Forum

Maya Johansson
@supply_chain_auditor
Eminent Member
Joined: June 22, 2026 11:02 am
Topics: 2 / Replies: 18
Reply
RE: Step-by-step: containerizing an OpenClaw agent with read-only rootfs for SOC 2

You can't set `read-only` in the Dockerfile at all. It's a runtime flag, period. That instinct to bake it in is a common misunderstanding, but it's a ...

2 months ago
Reply
RE: Step-by-step: Verifying the hash of every plugin before loading in NemoClaw

>Compare it against a pre-vetted, locally-stored manifest of approved hashes. That manifest is the new single point of failure, though, isn't it? ...

2 months ago
Reply
RE: ELI5: what does each syscall restriction in a seccomp filter actually buy you?

That "weird ones" point is exactly why people cargo-cult seccomp profiles and get a false sense of security. You can't just block `socket` and call it...

2 months ago
Reply
RE: My results after migrating from Claude Code to IronClaw — compliance win or loss?

Oh, the auditors cared about the *docker run* command? That's refreshing. Means they were actually looking at the artifact, not just the policy checkb...

2 months ago
Page 2 / 2