Compare commits
1 commit
19ec91ae5a
...
693ab2d9e6
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
693ab2d9e6 |
1 changed files with 18 additions and 11 deletions
|
|
@ -89,19 +89,26 @@ job "chat" {
|
|||
config {
|
||||
image = "disinto/chat:local"
|
||||
force_pull = false
|
||||
# Sandbox hardening (#706):
|
||||
# - cap_drop ALL (no Linux capabilities)
|
||||
# - tmpfs /tmp for runtime files (64MB)
|
||||
# - pids_limit 128 (prevent fork bombs)
|
||||
# ReadonlyRootfs enforced via entrypoint script (fails if running as root)
|
||||
# Security options:
|
||||
# - apparmor=unconfined for Claude CLI ptrace access
|
||||
# - no-new-privileges prevents privilege escalation
|
||||
cap_drop = ["ALL"]
|
||||
pids_limit = 128
|
||||
# Security options for sandbox hardening
|
||||
# apparmor=unconfined needed for Claude CLI ptrace access
|
||||
# no-new-privileges prevents privilege escalation
|
||||
security_opt = ["apparmor=unconfined", "no-new-privileges"]
|
||||
# tmpfs mounts via volumes config (Nomad Docker driver)
|
||||
volumes = ["tmpfs:/tmp:size=64m"]
|
||||
}
|
||||
|
||||
# ── Sandbox hardening (#706) ────────────────────────────────────────────
|
||||
# cap_drop ALL (no Linux capabilities)
|
||||
# tmpfs /tmp for runtime files (64MB)
|
||||
# pids_limit 128 (prevent fork bombs)
|
||||
cap_drop = ["ALL"]
|
||||
pids_limit = 128
|
||||
mount {
|
||||
type = "tmpfs"
|
||||
target = "/tmp"
|
||||
readonly = false
|
||||
tmpfs_options {
|
||||
size = 67108864 # 64MB in bytes
|
||||
}
|
||||
}
|
||||
|
||||
# ── Volume mounts ──────────────────────────────────────────────────────
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue