Add cap_drop ALL, no-new-privileges, read_only + tmpfs to all containers (postgres, redis, backend, celery worker, celery beat). Matches Phase 3 security hardening standards. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| backlog | ||
| config | ||
| files | ||
| portal | ||
| .env.example | ||
| .gitignore | ||
| Dockerfile | ||
| MODULE_SPEC.md | ||
| docker-compose.prod.yml | ||
| docker-compose.yml | ||
| manage.py | ||
| requirements.txt | ||