Skip to content

Harden SCP pod & container#103

Open
andrew-aiken wants to merge 1 commit intosynadia-io:mainfrom
andrew-aiken:scp-hardening
Open

Harden SCP pod & container#103
andrew-aiken wants to merge 1 commit intosynadia-io:mainfrom
andrew-aiken:scp-hardening

Conversation

@andrew-aiken
Copy link
Copy Markdown

Extend the the hardening to follow best practices

Overview

  • Require not to run as root
    • Set to non root user
  • Explicit seccomp deceleration to runtime default
  • Drop all Linux capabilities
  • Read Only file system

Signed-off-by: Andrew Aiken <andrew.aiken@machinemetrics.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant