Browse Source

Set all container root filesystems to read-only

read-only-fs
Julian Simioni 6 years ago
parent
commit
74d470ebcf
No known key found for this signature in database
GPG Key ID: B9EEB0C6EE0910A1
  1. 12
      projects/portland-metro/docker-compose.yml

12
projects/portland-metro/docker-compose.yml

@ -7,12 +7,14 @@ services:
image: pelias/libpostal-service image: pelias/libpostal-service
container_name: pelias_libpostal container_name: pelias_libpostal
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: always restart: always
ports: [ "4400:4400" ] ports: [ "4400:4400" ]
schema: schema:
image: pelias/schema:portland-synonyms image: pelias/schema:portland-synonyms
container_name: pelias_schema container_name: pelias_schema
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "./synonyms/custom_name.txt:/code/pelias/schema/synonyms/custom_name.txt" - "./synonyms/custom_name.txt:/code/pelias/schema/synonyms/custom_name.txt"
@ -21,6 +23,7 @@ services:
image: pelias/api:master image: pelias/api:master
container_name: pelias_api container_name: pelias_api
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: always restart: always
environment: [ "PORT=4000" ] environment: [ "PORT=4000" ]
ports: [ "4000:4000" ] ports: [ "4000:4000" ]
@ -30,6 +33,7 @@ services:
image: pelias/placeholder:master image: pelias/placeholder:master
container_name: pelias_placeholder container_name: pelias_placeholder
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: always restart: always
environment: [ "PORT=4100" ] environment: [ "PORT=4100" ]
ports: [ "4100:4100" ] ports: [ "4100:4100" ]
@ -40,6 +44,7 @@ services:
image: pelias/whosonfirst:master image: pelias/whosonfirst:master
container_name: pelias_whosonfirst container_name: pelias_whosonfirst
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "${DATA_DIR}:/data" - "${DATA_DIR}:/data"
@ -48,6 +53,7 @@ services:
image: pelias/openstreetmap:master image: pelias/openstreetmap:master
container_name: pelias_openstreetmap container_name: pelias_openstreetmap
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "${DATA_DIR}:/data" - "${DATA_DIR}:/data"
@ -56,6 +62,7 @@ services:
image: pelias/openaddresses:master image: pelias/openaddresses:master
container_name: pelias_openaddresses container_name: pelias_openaddresses
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "${DATA_DIR}:/data" - "${DATA_DIR}:/data"
@ -64,6 +71,7 @@ services:
image: pelias/transit:master image: pelias/transit:master
container_name: pelias_transit container_name: pelias_transit
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "${DATA_DIR}:/data" - "${DATA_DIR}:/data"
@ -71,6 +79,7 @@ services:
image: pelias/polylines:master image: pelias/polylines:master
container_name: pelias_polylines container_name: pelias_polylines
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
volumes: volumes:
- "./pelias.json:/code/pelias.json" - "./pelias.json:/code/pelias.json"
- "${DATA_DIR}:/data" - "${DATA_DIR}:/data"
@ -78,6 +87,7 @@ services:
image: pelias/interpolation:master image: pelias/interpolation:master
container_name: pelias_interpolation container_name: pelias_interpolation
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: always restart: always
environment: [ "PORT=4300" ] environment: [ "PORT=4300" ]
ports: [ "4300:4300" ] ports: [ "4300:4300" ]
@ -88,6 +98,7 @@ services:
image: pelias/pip-service:master image: pelias/pip-service:master
container_name: pelias_pip-service container_name: pelias_pip-service
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: always restart: always
environment: [ "PORT=4200" ] environment: [ "PORT=4200" ]
ports: [ "4200:4200" ] ports: [ "4200:4200" ]
@ -113,6 +124,7 @@ services:
image: pelias/fuzzy-tester:master image: pelias/fuzzy-tester:master
container_name: pelias_fuzzy_tester container_name: pelias_fuzzy_tester
user: "${DOCKER_USER}" user: "${DOCKER_USER}"
read_only: true
restart: "no" restart: "no"
command: "--help" command: "--help"
volumes: volumes:

Loading…
Cancel
Save