services: main_infrastructure: container_name: main_infrastructure image: alpine:latest profiles: - main_infrastructure volumes: - public_data:/public_data:rw - private_data:/private_data:rw read_only: true security_opt: - no-new-privileges:true cap_drop: - ALL cap_add: - CHOWN - DAC_OVERRIDE # Fix root permissions on mounted volumes command: chown -R ${PUID:-1000}:${PGID:-1000} /public_data /private_data volumes: public_data: name: public_data private_data: name: private_data networks: infra-network: driver: bridge name: infra-network intern-network: driver: bridge internal: true name: intern-network