feat: make the app root filesystem read-only (E00-S02-T06)

This commit is contained in:
implementer
2026-08-29 00:53:40 +00:00
parent 7cf7994fa8
commit 7ce3ba53cf
2 changed files with 23 additions and 7 deletions
+18 -3
View File
@@ -1,4 +1,4 @@
# EPPP Docker Compose baseline — [E00-S02-T01..T05]
# EPPP Docker Compose baseline — [E00-S02-T01..T06]
#
# `docker compose up -d` starts both the database (PostgreSQL) and the
# application (@personal-blog/server). Rollback: `docker compose down`.
@@ -23,8 +23,15 @@
# so the app container does not run with root privileges. No Compose-level
# `user:` override is needed: the image's USER is inherited by the container.
#
# Explicitly out of scope for T01..T05 (land in later E00-S02 tasks):
# - read-only root filesystem (T06), multi-arch build targets (T07)
# Read-only root filesystem (T06): the `app` service sets `read_only: true`, so
# the container's root filesystem is mounted read-only — a write anywhere on it
# is denied. Writable paths are limited to declared mounts and tmpfs: the app
# declares a `tmpfs` at `/tmp` and no writable volume/bind mounts, so `/tmp` is
# the only writable path. Rollback: drop `read_only`/`tmpfs` from the `app`
# service.
#
# Explicitly out of scope for T01..T06 (land in later E00-S02 tasks):
# - multi-arch build targets (T07), secrets not embedded (T08)
#
# All values have defaults so `docker compose up -d` works from a clean clone
# without a .env file (a committed .env.example template lands in E00-S04).
@@ -68,6 +75,14 @@ services:
depends_on:
db:
condition: service_healthy
# T06: read-only root filesystem — the container's root filesystem is
# mounted read-only (`read_only: true`), so writes are denied everywhere
# except the declared mounts/tmpfs below. The app writes nothing else, so
# the only writable path is the declared `tmpfs` at `/tmp` (no writable
# volumes or bind mounts on this service).
read_only: true
tmpfs:
- /tmp
# Named volumes shared across `docker compose` lifecycles. `db-data` (T04)
# holds the PostgreSQL data directory and is preserved across restart and