Read-only root filesystems + tmpfs mounts (fold into Podman conversion) #180

Open
opened 2026-08-27 11:49:28 -04:00 by mysticalsoap · 0 comments
Owner

Set read_only: true on services (Quadlet: ReadOnly=true) with per-service tmpfs:/Tmpfs= mounts for whatever paths each app actually writes to.

  • Stops a compromised process from writing a persistent implant to the container's own filesystem — different threat model than cap drops/rootless, which limit what the process can do, not whether it can persist.
  • Same directive shape in Compose and Quadlet, so this rides along with the Podman/Quadlet conversion instead of needing a second editing pass per stack.
  • No global flip: each image needs its writable paths discovered by trial and error (nginx PID file, app caches/logs, anything that renders config at startup). Do per-stack, not fleet-wide in one PR.
Set `read_only: true` on services (Quadlet: `ReadOnly=true`) with per-service `tmpfs:`/`Tmpfs=` mounts for whatever paths each app actually writes to. - Stops a compromised process from writing a persistent implant to the container's own filesystem — different threat model than cap drops/rootless, which limit what the process can *do*, not whether it can *persist*. - Same directive shape in Compose and Quadlet, so this rides along with the Podman/Quadlet conversion instead of needing a second editing pass per stack. - No global flip: each image needs its writable paths discovered by trial and error (nginx PID file, app caches/logs, anything that renders config at startup). Do per-stack, not fleet-wide in one PR.
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
mysticalsoap/docker#180
No description provided.