Review container hardening and AppArmor candidates #9

Open
opened 2026-08-23 17:07:49 +00:00 by stanta · 0 comments
Owner

Outcome

Apply targeted capability, filesystem, and AppArmor controls only where they improve a measured risk.

Current state

The repository has no complete workload-by-workload hardening review. Broad templates could break stateful or privileged services.

Work

  • Select representative public, internal, and privileged workloads.
  • Inventory required capabilities and writable paths.
  • Test read-only filesystems and capability removal.
  • Evaluate AppArmor where recovery remains practical.
  • Record rejected controls and reasons.

Validation

  • Changed workloads pass live functional tests.
  • No control is accepted only because Compose starts.
  • Rollback steps are recorded.

References

  • iac/guides/roadmap-phase-2.md
  • iac/ansible/roles/
## Outcome Apply targeted capability, filesystem, and AppArmor controls only where they improve a measured risk. ## Current state The repository has no complete workload-by-workload hardening review. Broad templates could break stateful or privileged services. ## Work - [ ] Select representative public, internal, and privileged workloads. - [ ] Inventory required capabilities and writable paths. - [ ] Test read-only filesystems and capability removal. - [ ] Evaluate AppArmor where recovery remains practical. - [ ] Record rejected controls and reasons. ## Validation - [ ] Changed workloads pass live functional tests. - [ ] No control is accepted only because Compose starts. - [ ] Rollback steps are recorded. ## References - `iac/guides/roadmap-phase-2.md` - `iac/ansible/roles/`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
stanta/homelab#9
No description provided.