Use read-only root for docker containers.
This commit is contained in:
parent
9bf2a912d6
commit
4a556bc84f
@ -15,7 +15,7 @@ make --directory=docker
|
|||||||
|
|
||||||
Next we need to launch the server:
|
Next we need to launch the server:
|
||||||
```bash
|
```bash
|
||||||
docker run --init --rm --publish 3000:3000/tcp org-investigation
|
docker run --init --rm --publish 3000:3000/tcp --read-only --mount type=tmpfs,destination=/tmp org-investigation
|
||||||
```
|
```
|
||||||
|
|
||||||
This launches a server listening on port 3000, so pop open your browser to http://127.0.0.1:3000/ to access the web interface.
|
This launches a server listening on port 3000, so pop open your browser to http://127.0.0.1:3000/ to access the web interface.
|
||||||
|
@ -6,7 +6,7 @@ DIR="$( cd "$( dirname "${BASH_SOURCE[0]}" )" && pwd )"
|
|||||||
|
|
||||||
function main {
|
function main {
|
||||||
make --directory "$DIR/../docker"
|
make --directory "$DIR/../docker"
|
||||||
exec docker run --init --rm --publish 3000:3000/tcp org-investigation
|
exec docker run --init --rm --read-only --mount type=tmpfs,destination=/tmp --publish 3000:3000/tcp org-investigation
|
||||||
}
|
}
|
||||||
|
|
||||||
main "${@}"
|
main "${@}"
|
||||||
|
Loading…
Reference in New Issue
Block a user