mirror of
https://github.com/tiennm99/composes.git
synced 2026-10-04 22:13:26 +00:00
Replace privileged: true with cap_drop ALL plus DAC_OVERRIDE, no-new-privileges, a read-only rootfs and memory/pid limits. DAC_OVERRIDE is what lets the uid-0 entrypoint create its storage directory and read the journal and /rootfs; every other capability stays dropped. Route prometheus.exporter.cadvisor, discovery.docker and loki.source.docker through a docker-socket-proxy sidecar on 127.0.0.1:2375 instead of bind-mounting the socket. POST is refused there, so container create and exec are no longer reachable. NETWORKS is granted because Docker SD resolves network names per container and returns no targets without it. Add an alloy validate step to CI and boot the test container with the shipped capability set, read-only rootfs and proxy rather than --privileged.