services:
secure-bash:
build: .
stdin_open: true
tty: true
read_only: true
tmpfs:
- /tmp
- /home/myuser
cap_drop:
- ALL
security_opt:
- no-new-privileges:true
deploy:
resources:
limits:
cpus: '0.5'
memory: 128M
reservations:
cpus: '0.25'
memory: 64M