[ORCH-119] Docker security hardening #254
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
Harden Docker container security for the orchestrator service.
Acceptance Criteria
Implementation Summary
Dockerfile Security Enhancements
4-Stage Multi-Stage Build
Non-Root User
Base Image
Health Check
Security Labels
docker-compose.yml Security
User Context
Capability Management
Security Options
Labels
Documentation
Created apps/orchestrator/SECURITY.md:
Testing
Note: Full build testing blocked by pre-existing TypeScript errors in codebase (unrelated to Docker security changes).
Dependencies
Files Changed
References
All acceptance criteria completed. See issue description for full implementation summary. Closing as complete.