v9.4.1
release-tag / release-image (push) Successful in 2m33s

This commit is contained in:
2026-09-01 06:31:55 +02:00
parent 695ac8a713
commit 97004838a3
4 changed files with 1712 additions and 0 deletions
@@ -0,0 +1,14 @@
# READ-ONLY HOST SECURITY AUDIT
#
# This mode can inspect installed host configuration and files but cannot
# change packages or configuration. Active service state is reported only when
# the optional host namespace executor is available.
services:
dockwatch:
environment:
HOST_ROOT: /host
HOST_SECURITY_ENABLED: "true"
ALLOW_HOST_SECURITY_CHANGES: "false"
ALLOW_HOST_PACKAGE_MANAGEMENT: "false"
volumes:
- /:/host:ro
@@ -0,0 +1,18 @@
# FULL HOST SECURITY MANAGEMENT (HIGH PRIVILEGE)
#
# This override intentionally grants Dockwatch broad host capabilities so it
# can install packages, enter the host namespaces, manage services, nftables,
# Fail2Ban and auditd. Use only on hosts where Dockwatch is part of your trusted
# administration plane. Keep OIDC enabled and restrict admin membership.
services:
dockwatch:
pid: host
privileged: true
environment:
HOST_ROOT: /host
HOST_SECURITY_ENABLED: "true"
ALLOW_HOST_SECURITY_CHANGES: "true"
ALLOW_HOST_PACKAGE_MANAGEMENT: "true"
HOST_SECURITY_HOST_PID: "1"
volumes:
- /:/host:rw