services: secure-bash: build: . stdin_open: true tty: true read_only: true tmpfs: - /tmp - /home/myuser cap_drop: - ALL security_opt: - no-new-privileges:true deploy: resources: limits: cpus: '0.5' memory: 128M reservations: cpus: '0.25' memory: 64M