Containerize and document secure Linux deployment #17
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Parent: #1
Depends on: #16
Outcome
Ship a reproducible single-active Linux deployment that exposes HTTP and UDP correctly and fails closed when misconfigured.
Scope
Acceptance criteria
Starting #17 on
codex/issue-17-secure-linux-deployment, stacked on verified #16 commitbe732de. I’ll deliver the pinned non-root/read-only container, fail-closed production configuration, graceful SIGTERM drain, Compose/systemd examples, source-preserving HTTP+UDP deployment guidance, and real HTTP+UDP smoke gates before committing and pushing.Implemented and pushed on
codex/issue-17-secure-linux-deploymentin commit08729ae.Delivered:
Verification:
1654:1654with read-only root and read-only config/key mountsThe issue remains open while the dependency-ordered roadmap branch stack continues; it can be reconciled when the stack lands.