Container Security
{
"containerDefinitions": [{
"readonlyRootFilesystem": true,
"user": "1000",
"linuxParameters": {
"capabilities": {
"drop": ["ALL"]
}
},
"mountPoints": [{
"sourceVolume": "tmp",
"containerPath": "/tmp",
"readOnly": false
}]
}]
}
Read-only root filesystem + drop ALL capabilities + non-root user = minimal blast radius if the container is compromised.