Use a read-only root filesystem in service containers
This commit is contained in:
parent
0df3008fa0
commit
9ee480b959
2 changed files with 2 additions and 0 deletions
|
|
@ -7,6 +7,7 @@ ContainerName=ollama
|
||||||
Image=docker.io/ollama/ollama:latest
|
Image=docker.io/ollama/ollama:latest
|
||||||
Network=ollama.network
|
Network=ollama.network
|
||||||
PublishPort=11434:11434
|
PublishPort=11434:11434
|
||||||
|
ReadOnly=true
|
||||||
Volume=%h/.local/share/ollama:/root/.ollama:ro,z
|
Volume=%h/.local/share/ollama:/root/.ollama:ro,z
|
||||||
# keep-sorted end
|
# keep-sorted end
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -11,6 +11,7 @@ Network=private
|
||||||
PublishPort=51413:51413
|
PublishPort=51413:51413
|
||||||
PublishPort=51413:51413/udp
|
PublishPort=51413:51413/udp
|
||||||
PublishPort=9091:9091
|
PublishPort=9091:9091
|
||||||
|
ReadOnly=true
|
||||||
UserNS=keep-id
|
UserNS=keep-id
|
||||||
Volume=%h/.config/transmission:/config:Z
|
Volume=%h/.config/transmission:/config:Z
|
||||||
Volume=%h/Downloads/transmission/watch:/watch:ro,Z
|
Volume=%h/Downloads/transmission/watch:/watch:ro,Z
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue