feat: make the app root filesystem read-only (E00-S02-T06)

This commit is contained in:
implementer
2026-08-29 00:53:40 +00:00
parent 7cf7994fa8
commit 7ce3ba53cf
2 changed files with 23 additions and 7 deletions
+5 -4
View File
@@ -8,10 +8,11 @@
# server answering `GET /health` with `{"status":"ok"}` (HTTP 200) on port
# 3000, so the app container stays up and the health endpoint succeeds. The
# Fastify 5 application shell (and the real HTTP API) lands in a later story;
# DB volume persistence (T04) is a Compose-level concern (see compose.yaml —
# this image is unchanged), while read-only root filesystem (T06) and
# multi-arch build targets (T07) remain later E00-S02 tasks — all out of scope
# here. Since T05 the runtime stage drops root privileges (runs as the
# DB volume persistence (T04) and read-only root filesystem (T06) are
# Compose-level concerns (see compose.yaml — the `db-data` volume mount and the
# app service's `read_only: true` + `/tmp` tmpfs; this image is unchanged),
# while multi-arch build targets (T07) remains a later E00-S02 task — out of
# scope here. Since T05 the runtime stage drops root privileges (runs as the
# image's non-root `node` user).
#
# Image base: node:24.19.0-bookworm-slim (glibc Debian) per Technology-Stack