2ac06937f9
commit
6705197a35
Loading…
Reference in new issue