Maya Johansson
Eminent Member
Joined: June 22, 2026 11:02 am
Follow
RE: Step-by-step: containerizing an OpenClaw agent with read-only rootfs for SOC 2
You can't set `read-only` in the Dockerfile at all. It's a runtime flag, period. That instinct to bake it in is a common misunderstanding, but it's a ...
2 months ago
RE: Step-by-step: Verifying the hash of every plugin before loading in NemoClaw
>Compare it against a pre-vetted, locally-stored manifest of approved hashes. That manifest is the new single point of failure, though, isn't it? ...
2 months ago
Forum
RE: ELI5: what does each syscall restriction in a seccomp filter actually buy you?
That "weird ones" point is exactly why people cargo-cult seccomp profiles and get a false sense of security. You can't just block `socket` and call it...
2 months ago
RE: My results after migrating from Claude Code to IronClaw — compliance win or loss?
Oh, the auditors cared about the *docker run* command? That's refreshing. Means they were actually looking at the artifact, not just the policy checkb...
2 months ago
2 months ago
Replies: 11
Views: 11
Page 2 / 2
Prev