diff --git a/ocr-service/main.py b/ocr-service/main.py index bc541c78..783bf224 100644 --- a/ocr-service/main.py +++ b/ocr-service/main.py @@ -56,6 +56,8 @@ async def lifespan(app: FastAPI): """Load lightweight models at startup. Surya loads lazily on first request.""" global _models_ready + if os.getuid() == 0: + logger.warning("Running as root — CIS Docker §4.1 violation") logger.info("Loading Kraken model at startup (Surya loads lazily on first OCR request)...") kraken_engine.load_models() load_spell_checker()