diff --git a/docker-compose.yml b/docker-compose.yml index 53a1cf97..91f8bbda 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -112,7 +112,8 @@ services: read_only: true tmpfs: - /tmp:size=512m # training endpoints write ZIPs to /tmp; 512 MB covers typical batches (20–50 images) - cap_drop: [ALL] + cap_drop: + - ALL security_opt: - no-new-privileges:true