Move ocr_cache mount from /root/.cache to /app/cache (correct path for non-root user). Add HF_HOME so Hugging Face resolves to the same path. Add runtime hardening: read_only, tmpfs /tmp (512 MB cap), cap_drop ALL, no-new-privileges. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
7.2 KiB
7.2 KiB