Tag: Read-Only Filesystems

Sep 23
Container Hardening for Agentic Runtimes: Read-Only Root Filesystems and Seccomp Profiles

In traditional enterprise software deployment, containers running inside Docker or Kubernetes are frequently treated as isolated black boxes. Out-of-the-box container images typically operate with broad privileges: applications run as the root user, root filesystems are fully writable, all Linux capabilities are enabled, and system call (syscall) filtering is left at default configurations. For standard stateless […]