Skip to content

Commit 3225e74

Browse files
authored
feat: add security profiles to harden security (#225)
1 parent 19d4cab commit 3225e74

File tree

1 file changed

+9
-0
lines changed

1 file changed

+9
-0
lines changed

container_manager/service.go

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -338,6 +338,15 @@ func (m Manager) serviceToServiceSpec(service Service) swarm.ServiceSpec {
338338
Command: service.Command,
339339
Env: env,
340340
Mounts: volumeMounts,
341+
Privileges: &swarm.Privileges{
342+
NoNewPrivileges: true,
343+
AppArmor: &swarm.AppArmorOpts{
344+
Mode: swarm.AppArmorModeDefault,
345+
},
346+
Seccomp: &swarm.SeccompOpts{
347+
Mode: swarm.SeccompModeDefault,
348+
},
349+
},
341350
},
342351
// Set network name
343352
Networks: networkAttachmentConfigs,

0 commit comments

Comments
 (0)