@@ -0,0 +1,14 @@
|
||||
# READ-ONLY HOST SECURITY AUDIT
|
||||
#
|
||||
# This mode can inspect installed host configuration and files but cannot
|
||||
# change packages or configuration. Active service state is reported only when
|
||||
# the optional host namespace executor is available.
|
||||
services:
|
||||
dockwatch:
|
||||
environment:
|
||||
HOST_ROOT: /host
|
||||
HOST_SECURITY_ENABLED: "true"
|
||||
ALLOW_HOST_SECURITY_CHANGES: "false"
|
||||
ALLOW_HOST_PACKAGE_MANAGEMENT: "false"
|
||||
volumes:
|
||||
- /:/host:ro
|
||||
@@ -0,0 +1,18 @@
|
||||
# FULL HOST SECURITY MANAGEMENT (HIGH PRIVILEGE)
|
||||
#
|
||||
# This override intentionally grants Dockwatch broad host capabilities so it
|
||||
# can install packages, enter the host namespaces, manage services, nftables,
|
||||
# Fail2Ban and auditd. Use only on hosts where Dockwatch is part of your trusted
|
||||
# administration plane. Keep OIDC enabled and restrict admin membership.
|
||||
services:
|
||||
dockwatch:
|
||||
pid: host
|
||||
privileged: true
|
||||
environment:
|
||||
HOST_ROOT: /host
|
||||
HOST_SECURITY_ENABLED: "true"
|
||||
ALLOW_HOST_SECURITY_CHANGES: "true"
|
||||
ALLOW_HOST_PACKAGE_MANAGEMENT: "true"
|
||||
HOST_SECURITY_HOST_PID: "1"
|
||||
volumes:
|
||||
- /:/host:rw
|
||||
Reference in New Issue
Block a user