Drop no-new-privileges: it stops containers starting on Ubuntu with AppArmor (v0.24.52)
0.24.51 set no-new-privileges on nginx and the databases. On Ubuntu with
AppArmor, entering Docker's AppArmor profile then counts as gaining a
privilege, so each container's first exec fails ("exec
/usr/local/bin/docker-entrypoint.sh: operation not permitted") and the
update left Postgres, Redis and InfluxDB restarting (Ubuntu 26.04,
Docker 29.8; Discussion #85). It's removed from every service. Dropped
capabilities, read-only root filesystems, the internal database network
and log rotation stay.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Container images (published once CI passes):
ghcr.io/2gt-media-group-llc/mikrotik-manager-backend:0.24.52-betaghcr.io/2gt-media-group-llc/mikrotik-manager-nginx:0.24.52-beta
Documentation: https://2gt-media-group-llc.github.io/mikrotik-manager/