diff --git a/docker-compose.yml b/docker-compose.yml index 2ced777..a43de29 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -5,6 +5,21 @@ services: build: . container_name: rwallet-online restart: unless-stopped + read_only: true + tmpfs: + - /tmp + - /var/cache/nginx + - /var/run + cap_drop: + - ALL + cap_add: + - NET_BIND_SERVICE + - CHOWN + - SETGID + - SETUID + - DAC_OVERRIDE + security_opt: + - no-new-privileges:true labels: - "traefik.enable=true" - "traefik.http.routers.rwallet.rule=Host(`rwallet.online`) || Host(`www.rwallet.online`) || Host(`wallets.bondingcurve.tech`)"