@@ -7,7 +7,15 @@ services:
|
||||
APP_MODE: agent
|
||||
AGENT_TOKEN: "replace-with-a-random-token-at-least-24-characters"
|
||||
HTTP_TIMEOUT_SECONDS: "10"
|
||||
# Optional: set HOST_ROOT=/host and mount /:/host:ro for identity checks.
|
||||
HOST_ROOT: ""
|
||||
ALLOW_HOST_USER_MANAGEMENT: "false"
|
||||
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
|
||||
volumes:
|
||||
- ./agent-data:/data
|
||||
- ./agent-stacks:/stacks
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
# For read-only host UID/GID + bind ownership checks:
|
||||
# - /:/host:ro
|
||||
# For explicit admin host-user creation only: use /:/host:rw and set
|
||||
# ALLOW_HOST_USER_MANAGEMENT=true.
|
||||
|
||||
@@ -0,0 +1,14 @@
|
||||
# Optional read-only host identity inspection for a local/agent Dockwatch instance.
|
||||
# Usage:
|
||||
# docker compose -f compose.yml -f examples/compose-host-identity.override.yml up -d
|
||||
#
|
||||
# This lets Dockwatch map container UID/GID to host accounts and inspect ownership
|
||||
# of bind-mount sources. It does NOT allow Dockwatch to create host users.
|
||||
services:
|
||||
dockwatch:
|
||||
environment:
|
||||
HOST_ROOT: /host
|
||||
ALLOW_HOST_USER_MANAGEMENT: "false"
|
||||
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
|
||||
volumes:
|
||||
- /:/host:ro
|
||||
@@ -0,0 +1,10 @@
|
||||
# High-trust opt-in for host bind-mount ownership/mode repair.
|
||||
# Dockwatch can chown host files through /host, so use only on trusted machines.
|
||||
services:
|
||||
dockwatch:
|
||||
environment:
|
||||
HOST_ROOT: /host
|
||||
ALLOW_HOST_USER_MANAGEMENT: "true"
|
||||
ALLOW_HOST_PERMISSION_MANAGEMENT: "true"
|
||||
volumes:
|
||||
- /:/host:rw
|
||||
@@ -0,0 +1,13 @@
|
||||
# DANGEROUS / EXPLICIT OPT-IN:
|
||||
# This gives Dockwatch write access to the host root so an administrator can create
|
||||
# a local user/group matching a container's effective UID/GID. The Docker socket
|
||||
# already grants broad host control, but this mount increases direct filesystem
|
||||
# exposure. Use only on trusted hosts and keep ALLOW_HOST_USER_MANAGEMENT=false by default.
|
||||
services:
|
||||
dockwatch:
|
||||
environment:
|
||||
HOST_ROOT: /host
|
||||
ALLOW_HOST_USER_MANAGEMENT: "true"
|
||||
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
|
||||
volumes:
|
||||
- /:/host:rw
|
||||
@@ -16,8 +16,16 @@ services:
|
||||
CHECK_CONCURRENCY: "8"
|
||||
CHECK_RETENTION_DAYS: "30"
|
||||
HTTP_TIMEOUT_SECONDS: "10"
|
||||
# Optional: set HOST_ROOT=/host and mount /:/host:ro for identity checks.
|
||||
HOST_ROOT: ""
|
||||
ALLOW_HOST_USER_MANAGEMENT: "false"
|
||||
ALLOW_HOST_PERMISSION_MANAGEMENT: "false"
|
||||
AUDIT_RETENTION_DAYS: "180"
|
||||
volumes:
|
||||
- ./master-data:/data
|
||||
- ./master-stacks:/stacks
|
||||
- /var/run/docker.sock:/var/run/docker.sock
|
||||
# For read-only host UID/GID + bind ownership checks:
|
||||
# - /:/host:ro
|
||||
# For explicit admin host-user creation only: use /:/host:rw and set
|
||||
# ALLOW_HOST_USER_MANAGEMENT=true.
|
||||
|
||||
Reference in New Issue
Block a user